Deployment

Deployment

Bacre isn't a container: it needs the host's btrfs filesystems and tools, so it runs directly on the server. Static binaries for amd64 and arm64 are attached to every GitHub release.

curl -fsSL -o /usr/local/bin/bacre https://github.com/butterhosting/bacre/releases/latest/download/bacre-linux-amd64
chmod +x /usr/local/bin/bacre
bacre --version

Bacre uses whatever is on the server: btrfs and findmnt for snapshots, restic for restic backups, and bash for the hooks.

systemd

Bacre runs as root, since btrfs requires it:

# /etc/systemd/system/bacre.service
[Unit]
Description=Bacre
After=network-online.target local-fs.target
Wants=network-online.target

[Service]
ExecStart=/usr/local/bin/bacre /etc/bacre/config.yaml
Restart=on-failure
# on a stop, a running backup or restore is allowed to finish first
TimeoutStopSec=infinity

[Install]
WantedBy=multi-user.target
systemctl daemon-reload
systemctl enable --now bacre

Configuration

# /etc/bacre/config.yaml
server:
  bind: 0.0.0.0
  port: 3000
services:
  - /opt/stacks/*/bacre.yaml
users:
  - admin:$2y$05$... # htpasswd -nB admin
envsets:
  nas:
    RESTIC_PASSWORD: correct-horse-battery-staple
webhook:
  url: http://ntfy.lan/backups
  secret: optional-hmac-secret
backends:
  restic:
    cacheDir: /var/cache/bacre/restic
    stagingDir: /var/lib/bacre/staging
KeyDescription
serverThe address and port of the web interface
servicesGlob patterns for finding bacre.yaml files
usersUsers for basic authentication, as name:bcrypt-hash; without any, the interface is open
envsetsNamed sets of environment variables for restic, used by a service's envset
webhookoptional http:// address to post finished jobs to, signed with HMAC-SHA256 in x-bacre-signature
backendsWhere restic keeps its cache and downloaded snapshots; leave it out when using btrfs only
tmpDiroptional directory for temporary files (default: the system's)

Relative paths are relative to the config file.