Scheduling
A configuration backup is useful only if it is recent: schedule it on the machine that keeps the archives. Put the connection in an options file, so the schedule stays short and the password or key path is not in the task definition.
--host=pve01,pve02,pve03--username=root--private-key-file=/root/.ssh/node-protectUse the full path of the binary (command -v cv4pve-node-protect shows it) and create the folders
first. One folder per schedule keeps daily, weekly and monthly copies apart, each with its own
--keep:
PATHS=/etc/.;/etc/pve/.;/var/lib/pve-cluster/.;/var/spool/cron/crontabs;/root/.ssh
# every day at 03:00, one week0 3 * * * root /usr/local/bin/cv4pve-node-protect @/etc/cv4pve/nodes.rsp backup --paths="$PATHS" --directory-work=/srv/node-protect/daily --keep=7 >> /var/log/cv4pve-node-protect.log 2>&1 || logger -t cv4pve-node-protect "backup failed"
# every Sunday at 04:00, four weeks0 4 * * 0 root /usr/local/bin/cv4pve-node-protect @/etc/cv4pve/nodes.rsp backup --paths="$PATHS" --directory-work=/srv/node-protect/weekly --keep=4 >> /var/log/cv4pve-node-protect.log 2>&1 || logger -t cv4pve-node-protect "backup failed"
# the 1st of the month at 05:00, one year0 5 1 * * root /usr/local/bin/cv4pve-node-protect @/etc/cv4pve/nodes.rsp backup --paths="$PATHS" --directory-work=/srv/node-protect/monthly --keep=12 >> /var/log/cv4pve-node-protect.log 2>&1 || logger -t cv4pve-node-protect "backup failed"Assigning PATHS on its own line is a feature of cron’s /etc/cron.d files. A cron line must fit on
one line.
In PowerShell, as administrator:
$exe = (Get-Command cv4pve-node-protect).Source$arguments = '@C:\cv4pve\nodes.rsp backup --paths="/etc/.;/etc/pve/.;/var/lib/pve-cluster/." ' + '--directory-work=D:\node-protect\daily --keep=7'
$action = New-ScheduledTaskAction -Execute $exe -Argument $arguments$trigger = New-ScheduledTaskTrigger -Daily -At 3amRegister-ScheduledTask -TaskName 'cv4pve-node-protect daily' -Action $action -Trigger $trigger ` -User 'NT AUTHORITY\SYSTEM'The task runs as SYSTEM, also when nobody is logged on: the options file and the key must be
readable by it, and D:\node-protect should not be readable by other users. Task Scheduler shows the
exit code of each run as Last Run Result: 0x1 means the run failed.
Notice failures
Section titled “Notice failures”A run where a node fails exits with code 1 and applies no retention: while a node stays down,
dated folders pile up (see When a run fails). Watch the exit code (the
|| logger above writes a line to the system log, your monitoring can do better) and the warnings in
the log: a path that disappeared does not make the run fail.