mirror of
https://github.com/Portabase/agent.git
synced 2026-10-11 15:31:50 +00:00
5d87fb2d7d
Back up and restore plain directories, alongside the database sources. Files source and Archive (P0) - `files` type: absolute path (not /), options.exclude and options.one_file_system; walk + tar.gz with symlinks kept as links, special files skipped, unreadable entries fail the run. - Mirror restore: archive validated first, then everything not excluded is wiped (mount points and special files kept) and the archive is extracted, retrying without metadata on filesystems refusing chown/chmod. - Windows-safe platform helpers; helm extraVolumes/extraVolumeMounts. Universal rclone mapper (P1) - rclone_target(storage) for s3, blob, gcs, drive, rclone and sftp; sftp goes through it; rclone obscure reads the password from stdin. Snapshots, restic (P2) - restic in the image; repository per source and channel, password derived from the master key (HKDF); stable host, bs:<row> tags, translated excludes; exit 3 fails and forgets the snapshot. - Mirror restore with `restic restore --delete`; restore payload carries the encrypted channel; snapshot ids must be full ids. - Engine in the ping and in scheduled task metadata. One locked method per source (spec A) - databases.json declares options.method (archive, snapshot, sync), reported in the ping for local sources only. - Sync: rclone sync per channel onto <folder>/sync/<id>/current, refuses an empty source, reports transferred/deleted counters. Local channel (spec B) - Snapshots and Sync reach the dashboard's local storage through its append-only restic REST server and its WebDAV server. Security - Strict rclone config validation: one section, no duplicate keys, no command, credential or host-file keys, no quoted values, valid backend type, blocked backends. - Scheduled task metadata (decrypted storages) is no longer logged.
Development Notes
Check that Kubernetes is reachable locally
kubectl get nodes
Install the local Portabase Agent Helm chart
helm install portabase-agent . \
--set env.EDGE_KEY=<your-edge-key>
Check the pods
kubectl get pods
Check the services
kubectl get svc
To update .env variables or JSON config:
kubectl rollout restart deployment portabase-agent
Install or upgrade the Helm chart
helm upgrade portabase-agent . \
--reuse-values \
--set env.EDGE_KEY="NEW_EDGE_KEY"
Rollout to restart
kubectl rollout restart deployment portabase-agent
List pods to get the pod name
kubectl get pods -l app=portabase-agent
Get logs for the pod
kubectl logs portabase-agent-6f7d4f5c6b-abc12
Uninstall Agent
helm uninstall portabase-agent
Mount a directory for a files source
A files source backs up a directory the agent can see. Mount it into the pod
with extraVolumes and extraVolumeMounts:
extraVolumes:
- name: shared-files
hostPath:
path: /srv/files
type: Directory
extraVolumeMounts:
- name: shared-files
mountPath: /data/files
Mount it read-write: restores write into it. The mountPath (here /data/files)
is the path to enter for the source in Portabase.