Skip to content

Scheduling

A configuration backup is useful only if it is recent: schedule it on the machine that keeps the archives. Put the connection in an options file, so the schedule stays short and the password or key path is not in the task definition.

/etc/cv4pve/nodes.rsp (chmod 600)
--host=pve01,pve02,pve03
--username=root
--private-key-file=/root/.ssh/node-protect

Use the full path of the binary (command -v cv4pve-node-protect shows it) and create the folders first. One folder per schedule keeps daily, weekly and monthly copies apart, each with its own --keep:

/etc/cron.d/cv4pve-node-protect
PATHS=/etc/.;/etc/pve/.;/var/lib/pve-cluster/.;/var/spool/cron/crontabs;/root/.ssh
# every day at 03:00, one week
0 3 * * * root /usr/local/bin/cv4pve-node-protect @/etc/cv4pve/nodes.rsp backup --paths="$PATHS" --directory-work=/srv/node-protect/daily --keep=7 >> /var/log/cv4pve-node-protect.log 2>&1 || logger -t cv4pve-node-protect "backup failed"
# every Sunday at 04:00, four weeks
0 4 * * 0 root /usr/local/bin/cv4pve-node-protect @/etc/cv4pve/nodes.rsp backup --paths="$PATHS" --directory-work=/srv/node-protect/weekly --keep=4 >> /var/log/cv4pve-node-protect.log 2>&1 || logger -t cv4pve-node-protect "backup failed"
# the 1st of the month at 05:00, one year
0 5 1 * * root /usr/local/bin/cv4pve-node-protect @/etc/cv4pve/nodes.rsp backup --paths="$PATHS" --directory-work=/srv/node-protect/monthly --keep=12 >> /var/log/cv4pve-node-protect.log 2>&1 || logger -t cv4pve-node-protect "backup failed"

Assigning PATHS on its own line is a feature of cron’s /etc/cron.d files. A cron line must fit on one line.

A run where a node fails exits with code 1 and applies no retention: while a node stays down, dated folders pile up (see When a run fails). Watch the exit code (the || logger above writes a line to the system log, your monitoring can do better) and the warnings in the log: a path that disappeared does not make the run fail.