back up Gitea + Skudak app data; drop PartKeepr and Pi-hole

Extends the Nextcloud backup machinery rather than adding a second
mechanism. cloud-backup.sh.j2 gains three guarded options, all no-ops for
the existing callers:

  backup_podman_user  Gitea runs rootless under `git`, not `podman`
  backup_db_type      postgres (Gitea) and mysql (BookStack) alongside
                      mariadb; each engine's completion trailer differs,
                      and grepping for the wrong one fails every run
  backup_sqlite_dbs   `sqlite3 .backup` for live WAL-mode SQLite, gated on
                      `pragma integrity_check` before promotion -- rsync
                      is either stale (no -wal) or torn (with it)

New instances: gitea-debyl, skudak-gitea, bookstack, partsy-skudak. The
alert handler is rendered once and shared, so its wording is now generic
rather than per-product; TAG stays nextcloud-backup because an external
Graylog rule matches on it.

`apply:` on the includes is load-bearing -- tags on a dynamic
include_tasks do not reach the tasks inside it.

Business data (skudak-gitea, bookstack, partsy-skudak) goes to TrueNAS
and on to Skudak's own iDrive account; the personal bucket's
/skudak*/** excludes are permanent, not a stopgap.

Removals: PartKeepr is superseded by Partsy, and its teardown never
finished -- it targeted /etc/systemd/system/podman-partkeepr*.service,
wrong prefix and wrong scope, leaving enabled user units in failed state.
Pi-hole's role was already orphaned (absent from deploy_home.yml); its
port 53 rule went with it after confirming nothing listens there.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Bastian de Byl
2026-07-30 18:08:47 -04:00
parent a63bf5edec
commit bc110ce69e
15 changed files with 236 additions and 129 deletions
@@ -1,59 +0,0 @@
---
# PartKeepr has been replaced by Partsy
# This playbook removes PartKeepr containers and services
# Keeping MySQL data volume for historical reference only
- name: stop and remove partkeepr container
become: true
become_user: "{{ podman_user }}"
containers.podman.podman_container:
name: partkeepr
state: absent
- name: stop and remove partkeepr-db container
become: true
become_user: "{{ podman_user }}"
containers.podman.podman_container:
name: partkeepr-db
state: absent
- name: remove systemd service for partkeepr
become: true
ansible.builtin.systemd:
name: "podman-partkeepr.service"
state: stopped
enabled: false
daemon_reload: true
ignore_errors: true
- name: remove systemd service for partkeepr-db
become: true
ansible.builtin.systemd:
name: "podman-partkeepr-db.service"
state: stopped
enabled: false
daemon_reload: true
ignore_errors: true
- name: remove systemd service files for partkeepr
become: true
ansible.builtin.file:
path: "{{ item }}"
state: absent
loop:
- "/etc/systemd/system/podman-partkeepr.service"
- "/etc/systemd/system/podman-partkeepr-db.service"
notify: systemd daemon-reload
- name: preserve partkeepr mysql data volume for history
become: true
ansible.builtin.file:
path: "{{ partkeepr_path }}/mysql"
state: directory
owner: "{{ podman_subuid.stdout }}"
group: "{{ podman_user }}"
mode: 0755
notify: restorecon podman
- name: flush handlers
ansible.builtin.meta: flush_handlers