Backup Strategies

Backup Strategies#

1. Backrest & Restic Google Drive Backup#

Encrypts TrueNAS/DSM network shares with Restic and stores them in Google Drive through Rclone. See Backrest & Restic Google Drive Backup Setup.

2. Proxmox PBS Backup to Google Drive#

Synchronizes the deduplicated PBS datastore from the UNAS-Pro NAS to Google Drive through MMDocker and Rclone. See Proxmox - PBS Backups via NAS with to GDrive.

3. UNAS-Pro to TrueNAS Rsync Pull Backups#

TrueNAS nodes pull shared data from UNAS-Pro on staggered hourly schedules into local ZFS datasets. See Unifi UNAS-Pro Backup Strategy.

Synology Administration Guide

Synology Administration Guide#

1 Syncthing Deployment#

1.1 Synology DSM Implementation (Docker)#

  1. Inotify Limit:
    echo "fs.inotify.max_user_watches=204800" | sudo tee -a /etc/sysctl.d/90-override.conf
    sudo sysctl -p /etc/sysctl.d/90-override.conf
  2. User IDs: Use Task Scheduler to run id > /volume1/docker/id.txt to find UID/GID (e.g., 1027/100).
  3. Docker Compose Highlights:
    environment:
      - PUID=1027
      - PGID=100
      - TZ=America/New_York
    volumes:
      - ./config:/config
      - /volume2/HP3Storage:/volume2/HP3Storage

1.2 Standard .stignore Patterns#

Create a .stignore file in the root of the sync folder:

(?i)#recycle
@eaDir
.DS_Store
.stfolder
.stignore
$RECYCLE.BIN
Thumbs.db
Desktop.ini
.SynologyWorkingDirectory

2 Storage & Maintenance Commands#

2.1 iPerf3#

sudo -i
synogear install
iperf3 -s -p 11111

2.2 Locked Folder Cleanup#

Remove Synology metadata directories when cleaning up a locked folder:

Unifi UNAS-Pro Usage Inventory Plan

Master Plan: UNAS Pro SMB Usage Inventory#

This document outlines the proposed step-by-step strategy to perform a comprehensive audit and inventory of all workloads, computers, virtual machines, Docker stacks, and scripts utilizing SMB shares from the UNAS Pro (10.1.2.2) NAS.

Active Share Matrices#

Workstations & Computers#

Server / Machine Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
MacBook Air X X X X X X X X X X X X X X X X X
MacBook Pro 15 X X X X X X X X X X X X X X X X X
MacBook Pro 16 X X X X X X X X X X X X X X X X X
iMac (MO) X X X X X X X X X X X X X X X X X

Mac Studio (10.1.2.4)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
Mac Studio (Host) X - X X X X X X X X X X X X - - -
    └─ open-webui - - - - - - - - - - - - - - - - -
    └─ portainer-agent - - - - - - - - - - - - - - - - -
    └─ cloudflared - - - - - - - - - - - - - - - - -
    └─ dockge - - - - - - - - - - - - - - - - -

MMProxmox (10.1.1.10)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
MMProxmox (Host) X - - - - - - - - - - - - - - - -
Pi-Hole (LXC 100) - - - - - - - - - - - - - - - - -
HomeAssistant (VM 200) - - - - - - - - - - - - - - - - -
MMDocker (VM 230) - OS Mounts X X - - X X X - X X X X X X - - -
    └─ Radarr - - - - - - X - - - - - - - - - -
    └─ Sonarr - - - - - - X - - - - - - - - - -
    └─ Lidarr - - - - - - X - - - - - - - - - -
    └─ qBittorrent - - - - - - X - - - - - - - - - -
    └─ Backup Sync - X - - - - - - - - - - - - - - -

HP1 Proxmox (10.1.1.11)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
HP1 Proxmox (Host) X - - - - - - - - - - - - - - - -
Pi-Hole-2 (LXC 101) - - - - - - - - - - - - - - - - -
VPSBackups (LXC 102) - - - - - - - - - - - - - - - - -
DatacenterManager (LXC 105) - - - - - - - - - - - - - - - - -
HP1TrueNAS (VM 201) - - - - - - - - - - - - - - - - -
HP1Docker (VM 202) - OS Mounts X - - X X X X - X X X X X X - - X
    └─ Backrest X - - - X X - - X X X X - - - - X
    └─ Paperless - - - X - - - - - - - - - - - - -
    └─ Paperless Sync (Cron) - - - - - X - - - - - - - - - - -
    └─ Hugo Publish (Cron) X - - - - - - - - - - - - - - - -
HP1BackupServer (VM 211) - OS Mounts X X - - - - - - - - - - - - - - -
    └─ PBS Daemon X X - - - - - - - - - - - - - - -
HP1Clouds (VM 217) - OS Mounts X - - X X X X - X X X X X X - - -
    └─ Nextcloud AIO X - - X X X X - X X X X X X - - -
    └─ Owncloud Server X - - X X X X - X X X X X X - - -
    └─ File Indexer (Cron) X - - X X X X - X X X X X X - - -
HP1SynologyDSM (VM 221) - - - - - - - - - - - - - - - - -
HP1GPU (VM 231) - OS Mounts X - - - X X X - X X X X X X - - -
    └─ Immich Server - - - - - - - - X - - X - - - - -
    └─ Emby - - - - - - X - - X - - X X - - -
    └─ Plex - - - - - - X - - X - X X X - - -
    └─ Navidrome - - - - - - - - - X - - - - - - -

Scripts & Automations#

Script / Automation Hook Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
Git Hook: post-commit X - - - - - - - - - - - - - - - -
proxmox_backup.sh X - - - - - - - - - - - - - - - -
HP1_UNAS_Pull_Backup.sh X - - - X X X X X X X X - - - - X
HP2_UNAS_Pull_Backup.sh X - - - X X - - X X X X - - - - X
HP3_UNAS_Pull_Backup.sh - - - - - - - - - - - - X X - - -
HP7_UNAS_Pull_Backup.sh X - - - X X - X X X X X - - - - X
HP8_UNAS_Pull_Backup.sh X - - - X X - X X X X X X X - - X

Target Inventory Scope#

The inventory will discover and map every dependency on the UNAS Pro SMB shares across four distinct layers:

UniFi UNAS-Pro Pool Migration Strategy

UniFi UNAS-Pro Pool Migration Strategy: Pool 1 (SSD) to Pool 2 (HDD)#

This document defines the operational plan, safety protocols, database update queries, and verification steps to migrate all shared folders from Storage Pool 1 (SSD - Degraded RAID5) to Storage Pool 2 (HDD - Healthy RAID5) on the master UniFi UNAS-Pro NAS (10.1.2.2) while preserving all access rights, Samba configurations, and TrueNAS backup operations.

Antigravity chat: agy –conversation=3dd15667-3c79-485d-af10-ebb5c4f9cc01


1. Executive Summary & Objective#

Due to hardware failures on Pool 1 (Slot 2 pulled, Slot 3 accumulating 75,000+ write failures), Pool 1 is operating with zero fault tolerance. To prevent data loss prior to receiving warranty replacement drives, all active shares on Pool 1 will be migrated to Pool 2.

Unifi UNAS-Pro Backup Strategy

UniFi UNAS-Pro Master Backup Strategy: Native Rsync Daemon (Pull) Architecture#

This document defines the complete operational standard, architecture, schedule matrix, node-by-node configuration reference, and disaster recovery procedures for backing up all shared data from the master UniFi UNAS-Pro NAS (10.1.2.2) across the fleet of 5 TrueNAS SCALE storage nodes (HP1, HP2, HP3, HP7, HP8). It is designed to be sufficient to fully reconstruct the entire setup from scratch.

Antigravity Chat: agy –conversation=4c0c9b6d-2722-4fd6-a4aa-638c75ab46f4

Unifi UNAS-Pro Backup Migration Plan

UNAS-Pro Backup Migration Plan: SMB (Push) to Native Rsync Daemon (Pull)#

Antigravity Chat: agy –conversation=4c0c9b6d-2722-4fd6-a4aa-638c75ab46f4

This document is the complete master migration plan for transitioning the UNAS-Pro backup strategy from the UniFi Drive UI-managed SMB (Push) setup to a Native Rsync Daemon (Pull) model.

Because the UniFi Drive UI natively supports Rsync server settings and shared folder modules, migrating to Rsync requires configuring your TrueNAS SCALE servers (HP1, HP2, HP3, HP7, HP8) to pull the backups directly from the UNAS-Pro Rsync daemon over TCP port 873.

Proxmox Backup Server - Mounting an SMB NAS Share as a PBS Datastore

Proxmox Backup Server - Mounting an SMB NAS Share as a PBS Datastore#

This note outlines the step-by-step process used to mount a remote SMB/Samba share from a NAS onto a Proxmox Backup Server (PBS) host at the OS level, assign proper permissions for the PBS daemon, and initialize it as a new backup datastore.

Prerequisites#

  • A target share on the NAS (e.g., //10.1.2.2/ProxmoxBackups).
  • An existing SMB credentials file on the PBS host (e.g., /root/.smb_credentials).

Step-by-Step Implementation#

Step 1: Create the Local Mount Directory#

Create a dedicated folder at the root of the PBS host filesystem where the network share will be attached.

Backrest & Restic Google Drive Backup Setup

NAS Backup Pipeline: Backrest, Restic & Google Drive#

Complete configuration guide for backing up isolated TrueNAS/DSM network shares from the headless Ubuntu VM (HP1Docker) to an encrypted Google Drive repository using Backrest (a Web UI wrapper for Restic) and Rclone. For baseline Rclone installation, remote management, and CLI commands, see the RClone Guide.


1. System Architecture Overview#

  • Source Data: 8 explicit network shares mounted via CIFS/SMB on the host VM at /mnt/<ShareName>.
  • Backup Host: Ubuntu VM (HP1Docker - 10.1.2.202).
  • Backup Agent: Backrest Docker Container running Restic 0.18.1.
  • Target Backend: Google Drive (proxmox.app@gmail.com) via a dedicated Rclone remote.
  • Security Model: Client-side, zero-knowledge encryption via a dedicated repository password before data leaves the local host.
  • Rate-Limit Protections: Powered by a custom Google Cloud Project ID to bypass global multi-user API query restrictions during multi-terabyte data transfers.

2. Directory Structure Setup#

All configuration and container runtime files are centralized on the host under the user deployment directory.

Fstab - Disk Passthrough

Proxmox Disk Passthrough Guide#


1. Discovery Commands#

Use these commands to identify physical disks on the Proxmox host.

# Install hardware lister
apt install lshw

# List disks and storage controllers
lshw -class disk -class storage

# List all Physical Disk IDs (The ID needed for passthrough)
ls -l /dev/disk/by-id/

# Advanced list: Maps Device to ID and filters out partitions/LVM
lsblk |awk 'NR==1{print $0" DEVICE-ID(S)"}NR>1{dev=$1;printf $0" ";system("find /dev/disk/by-id -lname \"*"dev"\" -printf \" %p\"");print "";}'|grep -v -E 'part|lvm'

2. Configuration Requirements#

Adding Serials (Crucial for TrueNAS/ZFS)#

In TrueNAS manually edit the VM config file to ensure disk serials persist:

TrueNAS Administration Guide

TrueNAS Administration Guide#

The complete UNAS-Pro backup architecture, schedules, TrueNAS node configuration, and recovery procedures are documented in Unifi UNAS-Pro Backup Strategy.


1. TrueNAS Scale: Initial Setup & Security#

Virtual Machine Configuration (Proxmox)#

  • Initial Setup: Create the VM. Add a second virtual disk (10GB) for apps and home directories.
  • Post-Login: Verify the Time Zone is accurate.
  • Duplicate Serial Error: If Proxmox reports Disks have duplicate serial numbers, add serials manually in the PVE host:
    nano /etc/pve/qemu-server/212.conf
    # Add serial strings:
    scsi0: Storage:vm-212-disk-0,discard=on,size=32G,ssd=1,serial=PROX-001
    scsi1: Storage:vm-212-disk-1,discard=on,size=1G,ssd=1,serial=PROX-002

Datasets & Users#

  1. Datasets: Create HP3-10Gb-Apps-HomeDirs. Add sub-datasets Apps (Type: Apps) and HomeDirs (Type: Generic).
  2. Standard User: Create user marc for SMB shares.
  3. Sync User: Create backupuser. Set a home directory, uncheck Samba authentication, and do not set a password.
  4. Admin Hardening: - Create user marcoue with full admin rights.
    • Upload SSH keys and enable 2FA for marcoue.
    • Disable the default truenas_admin account once verified.

SSH Hardening#

sudo nano /etc/ssh/sshd_config
# Modify/Add:
PermitRootLogin prohibit-password
PubkeyAuthentication yes

sudo systemctl restart sshd
  • Services: Go to System > Services > SSH and disable “Allow Password Authentication.”

2. System & Networking Optimization#

Startup Scripts & Cron#

  • Cron Shutdown: (System Settings > Advanced)
    • Command: /sbin/shutdown -h now
  • Init Scripts: (Post Init)
    • Command: iperf3 -s -d
  • Session Timeout: (Access > Configure) Set to 2147482.

Host Identification & Email#

  • Hostname/NetBIOS: Set to HP2TrueNAS.
  • Gmail OAuth/SMTP: - Use OAuth login if available.
    • SMTP: smtp.gmail.com | Port: 25 or 587.
    • Use an App Password from 1Password.

3. Data Protection & Replication#

Periodic Snapshots (Source)#

  • Path: Data Protection > Periodic Snapshot Tasks.
  • Settings: Uncheck “Recursive” (unless needed). Uncheck “Taking Empty Snapshot.”
  • Schedule: Daily at 08:30, retention 7 days.

Replication Task (Remote Server Pull)#

  1. Source: Different System.
  2. Connection: New SSH (Semi-Auto).
  3. Settings: Admin: marcoue, User: backupuser. Enable passwordless sudo.
  4. ZFS Commands: Check “Use Sudo for ZFS Commands.”
  5. Schedule: Every hour at 08:45.

4. Syncthing Deployment#

TrueNAS Scale Implementation#

  1. System Settings > Advanced > Sysctl:
    • Var: fs.inotify.max_user_watches | Value: 524288.
  2. Apps > Advanced: Disable “Host Path Safety Check.”
  3. App Setup: Install Enterprise Version. Use Host Path for storage (e.g., /mnt/HP1-4TBSSD-Raid0/HP1Storage).

5. Hardware-Specific Configurations#

Mac Pro Auto-Restart (After Power Outage)#

cd /sys/bus/pci/devices/0000:00:1f.0
sudo chmod -R 777 config
setpci -s 0:1f.0 0xa4.b=0

Wake-on-LAN (WOL) Persistence#

Create a systemd service to ensure WOL stays active: