Home / Support / Oracle Cloud Marketplace / restic
In Oracle reviewA hardened, CVE-patched virtual machine image that makes an Oracle Cloud Infrastructure instance a backup server for restic, the open-source, deduplicating backup program with end-to-end encryption: rest-server 0.14 (the restic project's HTTP backend) with the restic 0.19 client alongside, on Oracle Linux 9.
| Status | Submitted for Oracle certification review |
|---|---|
| Version | 0.14.0 |
| Platform | Oracle Linux 9 |
| Ports open in the host firewall | SSH (22/tcp), 8000/tcp |
| Category | Storage |
| Upstream licence | BSD-2-Clause |
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
ssh opc@PUBLIC_IPsudo systemctl status restic-server-firstboot restic-serversudo cat /root/.restic-server_default_credentialsrestic -r rest:https://backup:PASSWORD@127.0.0.1:8000/backup/ --cacert /etc/restic-server/tls/cert.pem init
restic -r rest:https://backup:PASSWORD@127.0.0.1:8000/backup/ --cacert /etc/restic-server/tls/cert.pem backup /usr/share/doc/restic-server
restic -r rest:https://backup:PASSWORD@127.0.0.1:8000/backup/ --cacert /etc/restic-server/tls/cert.pem snapshotssudo sed -i 's/^REST_SERVER_LISTEN=127.0.0.1:8000$/REST_SERVER_LISTEN=0.0.0.0:8000/' /etc/restic-server/restic-server.env && sudo systemctl restart restic-serverEach host copies /etc/restic-server/tls/cert.pem (its SAN lists the private IPs) and uses rest:https://USER:PASSWORD@PRIVATE_IP:8000/USER/ with --cacert. For a public IP or DNS name, re-issue the certificate with it:
sudo /usr/local/sbin/restic-server-cert NAME_OR_IPPort 8000 is already permitted in the host firewall. Restrict it in your VCN security list to the CIDRs of the hosts you back up; never expose it to the internet.
sudo htpasswd -B -C 10 /etc/restic-server/htpasswd HOST_NAMERansomware-resistant mode: clients can add backups but never delete or overwrite them, so retention runs here, as the service user, with the repository password:
sudo sed -i 's/^REST_SERVER_EXTRA_FLAGS=$/REST_SERVER_EXTRA_FLAGS=--append-only/' /etc/restic-server/restic-server.env && sudo systemctl restart restic-server
sudo -u restic-server /usr/local/bin/restic --no-cache -r /var/lib/restic-server/USER forget --keep-daily 14 --pruneexport AWS_ACCESS_KEY_ID=ACCESS_KEY AWS_SECRET_ACCESS_KEY=SECRET_KEY AWS_DEFAULT_REGION=REGION RESTIC_REPOSITORY=s3:https://NAMESPACE.compat.objectstorage.REGION.oraclecloud.com/BUCKET/USER
runuser -u restic-server -- /usr/local/bin/restic --no-cache init --from-repo /var/lib/restic-server/USER --copy-chunker-params
runuser -u restic-server -- /usr/local/bin/restic --no-cache copy --from-repo /var/lib/restic-server/USERThe image is CVE-patched at build time. Apply ongoing operating system updates with:
sudo dnf -y update
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.