diff --git a/docs/CHANGELOG.md b/docs/CHANGELOG.md index 954b774b..b8f2f235 100644 --- a/docs/CHANGELOG.md +++ b/docs/CHANGELOG.md @@ -1,5 +1,12 @@ # Changelog +## 2026-09-29 + +- **Separated Restic backup repositories per host**: + - Updated `services.restic.backups.default.repository` in `platforms/nixos/modules/nmasur/presets/services/restic/restic.nix` to append `/${config.networking.hostName}`, isolating backups by host in S3 (e.g., `.../restic/flame` and `.../restic/swan`). + - Enabled `services.restic.backups.default.initialize = true` to automatically initialize the repository in S3 if it does not already exist. + - Resolves exclusive lock contention during post-backup `forget --prune` when multiple servers run scheduled backups in overlapping windows. + ## 2026-09-19 - **Fixed missing user attribute and deprecations during flake check**: diff --git a/platforms/nixos/modules/nmasur/presets/services/restic/restic.nix b/platforms/nixos/modules/nmasur/presets/services/restic/restic.nix index c3d498db..4d58d2dc 100644 --- a/platforms/nixos/modules/nmasur/presets/services/restic/restic.nix +++ b/platforms/nixos/modules/nmasur/presets/services/restic/restic.nix @@ -44,7 +44,8 @@ in services.restic.backups = { default = { - repository = "s3:${cfg.s3.endpoint}/${cfg.s3.bucket}/restic"; + repository = "s3:${cfg.s3.endpoint}/${cfg.s3.bucket}/restic/${config.networking.hostName}"; + initialize = true; paths = [ ]; environmentFile = config.secrets.restic-s3-creds.dest; passwordFile = config.secrets.restic.dest;