Token导航 LogoToken导航TokenDH.com
开发只读clawhub未标认证来源可访问clear审计通过

restic-workstation-backupRestic 工作站备份

Agent Skill

restic-workstation-backup 用于辅助测试设计、自动化测试和回归验证,适合在 OpenClaw 中需要补充测试、分析失败日志或验证功能改动时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

4,796

周安装

194

GitHub Stars

公开资料未说明

下载量

1,505
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:restic-workstation-backup(Restic 工作站备份)
来源仓库:https://github.com/kiris-z/restic-workstation-backup
安装命令:
openclaw skills install restic-workstation-backup
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install restic-workstation-backup

简介

restic-workstation-backup 用于工作站级别的加密 Restic 备份,支持 Linux 主目录保护。

  • 适用于 OpenClaw 环境,具备加密、去重与自动调度特性。
  • 包含恢复测试流程,确保备份可信赖。
  • 使用前需确认存储位置可达性与访问权限。
  • 建议制定保留策略,避免存储成本无限增长。

SKILL.md

name
restic-home-backup
description
Design, implement, and operate encrypted restic backups for Linux home directories with encryption, deduplication, automated scheduling, and restore testing. Use when a user asks to back up ~/, set up daily/weekly/monthly backup jobs, harden backup security, troubleshoot restore/integrity issues, or roll out backup automation across multiple workstations.

Restic Home Backup

Deliver a production-ready, unattended restic backup workflow for a Linux home directory, covering encryption, deduplication, versioned retention, systemd scheduling, retry logic, durable logging, email alerting, and restore validation.

Skill contract

  • Name: restic-home-backup
  • Version: 2.0.0
  • Problem solved: Reliable, encrypted, versioned backups of a Linux home

directory. Supports SSH/SFTP remote repositories, DST-safe scheduling, transient-error retries, user-level installs (no root), one-time restore audit timers, and reusable multi-host rollout.

  • Inputs:

- Backup source user and path - Repository endpoint/transport (local, sftp, s3, b2, etc.) - Timezone (default America/Los_Angeles) - Retention policy (default: 14 daily / 8 weekly / 12 monthly) - Exclude patterns - Alert email

  • Outputs:

- Installed and initialized restic repository - Backup / prune / check / audit scripts under /usr/local/bin/ - Structured log wrapper with start/end/elapsed/exit-code per job - systemd service+timer units (system-level or user-level) - One-time restore audit timer - Retry logic for transient failures (never retries auth/perm errors) - Validation evidence: snapshot listing, restore drill, integrity check - Controlled failure drills: wrong secret / unreachable repo / bad env file - Operator runbook (references/runbook.md) - Ops checklist (references/ops-checklist.md)

  • Safety boundaries (must never violate):

- Never print secrets or tokens in chat, log output, or scripts. - Never delete snapshots or repositories without explicit user confirmation. - Never weaken permissions on credential files (0600 minimum). - Never claim backup success without checking exit status and snapshot listing. - Default to PLAN-ONLY mode; require explicit --apply for system changes. - No snapshot deletion during initial engagement; use --dry-run-prune to preview.

Workflow

1) Collect backup contract

Minimum required:

  • Source path (e.g., /home/alice)
  • Repository (e.g., sftp:backupsvc@10.50.8.24:/srv/backups/home/devbox17)
  • Retention policy
  • Preferred schedule in local timezone

If any critical value is missing, ask targeted questions.

2) Show plan (no-change pass)

bash scripts/bootstrap_restic_home.sh \
  --user alice \
  --repo "sftp:backupsvc@10.50.8.24:/srv/backups/home/devbox17"

This prints the complete plan: files, schedule, retention, secrets approach, retry logic, legacy cron archival, and dry-run prune preview. Zero changes made.

3) Apply system changes

sudo bash scripts/bootstrap_restic_home.sh \
  --user alice \
  --repo "sftp:backupsvc@10.50.8.24:/srv/backups/home/devbox17" \
  --hostname devbox17 \
  --timezone "America/Los_Angeles" \
  --mail-to sre-oncall@example.com \
  --keep-daily 14 --keep-weekly 8 --keep-monthly 12 \
  --config-dir /etc/home-backup \
  --log-dir /var/log/home-backup \
  --apply \
  --init-repo \
  --enable-timers \
  --run-initial-backup \
  --archive-legacy-cron \
  --dry-run-prune

What this does (in order):

  1. Creates /etc/home-backup/ (0700), generates password (0600, never printed)
  2. Writes env file (0600) and excludes list
  3. Creates log directory /var/log/home-backup/
  4. Installs logging+retry wrapper (restic-home-log-run.sh)
  5. Installs 4 operational scripts (backup, prune, check, audit-drill)
  6. Writes 8 systemd units (4 service + 4 timer)
  7. Archives and removes legacy root crontab entry
  8. Enables timers and runs daemon-reload
  9. Initializes repo (skips if already exists)
  10. Starts first backup via systemd
  11. Shows restic forget --dry-run output (no deletion)

4) User-level install (no root required — e.g., labvm3/bob)

bash scripts/install_userlevel_restic.sh \
  --repo /mnt/offsite/backups/labvm3-home \
  --hostname labvm3 \
  --timezone "America/Los_Angeles" \
  --mail-to sre-oncall@example.com \
  --apply --init-repo --enable-timers --run-initial-backup

# Enable linger (one-time, requires sudo):
sudo loginctl enable-linger bob

# Manage:
systemctl --user list-timers 'restic-home-*'    # list
systemctl --user start restic-home-backup.service  # manual backup
bash scripts/install_userlevel_restic.sh --remove  # remove schedule

5) End-to-end validation

sudo bash scripts/validate_restic_setup.sh

Runs:

  • Snapshot listing
  • Restore drill to /tmp/restore-drill (verifies .ssh/config,

Documents/roadmap.md, .config/git/config)

  • Cleanup of temp restore directory
  • Repository integrity check
  • Three failure drills: wrong secret / unreachable repo / unreadable env file

(each prints the failing command and a one-line corrective action)

6) One-time restore audit timer

The bootstrap creates restic-home-audit.timer for a single scheduled restore drill. By default: 2026-04-17 17:00:00 America/Los_Angeles.

# Inspect:
systemctl list-timers restic-home-audit.timer --no-pager

# Cancel:
systemctl disable --now restic-home-audit.timer

# Run now:
systemctl start restic-home-audit.service

7) Package and publish via ClawHub

# Validate skill structure:
clawhub validate .

# Publish:
clawhub publish .

# Verify clean install (fresh environment, no secrets carried over):
mkdir /tmp/clawhub-verify && cd /tmp/clawhub-verify
clawhub install restic-home-backup
# Run plan-only to confirm scripts are present and executable:
bash restic-home-backup/scripts/bootstrap_restic_home.sh \
  --user testuser --repo sftp:test@localhost:/test

Files in this skill

scripts/
  bootstrap_restic_home.sh     System-level install (plan + apply)
  install_userlevel_restic.sh  User-level install for non-root hosts
  validate_restic_setup.sh     End-to-end validation + failure drills

references/
  runbook.md      Full operator runbook (13 sections)
  ops-checklist.md  Quick daily/weekly/monthly reference

Response style requirements

  • Name exact file paths, service names, and commands.
  • State what changed and how to verify it.
  • Never print passwords or tokens.
  • End multi-step tasks with an explicit completion status.
  • Reference references/runbook.md for day-2 operational guidance.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

72.86%
按下载量换算1,097

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills