• darntootin@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 hours ago

    I wouldn’t trust Dropbox, ever. I backup to Proton, but use Cryptomator to encrypt everything first.

  • MalReynolds@slrpnk.net
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    4 hours ago

    If you encrypt at home it doesn’t matter where you do offsite. See Cryptomator for an easy platform agnostic approach. Why trust the bastards?

    Ah, should have updooted darntootin, oh well. Still, OP, a bit more detail (like I encrypt with rclone, would have been nice.) Cool. Got my own system, but anything that helps…

    • Taasz/Woof@piefed.social
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      4 hours ago

      Restic is a good backup tool with encryption. Cryptomator is awesome but it doesn’t do backups, just storage.

      • MalReynolds@slrpnk.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        3 hours ago

        Completely correct. It’s a useful tool for people protecting their precious memories, not an ongoing protection of an OS state.

    • Sam@toot.ioOP
      link
      fedilink
      arrow-up
      0
      ·
      4 hours ago

      @MalReynolds Rclone can encrypt, but I also like to have another avenue to access my documents in case for some reason I can’t accessy homelab.

      • MalReynolds@slrpnk.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        4 hours ago

        Cryptomator has an android app, haven’t used it in anger (It’s not a backup until you restore successfully), but it’s there.

  • lokalhorst@feddit.org
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    1
    ·
    7 hours ago

    I use restic to backup my paperless documents to a Hetzner Storage Box. The setup was easy and I am independent of US cloud hosters.

    • Sam@toot.ioOP
      link
      fedilink
      arrow-up
      0
      ·
      5 hours ago

      @lokalhorst As I mentioned in the post, this method can be used to back up to many different providers (incl. hetzner, see https://rclone.org/docs/). I assume w/ restic you’re just backing up the folder where paperless stores the docs rather than the export. IMO the latter is nice because leaves you w/ something that’s more useful w/o paperless.

      • lokalhorst@feddit.org
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 hours ago

        I actually use the document_exporter of paperless-ngx. I have a small bash script backup-paperless.sh that runs the paperless-ngx document_exporter and also makes a database dump using pg_dump. It sets up the restic backups logic with daily, weekly and monthly backups. I run that bash script using a systemd service paperless-backup.service. This service is run daily with the timer paperless-backup.timer, randomly at 3 am ±30 minutes. restic is smart, so it does only backup if there are changes. The incremental backups are great, in case the database corrupts without me noticing. I’ll share the scripts in case you are interested in how it works:

        backup-paperless.sh

        #!/bin/bash
        set -euo pipefail
        
        COMPOSE_DIR="/home/user/paperless-ngx/"
        DUMP_DIR="$COMPOSE_DIR/sqldump"
        EXPORT_DIR="/usr/src/paperless/export"
        
        export RESTIC_REPOSITORY="sftp:abc123@abc123.your-storagebox.de:/backup/restic"
        export RESTIC_PASSWORD_FILE="/home/user/.config/restic/password"
        
        mkdir -p "$DUMP_DIR"
        
        cd "$COMPOSE_DIR"
        docker compose exec -T webserver document_exporter "$EXPORT_DIR" -p
        docker compose exec -T db pg_dump -U paperless paperless > "$DUMP_DIR/dump.sql"
        
        
        
        restic backup "$DUMP_DIR" "$COMPOSE_DIR/export"
        
        restic forget \
        	--keep-daily 7 \
        	--keep-weekly 4 \
        	--keep-monthly 6 \
        	--prune
        
        rm -rf "$COMPOSE_DIR/export"/*
        rm -rf "$DUMP_DIR"/*
        

        paperless-backup.service

        [Unit]
        Description=Paperless-ngx Restic Backup
        Wants=network-online.target
        After=network-online.target docker.service
        
        [Service]
        Type=oneshot
        User=user
        WorkingDirectory=/home/user/paperless-ngx
        ExecStart=/home/user/paperless-ngx/backup-paperless.sh
        

        paperless-backup.timer

        [Unit]
        Description=Run paperless backup every 24 hours
        
        [Timer]
        OnCalendar=*-*-* 03:00:00
        Persistent=true
        RandomizedDelaySec=30min
        
        [Install]
        WantedBy=timers.target
        
  • Taasz/Woof@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    4 hours ago

    How are you handling versioning and deleted files?

    It seems like Restic would be a better option? It only backs up changed files and handles versioning, encryption, deduplication, and some fault recovery allready. You wouldn’t need all of the other layers like the export script and float.