Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / restic

In Oracle review

DCA Hardened Backup Server for restic — Support & Quick Start

A hardened, CVE-patched virtual machine image that makes an Oracle Cloud Infrastructure instance a backup server for restic, the open-source, deduplicating backup program with end-to-end encryption: rest-server 0.14 (the restic project's HTTP backend) with the restic 0.19 client alongside, on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version0.14.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8000/tcp
CategoryStorage
Upstream licenceBSD-2-Clause
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. On first boot the image generates an instance-unique TLS certificate and a backup user with a random password, proves them against the server, then starts rest-server (HTTPS only, authentication on, private repositories). Check both units:
    sudo systemctl status restic-server-firstboot restic-server
  3. Read the generated user, password and certificate fingerprint (root only):
    sudo cat /root/.restic-server_default_credentials
  4. Try it with the restic client installed here, replacing PASSWORD with the generated one. restic asks you to choose a repository password; it encrypts your data before it leaves the client, so the server never sees it, and losing it loses the data:
    restic -r rest:https://backup:PASSWORD@127.0.0.1:8000/backup/ --cacert /etc/restic-server/tls/cert.pem init
    restic -r rest:https://backup:PASSWORD@127.0.0.1:8000/backup/ --cacert /etc/restic-server/tls/cert.pem backup /usr/share/doc/restic-server
    restic -r rest:https://backup:PASSWORD@127.0.0.1:8000/backup/ --cacert /etc/restic-server/tls/cert.pem snapshots
  5. The server listens on 127.0.0.1:8000 as shipped. To take backups from your hosts, rebind and restart:
    sudo sed -i 's/^REST_SERVER_LISTEN=127.0.0.1:8000$/REST_SERVER_LISTEN=0.0.0.0:8000/' /etc/restic-server/restic-server.env && sudo systemctl restart restic-server

    Each host copies /etc/restic-server/tls/cert.pem (its SAN lists the private IPs) and uses rest:https://USER:PASSWORD@PRIVATE_IP:8000/USER/ with --cacert. For a public IP or DNS name, re-issue the certificate with it:

    sudo /usr/local/sbin/restic-server-cert NAME_OR_IP

    Port 8000 is already permitted in the host firewall. Restrict it in your VCN security list to the CIDRs of the hosts you back up; never expose it to the internet.

  6. Give every host its own user; each user reaches only its own /USER/ path (changes apply within 30 seconds, or at once with sudo systemctl reload restic-server):
    sudo htpasswd -B -C 10 /etc/restic-server/htpasswd HOST_NAME

    Ransomware-resistant mode: clients can add backups but never delete or overwrite them, so retention runs here, as the service user, with the repository password:

    sudo sed -i 's/^REST_SERVER_EXTRA_FLAGS=$/REST_SERVER_EXTRA_FLAGS=--append-only/' /etc/restic-server/restic-server.env && sudo systemctl restart restic-server
    sudo -u restic-server /usr/local/bin/restic --no-cache -r /var/lib/restic-server/USER forget --keep-daily 14 --prune
  7. Repositories live in /var/lib/restic-server; attach a block volume there before production use. Optional off-site copy to OCI Object Storage over its S3-compatible API: create a bucket and a Customer Secret Key, open a root shell (sudo -i) and run the lines below; restic asks for both repository passwords, and later copy runs send only new snapshots:
    export AWS_ACCESS_KEY_ID=ACCESS_KEY AWS_SECRET_ACCESS_KEY=SECRET_KEY AWS_DEFAULT_REGION=REGION RESTIC_REPOSITORY=s3:https://NAMESPACE.compat.objectstorage.REGION.oraclecloud.com/BUCKET/USER
    runuser -u restic-server -- /usr/local/bin/restic --no-cache init --from-repo /var/lib/restic-server/USER --copy-chunker-params
    runuser -u restic-server -- /usr/local/bin/restic --no-cache copy --from-repo /var/lib/restic-server/USER

The image is CVE-patched at build time. Apply ongoing operating system updates with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.