Skip to content

📸 Backrest: Immich Offsite Backup & Hetzner Storage Box ​

This document details the automated offsite backup pipeline for the Immich photo library using Backrest (a modern Web UI and orchestrator for Restic) backed by a 1TB Hetzner Storage Box BX11.


🏛️ Architecture Overview ​

The backup architecture provides encrypted, deduplicated offsite backups with automated health monitoring and multi-stage lifecycle maintenance:


⚙️ Service & Runtime Configuration ​

  • Host Container: LXC 131 (docker-media on PVE-1, IP 192.168.0.131)
  • Runtime User: admin-ssh (UID 1001 on LXC 131)
  • Application Version: Backrest v1.13.0
  • Configuration File: /home/admin-ssh/.config/backrest/config.json
  • Data & State Directory: /home/admin-ssh/.local/share/backrest
  • Web UI Auth: Authenticated user rayman (Port 9898)

🗄️ Repository Specification (immich-hetzner-bx11) ​

ParameterValueDescription
Repository IDimmich-hetzner-bx11Primary offsite photo repository
Target URIsftp:hetzner-immich-storagebox:immich-resticHetzner Storage Box BX11 (1TB) via SFTP
Connection Flags--option=sftp.args='-oBatchMode=yes'Non-interactive SSH key authentication
EncryptionEnabled (Restic AES-256)Client-side encrypted before transfer

Maintenance & Retention Policies: ​

json
{
  "forgetPolicy": {
    "schedule": { "cron": "0 6 * * *", "clock": "CLOCK_LOCAL" },
    "retention": {
      "policyTimeBucketed": {
        "hourly": 24,
        "daily": 14,
        "weekly": 8,
        "monthly": 6,
        "yearly": 1,
        "keepLastN": 7
      }
    }
  },
  "prunePolicy": {
    "schedule": { "cron": "0 4 1 * *", "clock": "CLOCK_LOCAL" },
    "maxUnusedPercent": 10
  },
  "checkPolicy": {
    "schedule": { "cron": "0 5 2 * *", "clock": "CLOCK_LOCAL" },
    "readDataSubsetPercent": 5
  }
}
  • Daily Forget (0 6 * * *): Cleans up old snapshots daily at 06:00 AM preserving 24 hourly, 14 daily, 8 weekly, 6 monthly, and 1 yearly snapshots.
  • Monthly Prune (0 4 1 * *): Repacks repository on the 1st of every month at 04:00 AM if unreferenced data exceeds 10%.
  • Monthly Integrity Check (0 5 2 * *): Validates repository structure and verifies a 5% random subset of data blocks on the 2nd of each month at 05:00 AM.

📋 Backup Plan (immich-photos) ​

  • Plan ID: immich-photos
  • Target Repository: immich-hetzner-bx11
  • Source Path: /mnt/media_root/media/photos
  • Schedule: 1 1 * * * (Daily at 01:01 AM local time)
  • Exclusions (iexcludes):
    • thumbs/** (Omits pre-generated UI image thumbnails)
    • encoded-video/** (Omits temporary/transcoded streaming video copies)

    TIP

    Excluding thumbnails and transcoded video streams saves gigabytes of cloud bandwidth and storage space while ensuring 100% of original raw photos, videos, and metadata are safely backed up. Immich can automatically regenerate thumbnails on demand.

  • Plan Retention: 24 hourly, 30 daily, 12 monthly snapshots.

🔔 Healthchecks.io Monitoring Integration ​

Backrest is configured with automatic webhook reporting to Healthchecks.io:

  • Endpoint: https://hc-ping.com/acb56dd5-7287-4198-bb53-3222c9b59648
  • Monitored Conditions:
    • CONDITION_SNAPSHOT_START: Signals backup start to initiate run duration timer.
    • CONDITION_SNAPSHOT_SUCCESS: Reports successful completion with summary statistics.
    • CONDITION_ANY_ERROR: Immediately raises failure alert if an error occurs.
    • CONDITION_SNAPSHOT_WARNING: Reports warnings or non-fatal issues.
  • Payload Template: {{ .Summary }}

Authoritative operational repository and DR hub.