Schliesst den lokalen Code-Stand fuer zwei offene MASTER_TODO-Punkte ab. monitoring: restliche Einzeldatei-Bind-Mounts (alertmanager, blackbox, loki, promtail, alertmanager-ntfy-bridge) auf Directory-Mounts umgestellt, analog zum Prometheus-Fix vom 2026-06-19. Vermeidet "Stale NFS file handle" auf dem /mnt/user-FUSE-Share bei git/Komodo-Updates. grafana-provisioning war bereits Directory-Mount. `docker compose config` gruen. Beim Deploy --force-recreate noetig, da sich Mount-Zielpfade aendern. backup: endpoint-agnostischer Dead-Man's-Switch (Healthchecks-kompatibel, Cloud oder self-hosted) in pull-critical-backups.ps1 und pre-borg.sh. Pings /start, Erfolg und /fail; No-Op ohne konfigurierte URL, bricht also keinen Lauf. Ping-URLs sind Capability-URLs und bleiben als Secret ausserhalb des Repos. Doku: SECRETS_MAP, Nearline-README und MASTER_TODO nachgezogen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Borg dump scripts
These scripts are intended to run on the Unraid host before a Borg backup starts.
Current script
pre-backup-dumps.shgitea-bundle-mirror.sh
Output
Fresh dump artifacts are written to:
/mnt/user/backups/borg/dumps/latest
Fresh Gitea repository bundles are written to:
/mnt/user/backups/git-bundles/gitea
Borg UI should include /local/borg-dumps as a backup source.
The Gitea bundle target should also be part of the Borg scope, either through
the backups share or an explicit Borg source.
The dump set also includes unraid-flash-config.tar.gz, a host-generated
archive of /boot/config plus checksum and manifest. Treat this archive as
secret backup material.
Notes
- The script is written for host execution where
dockeris available. gitea-bundle-mirror.shadditionally expects host access to the Gitea bare repositories under/mnt/user/services/gitea/data/git/repositories.- It does not assume Backrest.
- It keeps only the latest dump set because Borg itself provides history.
Recommended automation path
The recommended automation path is:
- Unraid User Scripts on the host
- host-side schedule / cron
- Borg UI backup job afterwards
This is preferred over a Borg UI inline hook because the dump script expects:
- host access to
docker exec - host paths like
/mnt/user/... - direct write access to the dump target directory
Do not treat pre-backup-dumps.sh as a Borg UI inline script unless the architecture is deliberately changed later.
See USER_SCRIPTS_SETUP.md for the intended host-side rollout.