Parent directory

duplicity-backup.conf.example

17615 bytes
  1#!/bin/bash
  2#
  3# Copyright (c) 2008-2010 Damon Timm.
  4# Copyright (c) 2010 Mario Santagiuliana.
  5# Copyright (c) 2012-2018 Marc Gallet.
  6#
  7# This program is free software: you can redistribute it and/or modify it under
  8# the terms of the GNU General Public License as published by the Free Software
  9# Foundation, either version 3 of the License, or (at your option) any later
 10# version.
 11#
 12# This program is distributed in the hope that it will be useful, but WITHOUT
 13# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
 14# FOR A PARTICULAR PURPOSE.  See the GNU General Public License for more
 15# details.
 16#
 17# You should have received a copy of the GNU General Public License along with
 18# this program.  If not, see <http://www.gnu.org/licenses/>.
 19#
 20# MORE ABOUT THIS SCRIPT AVAILABLE IN THE README AND AT:
 21#
 22# http://zertrin.org/projects/duplicity-backup/ (for this version)
 23# http://damontimm.com/code/dt-s3-backup (for the original program by Damon Timm)
 24#
 25# Latest code available at:
 26# http://github.com/zertrin/duplicity-backup.sh
 27#
 28# List of contributors:
 29# https://github.com/zertrin/duplicity-backup.sh/graphs/contributors
 30#
 31# ---------------------------------------------------------------------------- #
 32
 33# #############################################
 34# #       DUPLICITY-BACKUP CONFIG FILE        #
 35# #############################################
 36
 37# !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
 38# !           DO NOT edit this file!          !
 39# !      (duplicity-backup.conf.example)      !
 40# !    please copy it to anywhere you want    !
 41# !     (typically duplicity-backup.conf)     !
 42# !        and edit that copy instead         !
 43# !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
 44
 45#               .............
 46#               .  WARNING  .
 47#               .............
 48#
 49# duplicity-backup.sh IS NOT duplicity!
 50#
 51# It is only a wrapper script for duplicity written in bash!
 52#
 53# This means the following:
 54#
 55#     * You need to install and configure duplicity BEFORE using duplicity-backup.sh
 56#
 57#     * The official documentation of duplicity (http://duplicity.nongnu.org/duplicity.1.html)
 58#       is relevant to duplicity-backup.sh too. Virtually any option supported
 59#       by duplicity can be specified in the config file of duplicity-backup.sh.
 60#       See the `STATIC_OPTIONS`, `CLEAN_UP_TYPE` and `CLEAN_UP_VARIABLE` parameters in particular.
 61#
 62#     * Before asking something about duplicity-backup.sh, ensure that your question
 63#       isn't actually concerning duplicity ;)
 64#       First, make sure you can perform a backup with duplicity without using this script.
 65#       If you can't make the backup work with duplicity alone, the problem is probably
 66#       concerning duplicity and not this script. If you manage to make a backup with duplicity
 67#       alone but not with this script, then there is probably a problem with duplicity-backup.sh.
 68
 69
 70# ------------------------------------------------------------------------------
 71# BACKUP SOURCE INFORMATION
 72# ------------------------------------------------------------------------------
 73#
 74# The ROOT of your backup (where you want the backup to start);
 75# This can be / or somewhere else -- I use /home/ because all the
 76# directories that I want to backup start with /home/.
 77#
 78ROOT='/home'
 79
 80# Set hostname for this duplicity instance, useful for e-mail reports
 81#
 82HOSTNAME=$(hostname -f)
 83
 84# ------------------------------------------------------------------------------
 85# BACKUP DESTINATION INFORMATION
 86# ------------------------------------------------------------------------------
 87# In my case, I use Amazon S3 use this - so I made up a unique
 88# bucket name (you don't have to have one created, it will do it
 89# for you). If you don't want to use Amazon S3, you can backup
 90# to a file or any of duplicity's supported outputs.
 91#
 92# The s3+http scheme uses the default aws s3 hostname.
 93# Use s3://host/bucket/[backup-folder/] if you want to specify the host name.
 94# If using the s3://... scheme and you have s3cmd installed, be sure to change
 95# 's3.amazonaws.com' to the appropriate host in your .s3cfg file so that the
 96# remote file size check will work.
 97
 98#DEST="s3://host/backup-bucket/backup-folder/"
 99DEST="s3+http://foobar-backup-bucket/backup-folder/"
100
101# Other possible locations
102# Be sure to check duplicity's man page to know how to use them
103# (http://duplicity.nongnu.org/duplicity.1.html)
104#
105#DEST="gs://foobar-backup-bucket/backup-folder/"
106#DEST="ftp://user[:password]@other.host[:port]/some_dir"
107#DEST="ftps://user[:password]@other.host[:port]/some_dir"
108#DEST="ftpes://user[:password]@other.host[:port]/some_dir"
109#DEST="rsync://user@host.com[:port]//absolute_path"
110#DEST="scp://user[:password]@other.host[:port]/[/]some_dir"
111#DEST="sftp://user[:password]@other.host[:port]/[/]some_dir"
112#DEST="file:///home/foobar_user_name/new-backup-test/"
113#DEST="imap[s]://user[:password]@host.com[/from_address_prefix]"
114#DEST="webdav[s]://user[:password]@other.host[:port]/some_dir"
115#DEST="b2://some_account_id[:some_application_key]@some_bucket_name/some_dir"
116
117
118# ------------------------------------------------------------------------------
119# DESTINATION BACKEND PASSWORD
120# ------------------------------------------------------------------------------
121# Instead of setting the password needed for the backup destination in the
122# DEST url, you can supply it in the BACKEND_PASSWORD variable below, which is
123# used by most, if not all backends, regardless of its name.
124# Duplicity's official documentation states:
125#   "Supported by most backends which are password capable. More secure than
126#    setting it in the backend url (which might be readable in the operating
127#    systems process listing to other users on the same machine)."
128#
129#BACKEND_PASSWORD='password'
130
131
132# ------------------------------------------------------------------------------
133# AMAZON S3 INFORMATION
134# ------------------------------------------------------------------------------
135# Uncomment these lines if you're using Amazon S3
136#
137#AWS_ACCESS_KEY_ID="foobar_aws_key_id"
138#AWS_SECRET_ACCESS_KEY="foobar_aws_access_key"
139#
140# SET STORAGE CLASS for AWS
141# The default storage class is STANDARD STORAGE. You can comment this option if
142# want to go with standard. The other storage options are --s3-use-ia and --s3-use-rrs.
143# Note: --s3-use-ia option is supported only in duplicity version greater than 0.7.06
144#
145#STORAGECLASS="--s3-use-ia"
146#
147# S3CMD INFORMATION
148# Most people don't need this, but in some cases
149# you may want to specify a custom configuration file
150# to pass to s3cmd. If so, set the S3CMD_CONF_FILE variable
151# to the full path of this custom config file.
152# Per default s3cmd uses ${HOME}/.s3cfg
153#
154#S3CMD_CONF_FILE='/path/to/your/s3cmd/conf/file'
155
156# ------------------------------------------------------------------------------
157# INCLUDE LIST OF DIRECTORIES
158# ------------------------------------------------------------------------------
159# Here is a list of directories to include; if you want to include
160# everything that is in ROOT, leave this list empty.
161#
162# Here is an example with multiple locations:
163#
164#INCLIST=(  '/home/*/Documents' \
165#           '/home/*/Projects' \
166#           '/home/*/logs' \
167#           '/home/www/mysql-backups' \
168#        )
169#
170# Simpler example with one location:
171
172INCLIST=( '/home/foobar_user_name/Documents/' )
173
174
175# ------------------------------------------------------------------------------
176# EXCLUDE LIST OF DIRECTORIES
177# ------------------------------------------------------------------------------
178# Even though I am being specific about what I want to include,
179# there is still a lot of stuff I don't need.
180# If you don't want to exclude anything, leave this list empty.
181#
182# Here is an example with multiple locations:
183#
184#EXCLIST=(   '/home/*/Trash' \
185#            '/home/*/Projects/Completed' \
186#            '/**.DS_Store' \
187#            '/**Icon?' \
188#            '/**.AppleDouble' \
189#        )
190#
191# If you don't want to exclude anything, use EXCLIST=()
192#
193# Simpler example with one location. Adapt it to your needs.
194
195EXCLIST=( '/home/foobar_user_name/Documents/foobar-to-exclude' )
196
197
198# ------------------------------------------------------------------------------
199# INCLUDE GLOBBING FILELIST
200# ------------------------------------------------------------------------------
201# Instead of using the INCLIST/EXCLIST variable you can also define a special
202# (text-)file where each line in the filelist will be interpreted as
203# a globbing pattern. By using the '+' or '-' sign at the beginning of each line
204# you are able to specify if the folder should be included or excluded.
205#
206# Example:
207#   + /dir/foo
208#   - /dir/foob*
209#   + /dir/*
210#
211# From the duplicity manual:
212# Lines starting with "+" are interpreted as include directives[...]Similarly, lines starting with "-" exclude files even if they are found within an include filelist.
213# For more examples or information refer to http://duplicity.nongnu.org/duplicity.1.html#sect10
214#
215#INCEXCFILE=/path/to/file
216
217
218# ------------------------------------------------------------------------------
219# EXCLUDE DEVICE FILES
220# ------------------------------------------------------------------------------
221# Exclude all device files. This can be useful for security/permissions reasons
222# or if device files are not handled correctly.
223#
224EXDEVICEFILES=1
225
226
227# ------------------------------------------------------------------------------
228# ENCRYPTION INFORMATION
229# ------------------------------------------------------------------------------
230#
231# Do you want your backup to be encrypted? yes/no
232# If yes, please make sure you specify either PASSPHRASE or GPG_ENC_KEY/GPG_SIGN_KEY
233
234ENCRYPTION='yes'
235
236# If you are NOT running this from a cron, comment this line out
237# and duplicity should prompt you for your password.
238# Otherwise this password is either used for symmetric encryption
239# (your backups will be encrypted with this password) or is used
240# for the "GPG_SIGN_KEY" (see below).
241# Comment out if you aren't using encryption
242# Note: if you have a ' in your passphrase, escape it accordingly.
243
244PASSPHRASE='foobar_gpg_passphrase'
245
246# Specify which GPG keys you would like to use (even if you have only one).
247# If you are running this from a cron, it is highly recommended to create separate
248# signature and encryption keys, because you have to specify the password for the
249# GPG_SIGN_KEY via the above PASSPHRASE variable
250# (see http://www.debian-administration.org/articles/209#d0e109).
251# If you are not running the script from a cron, duplicity should prompt you for the
252# GPG_SIGN_KEY password.
253# If you choose to use the same GPG key for encryption and signature, set it both
254# in GPG_ENC_KEY and GPG_SIGN_KEY.
255# Comment out if you're using only PASSPHRASE (symmetric encryption) or not using
256# encryption at all.
257
258GPG_ENC_KEY="foobar_gpg_key"
259GPG_SIGN_KEY="foobar_gpg_key"
260
261# Do you want to hide the key id of the encrypted files? yes/no
262# It uses the gpg's --hidden-recipient command to obfuscate the owner of the backup.
263# On restore, gpg will automatically try all available secret keys in order to
264# decrypt the backup. See gpg(1) for more details.
265#
266# HIDE_KEY_ID='yes'
267
268# You can optionally specify the secret keyring file to use for the encryption and
269# signing keys. If not specified, the default secret keyring is used which is
270# usually located at ~/.gnupg/secring.gpg
271#
272#SECRET_KEYRING="/home/foobar_user_name/.gnupg/duplicity.gpg
273
274# Here you can specify options that will be passed to GPG.
275# If you can, avoid using quotes here, as it hasn't been tested much yet.
276# You shouldn't need to remove the following default (--no-show-photos)
277# For example an user reported (GitHub issue #145) that since gnupg v2.1,
278# the option "--pinentry-mode loopback" is necessary,
279# then set GPG_OPTIONS="--no-show-photos --pinentry-mode loopback"
280GPG_OPTIONS="--list-options no-show-photos"
281
282
283# ------------------------------------------------------------------------------
284# STATIC BACKUP OPTIONS
285# ------------------------------------------------------------------------------
286#
287# Here you can define the static backup options that you want to run with
288# duplicity. Reference is the manpage of duplicity (available at
289# http://duplicity.nongnu.org/duplicity.1.html for example)
290# Useful examples are `--full-if-older-than` option and (for those using
291# Amazon S3 in Europe) `--s3-use-new-style` and `--s3-european-buckets` options
292# Be sure to separate your options with appropriate spacing.
293
294STATIC_OPTIONS="--full-if-older-than 14D --s3-use-new-style"
295
296
297# ------------------------------------------------------------------------------
298# FULL BACKUP & REMOVE OLDER THAN SETTINGS
299# ------------------------------------------------------------------------------
300#
301# Because duplicity will continue to add to each backup as you go,
302# it will eventually create a very large set of files.  Also, incremental
303# backups leave room for problems in the chain, so doing a "full"
304# backup every so often is not a bad idea.
305#
306# You can remove older than a specific time period:
307#
308#CLEAN_UP_TYPE="remove-older-than"
309#CLEAN_UP_VARIABLE="31D"
310#
311# Or, If you would rather keep a certain (n) number of full backups (rather
312# than removing the files based on their age), you can use what I use:
313
314CLEAN_UP_TYPE="remove-all-but-n-full"
315CLEAN_UP_VARIABLE="4"
316
317# The third option is to skip cleanup altogether, by:
318#
319#CLEAN_UP_TYPE="none"
320#
321# In combination with "remove-older-than" clean-up type, you may want
322# to keep only the full backups older than (n) number backup sets. For example,
323# let's say you set to CLEAN_UP_TYPE="remove-older-than", CLEAN_UP_VARIABLE
324# to "6M" (six months), STATIC_OPTIONS to "--full-if-older-than 7D"
325# (a full backup every 7 days), and you execute duplicity-backup once a day.
326# After six months you'll have 25 full backups, each with daily incrementals
327# in between. Perhaps you're keeping the backups past 1 month "just in case",
328# and so the older incrementals are overkill - weekly full backups beyond
329# one month backward would suffice. In this case you can set
330# "REMOVE_INCREMENTALS_OLDER_THAN to, say, "4" which will delete the
331# incrementals for backup sets beyond the four most recent, keeping
332# only the full weekly backups for those backup sets. The incrementals
333# for the four most recent backup sets remain untouched.
334#
335#REMOVE_INCREMENTALS_OLDER_THAN="4"
336
337
338# ------------------------------------------------------------------------------
339# LOGFILE INFORMATION DIRECTORY
340# ------------------------------------------------------------------------------
341#
342# Provide directory for logfile, ownership of logfile & directory, and verbosity level.
343# I run this script as root, but save the log files under my user name --
344# just makes it easier for me to read them and delete them as needed.
345
346LOGDIR="/home/foobar_user_name/logs/test2/"
347LOG_FILE="duplicity-$(date +%Y-%m-%d_%H-%M).txt"
348
349# Note that if the configured LOGDIR does not exist it will be created
350# and its owner:group set to that of the configured LOG_FILE_OWNER.
351# If the configured LOGDIR already exists no change to owner:group is attempted.
352#
353#REMOVE_LOGS_OLDER_THAN='30' # (days) uncomment to activate
354
355VERBOSITY="-v3"
356
357# Set the tmpdir for duplicity to use.
358#TMPDIR="/tmp"
359
360
361# ------------------------------------------------------------------------------
362# EMAIL ALERT (*thanks: rmarescu*)
363# ------------------------------------------------------------------------------
364#
365# Provide an email address to receive the logfile by email. If EMAIL_TO is not
366# provided, no alert will be sent.
367# You can set a custom from email address and a custom subject (both optionally)
368# If no value is provided for the subject, the following value will be
369# used by default: "duplicity-backup Alert ${LOG_FILE}"
370# MTA used: mailx
371
372#EMAIL_TO="admin@example.com"
373EMAIL_TO=
374EMAIL_FROM=
375EMAIL_SUBJECT=
376EMAIL_FAILURE_ONLY="yes" # send e-mail only if there was an error while creating backup
377
378# command to use to send mail
379MAIL="mailx"     # default command for Linux mail
380#MAIL="mail"     # for CentOS, if "mailx" fails try this one
381#MAIL="ssmtp"
382#MAIL="sendmail"
383#MAIL="msmtp"
384
385# You may specify a custom mail script instead.  It will be called with
386# the following convention:
387# MAIL "SUBJECT OF MESSAGE" "TO EMAIL ADDRESS" "FROM EMAIL ADDRESS"
388# The email body will be available on stdin.
389#
390#MAIL="/path/to/custom/mail_script.py"
391
392
393# ------------------------------------------------------------------------------
394# NOTIFICATIONS
395# ------------------------------------------------------------------------------
396#
397# Third-party notification services. If NOTIFICATION_SERVICE is not provided, no
398# notifications will be sent.
399
400# Possible values for NOTIFICATION_SERVICE are: slack, pushover, ifttt, telegram
401NOTIFICATION_SERVICE=""
402NOTIFICATION_FAILURE_ONLY="yes" # send notifications only if there was an error while creating backup
403
404# Provider: Telegram
405TELEGRAM_CHATID="" #Generate a Telegram bot following guide: https://core.telegram.org/bots#3-how-do-i-create-a-bot
406TELEGRAM_KEY=""
407
408# ------------------------------------------------------------------------------
409# TROUBLESHOOTING
410# ------------------------------------------------------------------------------
411#
412# If you are having any problems running this script it is
413# helpful to see the command output that is being generated to determine if the
414# script is causing a problem or if it is an issue with duplicity (or your
415# setup).  Simply  uncomment the ECHO line below and the commands will be
416# printed to the logfile.  This way, you can see if the problem is with the
417# script or with duplicity.
418#
419#ECHO=$(which echo)