mirror of
https://github.com/kevinveenbirkenbach/docker-volume-backup.git
synced 2026-08-01 12:34:50 +00:00
feat(backup): capture volumes from a filesystem snapshot
Backing up a live volume with rsync copies a moving target: a database
written to mid-copy lands on disk in a state no engine ever committed.
Stopping the container avoids that at the cost of downtime.
A snapshot removes both. `--snapshot {btrfs,zfs}` with `--snapshot-subject`
freezes the docker root once per run, and every volume copy is then read
from that frozen tree while the containers keep serving. A restore of such
a copy is an ordinary crash recovery, which every supported engine performs
on its own at startup.
An unsupported filesystem or an unknown snapshot kind fails loudly rather
than degrading to a live copy, since a silent fallback would return exactly
the torn backup the mode exists to prevent. `--shutdown` is rejected
alongside `--snapshot` instead of being ignored: under a snapshot no
container is ever stopped, so accepting the flag would promise downtime
semantics the run does not deliver.
Copies out of a snapshot skip rsync's --checksum verification. The source
is immutable for the lifetime of the copy, so size-and-mtime cannot race,
and dropping the second full read roughly halves the I/O per volume.
backup/app.py grew past what one module could carry and is split into
layout, policy and dumps along the lines it already had internally.
Tests: unit coverage for the new snapshot, layout, policy, volume and cli
units; e2e cases drive real btrfs, zfs and ext4 filesystems on loop devices
in a privileged container, including a MariaDB that is written to across
the snapshot and must recover from the restored copy without losing a
committed row. CI installs zfs and sets E2E_REQUIRE_FILESYSTEMS so a
missing kernel module fails the build instead of silently skipping a
filesystem.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
107
tests/unit/backup/test_snapshot.py
Normal file
107
tests/unit/backup/test_snapshot.py
Normal file
@@ -0,0 +1,107 @@
|
||||
"""Contract of the filesystem snapshot used to capture volumes atomically."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import unittest
|
||||
|
||||
from baudolo.backup.snapshot import SnapshotError, volume_snapshot
|
||||
|
||||
|
||||
class Runner:
|
||||
def __init__(self, replies: dict[str, list[str]] | None = None) -> None:
|
||||
self.calls: list[str] = []
|
||||
self.replies = replies or {}
|
||||
|
||||
def __call__(self, command: str) -> list[str]:
|
||||
self.calls.append(command)
|
||||
for prefix, reply in self.replies.items():
|
||||
if command.startswith(prefix):
|
||||
return reply
|
||||
return []
|
||||
|
||||
|
||||
class TestBtrfs(unittest.TestCase):
|
||||
def test_it_creates_a_read_only_snapshot_beside_the_subject(self) -> None:
|
||||
run = Runner()
|
||||
with volume_snapshot("btrfs", "/var/lib/docker", "20260731", run=run):
|
||||
pass
|
||||
self.assertEqual(
|
||||
run.calls[0],
|
||||
"btrfs subvolume snapshot -r /var/lib/docker /var/lib/.baudolo-20260731",
|
||||
)
|
||||
|
||||
def test_it_removes_the_snapshot_afterwards(self) -> None:
|
||||
run = Runner()
|
||||
with volume_snapshot("btrfs", "/var/lib/docker", "20260731", run=run):
|
||||
pass
|
||||
self.assertEqual(run.calls[-1], "btrfs subvolume delete /var/lib/.baudolo-20260731")
|
||||
|
||||
def test_it_maps_a_volume_path_into_the_snapshot(self) -> None:
|
||||
run = Runner()
|
||||
with volume_snapshot("btrfs", "/var/lib/docker", "20260731", run=run) as resolve:
|
||||
self.assertEqual(
|
||||
resolve("/var/lib/docker/volumes/postgres_data/_data"),
|
||||
"/var/lib/.baudolo-20260731/volumes/postgres_data/_data",
|
||||
)
|
||||
|
||||
def test_it_removes_the_snapshot_even_when_the_body_raises(self) -> None:
|
||||
run = Runner()
|
||||
with self.assertRaises(ZeroDivisionError):
|
||||
with volume_snapshot("btrfs", "/var/lib/docker", "20260731", run=run):
|
||||
raise ZeroDivisionError
|
||||
self.assertTrue(run.calls[-1].startswith("btrfs subvolume delete"))
|
||||
|
||||
|
||||
class TestZfs(unittest.TestCase):
|
||||
def _run(self) -> Runner:
|
||||
return Runner({"zfs list": ["tank/docker"]})
|
||||
|
||||
def test_it_snapshots_the_dataset_mounted_at_the_subject(self) -> None:
|
||||
run = self._run()
|
||||
with volume_snapshot("zfs", "/var/lib/docker", "20260731", run=run):
|
||||
pass
|
||||
self.assertIn("zfs snapshot tank/docker@baudolo-20260731", run.calls)
|
||||
|
||||
def test_it_destroys_the_snapshot_afterwards(self) -> None:
|
||||
run = self._run()
|
||||
with volume_snapshot("zfs", "/var/lib/docker", "20260731", run=run):
|
||||
pass
|
||||
self.assertEqual(run.calls[-1], "zfs destroy tank/docker@baudolo-20260731")
|
||||
|
||||
def test_it_maps_a_volume_path_through_the_dot_zfs_directory(self) -> None:
|
||||
run = self._run()
|
||||
with volume_snapshot("zfs", "/var/lib/docker", "20260731", run=run) as resolve:
|
||||
self.assertEqual(
|
||||
resolve("/var/lib/docker/volumes/postgres_data/_data"),
|
||||
"/var/lib/docker/.zfs/snapshot/baudolo-20260731/volumes/postgres_data/_data",
|
||||
)
|
||||
|
||||
def test_an_unmounted_dataset_is_an_error(self) -> None:
|
||||
run = Runner({"zfs list": [""]})
|
||||
with self.assertRaises(SnapshotError):
|
||||
with volume_snapshot("zfs", "/var/lib/docker", "20260731", run=run):
|
||||
pass
|
||||
|
||||
|
||||
class TestRejections(unittest.TestCase):
|
||||
def test_an_unknown_kind_is_rejected(self) -> None:
|
||||
run = Runner()
|
||||
with self.assertRaises(SnapshotError):
|
||||
with volume_snapshot("ext4", "/var/lib/docker", "20260731", run=run):
|
||||
pass
|
||||
self.assertEqual(run.calls, [])
|
||||
|
||||
def test_a_path_outside_the_subject_is_rejected(self) -> None:
|
||||
run = Runner()
|
||||
with volume_snapshot("btrfs", "/var/lib/docker", "20260731", run=run) as resolve:
|
||||
with self.assertRaises(SnapshotError):
|
||||
resolve("/etc/passwd")
|
||||
|
||||
def test_the_subject_itself_resolves_to_the_snapshot_root(self) -> None:
|
||||
run = Runner()
|
||||
with volume_snapshot("btrfs", "/var/lib/docker", "20260731", run=run) as resolve:
|
||||
self.assertEqual(resolve("/var/lib/docker"), "/var/lib/.baudolo-20260731")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
Reference in New Issue
Block a user