BorgBackup On A Timer, Proven By A Restore
BorgBackup from EPEL: an encrypted, deduplicated repository, your paths backed up on a systemd timer with daily, weekly and monthly retention, the passphrase generated once and the key exported. The live test backs up a file through the unit, deletes it, restores it byte for byte, and sees a wrong passphrase refused. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-borg?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [BorgBackup On A Timer, Proven By A Restore](https://www.iac-bazaar.com/catalog/ansible-borg?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# BorgBackup On A Timer, Proven By A Restore: https://www.iac-bazaar.com/catalog/ansible-borg (download from your IaC Bazaar account)
```Preview:
Documentation
borg
BorgBackup from EPEL: an encrypted (repokey-blake2), deduplicated repository, a backup of the paths you list on a systemd timer with daily, weekly and monthly retention, a passphrase generated once and kept, and the repository key exported beside it. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages borg in EPEL, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
A timer, not a daemon. borg runs when the timer fires: the role installs
borg-backup.service (a oneshot running /usr/local/sbin/borg-backup:
create, prune, compact) and borg-backup.timer, and enables the timer.
Copy two files off the host. Without /etc/borg/passphrase and
/etc/borg/key-export, an encrypted repository cannot be read - and a local
repository is lost with the disk it sits on. Point borg_repository at a
backup host (ssh://...) for anything that matters.
It will not paper over a wrong passphrase. The role asks the repository
to open with the passphrase first; when it does not, borg init refuses to
write over the existing repository, so the play stops rather than starting a
second one.
Proven by a restore. The live test writes a file under a backed-up path,
runs the backup unit as the timer would, lists the archive, deletes the
file, extracts it from the newest archive and compares it with a copy, byte
for byte. A wrong passphrase is refused ("...is incorrect"), borg check
passes, the timer is enabled and the passphrase file is 0600.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-garage
Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.
ansible-kopia
kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-samba-share
Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.
ansible-seaweedfs
SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.
ansible-syncthing
Syncthing from the upstream release with its API on loopback behind a key that never appears in the unit file. Discovery, relays, NAT traversal, crash reports and self-upgrade are switched off through the REST API. The live test sees a missing or wrong key refused, finds no key in the unit, and watches a shared folder get indexed. Original role, live-tested on Rocky Linux 10.
ansible-rclone
rclone on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which copies a directory, lists the copy with its size and has rclone check report 0 differences. Remotes are rclone config, per user. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.