Metadata-Version: 2.3
Name: restic-backups
Version: 0.1.4
Summary: Restic backup CLI with optional SOPS configuration.
Requires-Dist: boto3>=1.43.62
Requires-Dist: click>=8.4.2
Requires-Dist: mlx-whisper>=0.4.3 ; platform_machine == 'arm64' and sys_platform == 'darwin'
Requires-Dist: pyannote-audio>=3.4.0
Requires-Dist: pyyaml>=6.0.3
Requires-Dist: questionary>=2.1.1
Requires-Dist: requests>=2.34.2
Requires-Dist: rich>=13.9.4
Requires-Dist: textual>=0.89.1
Requires-Dist: torch>=2.13.0
Requires-Dist: torchaudio>=2.11.0
Requires-Dist: typer>=0.27.0
Requires-Python: >=3.11
Project-URL: Documentation, https://jr200-labs.github.io/restic-backups/
Project-URL: Repository, https://github.com/jr200-labs/restic-backups
Description-Content-Type: text/markdown

# Restic Backups

YAML configuration and a Python CLI for running multiple restic repositories,
with optional SOPS decryption. The package currently includes a complete macOS
Voice Memos workflow for backup, transcription, summarisation, and speaker
diarization.

## Why

Create encrypted, deduplicated **incremental backups** that upload only new or
changed data. This makes reliable off-site backups practical with
[cheaper storage options](docs/storage-costs.qmd), without maintaining a
separate backup script for every repository.

Backup payloads, generated metadata, model caches, and restores are excluded
from Git by a default-deny `.gitignore`.

## Install

```sh
make install-deps  # Homebrew: restic, sops, uv, ffmpeg, jq, coreutils
make install       # uv sync, including the dev group and Quarto
```

`make init` loads the selected configuration and initializes each enabled store
that does not already exist. It reports and skips disabled or initialized
stores, and does not back up files.

## CLI

Use the built-in help for available commands and options:

```sh
uv run restic-backups  # interactive arrow-key menu
uv run restic-backups --help
uv run restic-backups generic --help
uv run restic-backups voice-memos --help
```

The interactive menus include **Help** and **Back** at every level. Help stays
at the current level and does not load configuration or access a repository.
Generic write actions also offer a Space-toggleable **Dry run** checkbox so the
operation can be inspected without changing repository data.

Command auditing is enabled by default and appends JSON records to
`audit-log.json` in the current directory. Set `RESTIC_BACKUPS_AUDIT=0` to
disable it. Passwords and other secret-like argument values are redacted.

## Configuration

Pass a plain YAML file explicitly:

```sh
uv run restic-backups --config config.yaml check-config
```

For SOPS, add `--sops`. The equivalent environment variables are
`RESTIC_BACKUPS_CONFIG` and `RESTIC_BACKUPS_SOPS=1`; they also configure
`make config-check` and `make init`.

The configuration separates:

- `credentials`: reusable S3-compatible authentication;
- `restic-stores`: endpoint, region, bucket, key prefix/password, and optional
  cache directory and archive policy;
- `backups`: CLI selections linked to a store, local source paths, and an
  optional restic snapshot tag (defaulting to the job ID).

One credential may serve many stores, and multiple backups may share a store.
Disabled stores may contain `CHANGE_ME`; all placeholders must be replaced
before enabling one.

## Data and source paths

Managed local artifacts use:

```text
data/<store-id>/<bucket>/<key-prefix>/<job-id>/
```

This directory is created beside the selected configuration file. It is
metadata/workspace organization, not a restriction on backup sources. Restic
may back up absolute paths anywhere on the machine. Resolve a managed directory
without exposing credentials with:

```sh
uv run restic-backups generic backup data-dir voice-memos
```

## AWS Glacier

Use `GLACIER_IR` with `restore: null` for normal immediate restic access. Cold
`GLACIER` and `DEEP_ARCHIVE` stores require a configured retrieval tier, days,
and timeout. Retrieval must also be acknowledged at runtime:

```sh
ALLOW_ARCHIVE_RETRIEVAL=1 uv run restic-backups generic restic run \
  --backup <job-id> restore latest --target <dir>
```

Storage-class changes apply only to new objects. Use a new `key_prefix` instead
of mixing storage policies in one repository.

## Documentation

```sh
make docs          # render docs/_site
make docs-preview  # local preview server
```

Start with the [Quick Start](docs/quick-start.qmd). Never commit decrypted SOPS
configuration or anything below `data/`.
