Appearance
📸 Backrest: Immich Offsite Backup & Hetzner Storage Box
This document details the automated offsite backup pipeline for the Immich photo library using Backrest (a modern Web UI and orchestrator for Restic) backed by a 1TB Hetzner Storage Box BX11.
🏛️ Architecture Overview
The backup architecture provides encrypted, deduplicated offsite backups with automated health monitoring and multi-stage lifecycle maintenance:
⚙️ Service & Runtime Configuration
- Host Container: LXC 131 (
docker-mediaon PVE-1, IP192.168.0.131) - Runtime User:
admin-ssh(UID1001on LXC 131) - Application Version: Backrest v1.13.0
- Configuration File:
/home/admin-ssh/.config/backrest/config.json - Data & State Directory:
/home/admin-ssh/.local/share/backrest - Web UI Auth: Authenticated user
rayman(Port9898)
🗄️ Repository Specification (immich-hetzner-bx11)
| Parameter | Value | Description |
|---|---|---|
| Repository ID | immich-hetzner-bx11 | Primary offsite photo repository |
| Target URI | sftp:hetzner-immich-storagebox:immich-restic | Hetzner Storage Box BX11 (1TB) via SFTP |
| Connection Flags | --option=sftp.args='-oBatchMode=yes' | Non-interactive SSH key authentication |
| Encryption | Enabled (Restic AES-256) | Client-side encrypted before transfer |
Maintenance & Retention Policies:
json
{
"forgetPolicy": {
"schedule": { "cron": "0 6 * * *", "clock": "CLOCK_LOCAL" },
"retention": {
"policyTimeBucketed": {
"hourly": 24,
"daily": 14,
"weekly": 8,
"monthly": 6,
"yearly": 1,
"keepLastN": 7
}
}
},
"prunePolicy": {
"schedule": { "cron": "0 4 1 * *", "clock": "CLOCK_LOCAL" },
"maxUnusedPercent": 10
},
"checkPolicy": {
"schedule": { "cron": "0 5 2 * *", "clock": "CLOCK_LOCAL" },
"readDataSubsetPercent": 5
}
}- Daily Forget (
0 6 * * *): Cleans up old snapshots daily at 06:00 AM preserving 24 hourly, 14 daily, 8 weekly, 6 monthly, and 1 yearly snapshots. - Monthly Prune (
0 4 1 * *): Repacks repository on the 1st of every month at 04:00 AM if unreferenced data exceeds 10%. - Monthly Integrity Check (
0 5 2 * *): Validates repository structure and verifies a 5% random subset of data blocks on the 2nd of each month at 05:00 AM.
📋 Backup Plan (immich-photos)
- Plan ID:
immich-photos - Target Repository:
immich-hetzner-bx11 - Source Path:
/mnt/media_root/media/photos - Schedule:
1 1 * * *(Daily at 01:01 AM local time) - Exclusions (
iexcludes):thumbs/**(Omits pre-generated UI image thumbnails)encoded-video/**(Omits temporary/transcoded streaming video copies)
TIP
Excluding thumbnails and transcoded video streams saves gigabytes of cloud bandwidth and storage space while ensuring 100% of original raw photos, videos, and metadata are safely backed up. Immich can automatically regenerate thumbnails on demand.
- Plan Retention: 24 hourly, 30 daily, 12 monthly snapshots.
🔔 Healthchecks.io Monitoring Integration
Backrest is configured with automatic webhook reporting to Healthchecks.io:
- Endpoint:
https://hc-ping.com/acb56dd5-7287-4198-bb53-3222c9b59648 - Monitored Conditions:
CONDITION_SNAPSHOT_START: Signals backup start to initiate run duration timer.CONDITION_SNAPSHOT_SUCCESS: Reports successful completion with summary statistics.CONDITION_ANY_ERROR: Immediately raises failure alert if an error occurs.CONDITION_SNAPSHOT_WARNING: Reports warnings or non-fatal issues.
- Payload Template:
{{ .Summary }}