Metadata-Version: 2.3
Name: restic-backups
Version: 0.1.5
Summary: Restic backup CLI with optional SOPS configuration.
Requires-Dist: boto3>=1.43.62
Requires-Dist: click>=8.4.2
Requires-Dist: mlx-whisper>=0.4.3 ; platform_machine == 'arm64' and sys_platform == 'darwin'
Requires-Dist: pyannote-audio>=3.4.0
Requires-Dist: pyyaml>=6.0.3
Requires-Dist: questionary>=2.1.1
Requires-Dist: requests>=2.34.2
Requires-Dist: rich>=13.9.4
Requires-Dist: textual>=0.89.1
Requires-Dist: torch>=2.13.0
Requires-Dist: torchaudio>=2.11.0
Requires-Dist: typer>=0.27.0
Requires-Python: >=3.11
Project-URL: Documentation, https://jr200-labs.github.io/restic-backups/
Project-URL: Repository, https://github.com/jr200-labs/restic-backups
Description-Content-Type: text/markdown

# Restic Backups

YAML configuration and a Python CLI for running multiple restic repositories,
with optional SOPS decryption. The package currently includes a complete macOS
Voice Memos workflow for backup, transcription, summarisation, and speaker
diarization.

## Why

Create encrypted, deduplicated **incremental backups** that upload only new or
changed data. This makes reliable off-site backups practical with
[cheaper storage options](docs/storage-costs.qmd), without maintaining a
separate backup script for every repository.

Backup payloads, generated metadata, model caches, and restores are excluded
from Git by a default-deny `.gitignore`.

## Install

```sh
make install-deps  # Homebrew: restic, sops, uv, ffmpeg, jq, coreutils
make install       # uv sync, including the dev group and Quarto
```

`make init` loads the selected configuration and initializes each enabled restic
repository that does not already exist. It reports and skips disabled or
initialized repositories, and does not back up files.

## CLI

Use the built-in help for available commands and options:

```sh
uv run restic-backups  # interactive arrow-key menu
uv run restic-backups --help
uv run restic-backups generic --help
uv run restic-backups voice-memos --help
```

The interactive menus include **Help** and **Back** at every level. Press
Escape to go back or Ctrl+C to exit. Help stays at the current level and does
not load configuration or access a repository.
Generic write actions also offer a Space-toggleable **Dry run** checkbox so the
operation can be inspected without changing repository data.

Command auditing is enabled by default and appends JSON records to
`audit-log.json` in the current directory. Set `RESTIC_BACKUPS_AUDIT=0` to
disable it. Passwords and other secret-like argument values are redacted.

## Configuration

Pass a plain YAML file explicitly:

```sh
uv run restic-backups --config config.yaml check-config
```

For SOPS, add `--sops`. The equivalent environment variables are
`RESTIC_BACKUPS_CONFIG` and `RESTIC_BACKUPS_SOPS=1`; they also configure
`make config-check` and `make init`.

The configuration separates:

- `storage`: S3-compatible services and mounted local filesystems, with S3
  credentials kept on the relevant storage entry;
- `restic-repositories`: encrypted repositories within storage, including the
  bucket/key prefix or local path, restic password, cache, and archive policy;
- `backups`: jobs linked to a restic repository, local source paths, and an
  optional snapshot tag (defaulting to the job ID).

Multiple restic repositories may use one storage backend, and multiple backup
jobs may share one restic repository. Disabled repositories may contain
`CHANGE_ME`; all placeholders must be replaced before enabling one.

## Data and source paths

Managed local artifacts use:

```text
data/<storage-id>/<repository-path>/<job-id>/
```

This directory is created beside the selected configuration file. It is
metadata/workspace organization, not a restriction on backup sources. Restic
may back up absolute paths anywhere on the machine. Resolve a managed directory
without exposing credentials with:

```sh
uv run restic-backups generic backup data-dir voice-memos
```

## AWS Glacier

Use `GLACIER_IR` with `restore: null` for normal immediate restic access. Cold
`GLACIER` and `DEEP_ARCHIVE` repositories require a configured retrieval tier,
days, and timeout. Retrieval must also be acknowledged at runtime:

```sh
ALLOW_ARCHIVE_RETRIEVAL=1 uv run restic-backups generic restic run \
  --backup <job-id> restore latest --target <dir>
```

Storage-class changes apply only to new objects. Use a new `key_prefix` instead
of mixing storage policies in one repository.

## Documentation

```sh
make docs          # render docs/_site
make docs-preview  # local preview server
```

Start with the [Quick Start](docs/quick-start.qmd). Never commit decrypted SOPS
configuration or anything below `data/`.
