1
1
mirror of https://gitlab.archlinux.org/archlinux/infrastructure.git synced 2025-01-18 08:06:16 +01:00
infrastructure/roles/borg-server/tasks/main.yml

42 lines
1.0 KiB
YAML

---
- name: install borg
pacman: name=borg state=present
- name: create borg user
user:
name: borg
home: "{{ backup_dir }}"
- name: create borg user home
file:
path: "{{ backup_dir }}"
state: directory
owner: borg
group: borg
mode: 0700
- name: create the root backup directory at {{ backup_dir }}
file:
path: "{{ backup_dir }}/{{ item }}"
state: directory
owner: borg
group: borg
mode: 0700
with_items: "{{ backup_clients }}"
- name: fetch ssh keys from each borg client machine
command: cat /root/.ssh/id_rsa.pub
register: ssh_keys
delegate_to: "{{ item }}"
with_items: "{{ backup_clients }}"
changed_when: ssh_keys.stdout | length > 0
- name: allow certain clients to connect
authorized_key:
user: borg
key: "{{ item.stdout }}"
manage_dir: yes
key_options: "command=\"/usr/bin/borg serve --restrict-to-path {{ backup_dir }}/{{ item['item'] }}\",no-pty,no-agent-forwarding,no-port-forwarding,no-X11-forwarding,no-user-rc"
with_items: "{{ ssh_keys.results }}"