Wasabi Restic Backup Script
This script automates backups to a Wasabi S3-compatible bucket using restic.
It loads secrets from .env.local, builds a restic repository string, and runs restic backup with redacted environment logging.
Features
- Two subcommands:
init(initialize a new repository) andbackup(run a backup). - Backup a single source path with
-s/--source. - Backup multiple source paths from a JSON config file with
-f/--file. - Load secrets from
.env.localvia python-dotenv. - Support a prebuilt restic repository via
--repositoryorRESTIC_REPOSITORY. - Redact sensitive environment values in output.
- Support dry-run mode for command verification.
Requirements
- Python 3.8+
- restic installed and available on
PATH - Install dependencies:
pip install -r requirements.txt
Environment Variables
The script loads .env.local automatically and uses these variables:
| Variable | Required | Description |
|---|---|---|
AWS_ACCESS_KEY_ID |
Yes | Wasabi access key |
AWS_SECRET_ACCESS_KEY |
Yes | Wasabi secret key |
RESTIC_PASSWORD |
Yes | Restic repository encryption password |
WASABI_ENDPOINT |
No | S3 endpoint (defaults to s3.<region>.wasabisys.com) |
WASABI_REGION |
No | Wasabi region, e.g. us-east-2 (used to derive endpoint) |
WASABI_BUCKET |
No | Bucket name (used when RESTIC_REPOSITORY is not set) |
RESTIC_REPOSITORY |
No | Full restic repository string (overrides bucket/prefix/region) |
RESTIC_PREFIX |
No | Prefix (folder) inside bucket |
FILE_PATH_CONFIG_PATH |
No | Path to JSON config file (backup subcommand only) |
Only AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, RESTIC_PASSWORD, and WASABI_ENDPOINT are passed to the restic subprocess. The script builds a minimal environment to avoid leaking unrelated variables.
Create a RESTIC_PASSWORD via openssl rand -base64 32 for best security.
Subcommands
init — Initialize a New Repository
python travel-backup-script.py init --bucket my-bucket --region us-east-2 --dry-run
backup — Run a Backup
python travel-backup-script.py backup --source /etc --bucket my-bucket --dry-run
Repository Resolution
The repository string is resolved in this order:
--repositoryCLI flag orRESTIC_REPOSITORYenv var (must matchs3:s3.<region>.wasabisys.com/<bucket>[/<prefix>]).- Otherwise, built from
--bucket/WASABI_BUCKET,--region/WASABI_REGION,WASABI_ENDPOINT, and--prefix/RESTIC_PREFIX.
CLI Options
Shared options (both init and backup):
--bucket: Wasabi bucket name (or setWASABI_BUCKET)--prefix: Prefix inside the bucket (or setRESTIC_PREFIX)--region: Wasabi region, e.g.us-east-2(or setWASABI_REGION)--repository: Full restic repository string (or setRESTIC_REPOSITORY)--dry-run: Print the command and redacted environment without runningrestic
Backup-only options:
-s,--source: Single file or directory to back up-f,--file: Path to a JSON file containing{"paths": ["..."]}
-s/--source and -f/--file are mutually exclusive. One of them (or the FILE_PATH_CONFIG_PATH env var) is required for backup.
JSON File Format
Example config:
{
"paths": [
"/path/to/Documents",
"/path/to/Pictures"
]
}
Examples
Initialize a repository (dry run):
python travel-backup-script.py init --bucket my-bucket --region us-east-2 --dry-run
Backup a single source (dry run):
python travel-backup-script.py backup --source /etc --bucket my-bucket --dry-run
Backup from a JSON file (dry run):
python travel-backup-script.py backup --file backup-paths.json --bucket my-bucket --dry-run
Use a custom prefix:
python travel-backup-script.py backup --source ~/Documents --bucket my-bucket --prefix laptop-backups
Use a full repository string:
python travel-backup-script.py backup --source ~/Documents --repository s3:s3.us-east-2.wasabisys.com/my-bucket/laptop-backups