Files
Portabase.Agent/helm
Charles Gauthereau 5d87fb2d7d feat(files): files sources with Archive, Snapshots and Sync methods
Back up and restore plain directories, alongside the database sources.

Files source and Archive (P0)
- `files` type: absolute path (not /), options.exclude and
  options.one_file_system; walk + tar.gz with symlinks kept as links,
  special files skipped, unreadable entries fail the run.
- Mirror restore: archive validated first, then everything not excluded
  is wiped (mount points and special files kept) and the archive is
  extracted, retrying without metadata on filesystems refusing chown/chmod.
- Windows-safe platform helpers; helm extraVolumes/extraVolumeMounts.

Universal rclone mapper (P1)
- rclone_target(storage) for s3, blob, gcs, drive, rclone and sftp; sftp
  goes through it; rclone obscure reads the password from stdin.

Snapshots, restic (P2)
- restic in the image; repository per source and channel, password
  derived from the master key (HKDF); stable host, bs:<row> tags,
  translated excludes; exit 3 fails and forgets the snapshot.
- Mirror restore with `restic restore --delete`; restore payload carries
  the encrypted channel; snapshot ids must be full ids.
- Engine in the ping and in scheduled task metadata.

One locked method per source (spec A)
- databases.json declares options.method (archive, snapshot, sync),
  reported in the ping for local sources only.
- Sync: rclone sync per channel onto <folder>/sync/<id>/current, refuses
  an empty source, reports transferred/deleted counters.

Local channel (spec B)
- Snapshots and Sync reach the dashboard's local storage through its
  append-only restic REST server and its WebDAV server.

Security
- Strict rclone config validation: one section, no duplicate keys, no
  command, credential or host-file keys, no quoted values, valid backend
  type, blocked backends.
- Scheduled task metadata (decrypted storages) is no longer logged.
2026-10-04 10:09:56 +02:00
..
2026-03-09 16:41:14 +01:00
2026-03-09 16:41:14 +01:00

Development Notes

Check that Kubernetes is reachable locally

kubectl get nodes

Install the local Portabase Agent Helm chart

helm install portabase-agent . \ 
--set env.EDGE_KEY=<your-edge-key>

Check the pods

kubectl get pods

Check the services

kubectl get svc

To update .env variables or JSON config:

kubectl rollout restart deployment portabase-agent

Install or upgrade the Helm chart

helm upgrade portabase-agent . \
--reuse-values \
--set env.EDGE_KEY="NEW_EDGE_KEY"

Rollout to restart

kubectl rollout restart deployment portabase-agent

List pods to get the pod name

kubectl get pods -l app=portabase-agent

Get logs for the pod

kubectl logs portabase-agent-6f7d4f5c6b-abc12

Uninstall Agent

helm uninstall portabase-agent

Mount a directory for a files source

A files source backs up a directory the agent can see. Mount it into the pod with extraVolumes and extraVolumeMounts:

extraVolumes:
  - name: shared-files
    hostPath:
      path: /srv/files
      type: Directory

extraVolumeMounts:
  - name: shared-files
    mountPath: /data/files

Mount it read-write: restores write into it. The mountPath (here /data/files) is the path to enter for the source in Portabase.