BorgBackup On A Timer, Proven By A Restore

BorgBackup from EPEL: an encrypted, deduplicated repository, your paths backed up on a systemd timer with daily, weekly and monthly retention, the passphrase generated once and the key exported. The live test backs up a file through the unit, deletes it, restores it byte for byte, and sees a wrong passphrase refused. Original role, live-tested on Rocky Linux 10.

ansibleStorage

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-borg/badge)](https://www.iac-bazaar.com/catalog/ansible-borg?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [BorgBackup On A Timer, Proven By A Restore](https://www.iac-bazaar.com/catalog/ansible-borg?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# BorgBackup On A Timer, Proven By A Restore: https://www.iac-bazaar.com/catalog/ansible-borg (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

borg

BorgBackup from EPEL: an encrypted (repokey-blake2), deduplicated repository, a backup of the paths you list on a systemd timer with daily, weekly and monthly retention, a passphrase generated once and kept, and the repository key exported beside it. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages borg in EPEL, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

A timer, not a daemon. borg runs when the timer fires: the role installs borg-backup.service (a oneshot running /usr/local/sbin/borg-backup: create, prune, compact) and borg-backup.timer, and enables the timer.

Copy two files off the host. Without /etc/borg/passphrase and /etc/borg/key-export, an encrypted repository cannot be read - and a local repository is lost with the disk it sits on. Point borg_repository at a backup host (ssh://...) for anything that matters.

It will not paper over a wrong passphrase. The role asks the repository to open with the passphrase first; when it does not, borg init refuses to write over the existing repository, so the play stops rather than starting a second one.

Proven by a restore. The live test writes a file under a backed-up path, runs the backup unit as the timer would, lists the archive, deletes the file, extracts it from the newest archive and compares it with a copy, byte for byte. A wrong passphrase is refused ("...is incorrect"), borg check passes, the timer is enabled and the passphrase file is 0600.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-garage

Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kopia

kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-samba-share

Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-seaweedfs

SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-syncthing

Syncthing from the upstream release with its API on loopback behind a key that never appears in the unit file. Discovery, relays, NAT traversal, crash reports and self-upgrade are switched off through the REST API. The live test sees a missing or wrong key refused, finds no key in the unit, and watches a shared folder get indexed. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-rclone

rclone on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which copies a directory, lists the copy with its size and has rclone check report 0 differences. Remotes are rclone config, per user. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module