Kopia, A Backup Taken, Listed And Verified

kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

ansibleCloud Tooling

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify

Documentation

kopia

Kopia kopia on EL 10 from the vendor's release, checked against the published SHA-256, pinned to a version, installed as root's binary in /usr/local/bin. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No package worth the name. EL 10 carries no kopia, and a third-party repository is one more key to trust. This role takes the release from kopia.io, has Ansible's get_url refuse the asset unless its SHA-256 is the published one, and the live test checks the asset on disk against the same published value again.

Pinned. kopia_version is what gets installed, kept in a directory of its own so the checksum file and the asset it names stay together. A newer release is a variable change and a run; the same version is changed=0.

Proven to run. The live test runs kopia snapshot verify --config-file /tmp/kp/kopia.config --password iacbazaar-probe and expects "Finished processing" - the binary ran all the way to the point where it needed something this host does not have.

A backup, end to end, offline. The live test creates a filesystem repository with a throwaway password, snapshots a directory into it, lists the snapshot (the source path and files:1), and has kopia snapshot verify read every object back: "Finished processing" is the proof. Remote repositories (S3, GCS, Azure, B2, SFTP, WebDAV, rclone) take the same commands with a different repository create. The asset is named linux-x64 on amd64 and linux-arm64 on arm64, which the architecture map carries; the checksum file is signed (.sig beside it) and this role checks the SHA-256.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules