Skip to main content

Restic Backups

YAML configuration and a Python CLI for running multiple restic repositories, with optional SOPS decryption. The package currently includes a complete macOS Voice Memos workflow for backup, transcription, summarisation, and speaker diarization, plus managed backups of explicit GitHub repositories or every repository owned by a GitHub organization or user.

Why

Create encrypted, deduplicated incremental backups that upload only new or changed data. This makes reliable off-site backups practical with cheaper storage options, without maintaining a separate backup script for every repository.

Backup payloads, generated metadata, model caches, and restores are excluded from Git by a default-deny .gitignore.

Install

make install-deps  # Homebrew tools, including restic, sops, git-lfs, gh, and uv
make install       # uv sync, including the dev group and Quarto

make init loads the selected configuration and initializes each enabled restic repository that does not already exist. It reports and skips disabled or initialized repositories, and does not back up files.

CLI

Use the built-in help for available commands and options:

uv run restic-backups  # interactive arrow-key menu
uv run restic-backups --help
uv run restic-backups job --help
uv run restic-backups github-repository --help
uv run restic-backups generic --help
uv run restic-backups voice-memos --help

The interactive menus include Help and Back at every level. Press Escape to go back or Ctrl+C to exit. Help stays at the current level and does not load configuration or access a repository. Generic write actions also offer a Space-toggleable Dry run checkbox so the operation can be inspected without changing repository data.

Command auditing is enabled by default and appends JSON records to audit-log.json in the current directory. Set RESTIC_BACKUPS_AUDIT=0 to disable it. Passwords and other secret-like argument values are redacted. GitHub jobs also audit their raw git, git lfs, gh, and restic commands; tokens and temporary credential paths remain outside those arguments.

Configuration

Pass a plain YAML file explicitly:

uv run restic-backups --config config.yaml check-config

For SOPS, add --sops. The equivalent environment variables are RESTIC_BACKUPS_CONFIG and RESTIC_BACKUPS_SOPS=1; they also configure make config-check and make init.

The configuration separates:

  • storage: S3-compatible services and mounted local filesystems, with S3 credentials kept on the relevant storage entry;
  • restic-repositories: encrypted repositories within storage, including the bucket/key prefix or local path, restic password, cache, and archive policy;
  • jobs: typed work linked to one or more restic repositories. files, github-repository, github-owner, and voice-memos jobs share the same destination and snapshot fields while defining their input under source. One github-repository job may incrementally maintain multiple repository URLs and snapshot their combined state together. One github-owner job discovers every repository visible to the active GitHub credentials before using that same multi-repository workflow. Local runs reuse gh auth login; unattended runs may read a token from an environment variable or mounted file. A dry run still performs read-only discovery so it can report the exact plan, but never runs Git or writes to restic.

Multiple restic repositories may use one storage backend, one job may write to several repositories, and several jobs may share one repository. The job TUI preselects a sole enabled destination; multiple destinations start unchecked. Disabled repositories may contain CHANGE_ME; all placeholders must be replaced before enabling one.

Data and source paths

Managed local artifacts use:

data/<storage-id>/<repository-path>/<job-id>/

This directory is created beside the selected configuration file. It is metadata/workspace organization, not a restriction on backup sources. Restic may back up absolute paths anywhere on the machine. List or run every job type through the same commands:

uv run restic-backups job list
uv run restic-backups job run documents

AWS Glacier

Use GLACIER_IR with restore: null for normal immediate restic access. Cold GLACIER and DEEP_ARCHIVE repositories require a configured retrieval tier, days, and timeout. Retrieval must also be acknowledged at runtime:

ALLOW_ARCHIVE_RETRIEVAL=1 uv run restic-backups generic restic run \
  --backup <job-id> restore latest --target <dir>

Storage-class changes apply only to new objects. Use a new key_prefix instead of mixing storage policies in one repository.

Documentation

make docs          # render docs/_site
make docs-preview  # local preview server

Start with the Quick Start. Never commit decrypted SOPS configuration or anything below data/.

For complete reachable Git history, multiple explicit repository URLs, owner discovery, and optional LFS objects, wikis, GitHub metadata, and release assets, see GitHub Backups.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

restic_backups-0.1.7.tar.gz (56.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

restic_backups-0.1.7-py3-none-any.whl (68.7 kB view details)

Uploaded Python 3

File details

Details for the file restic_backups-0.1.7.tar.gz.

File metadata

  • Download URL: restic_backups-0.1.7.tar.gz
  • Upload date:
  • Size: 56.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for restic_backups-0.1.7.tar.gz
Algorithm Hash digest
SHA256 2febb89a7340d248168095c560459a2f5eea7e987cae2f126231aecb1aba8679
MD5 9d28e26f961a20bcc18235e0d30c15c0
BLAKE2b-256 844cbc1697f9f84b28f5cb438b0e6408cdee9f996c1b8bb1be21a5e2050e6aad

See more details on using hashes here.

File details

Details for the file restic_backups-0.1.7-py3-none-any.whl.

File metadata

  • Download URL: restic_backups-0.1.7-py3-none-any.whl
  • Upload date:
  • Size: 68.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for restic_backups-0.1.7-py3-none-any.whl
Algorithm Hash digest
SHA256 35e190836f78dd8dfd6635c0170d281a3c1b6cb4fea97f47d46cea2847e784aa
MD5 72eb67c5464f3a7dde94583917497a93
BLAKE2b-256 78f0feb9a745690b87e029f3fb89e24127b2f673c42c44b5764699808bb3376a

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page