Skip to content

Check restic-check

Overview

Verifies the integrity of a restic backup repository by running restic check. Alerts when the repository contains errors or inconsistencies. In contrast to the interactive restic check sub-command, it cannot be used to read all data and therefore simulate a restore.

Important Notes:

  • Requires root or sudo
  • Refer to the online manual for more details about restic

Data Collection:

  • Executes restic --json --repo=... --password-file=... check
  • Always loads all data directly from the repository and does not use a local cache, so execution may take several minutes, especially if the repository is corrupted
  • If the output exceeds 10 lines, it is shortened to the first 5 and last 5 lines

Fact Sheet

Fact Value
Check Plugin Download https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/restic-check
Nagios/Icinga Check Name check_restic_check
Check Interval Recommendation Every day
Can be called without parameters No (--repo is required)
Runs on Cross-platform
Compiled for Windows No (runs with Python interpreter)

Help

usage: restic-check [-h] [-V] [--always-ok] [--password-file PASSWORD_FILE]
                    [--repo REPO] [--repository-file REPOSITORY_FILE]

Verifies the integrity of a restic backup repository by running "restic
check". Alerts when the repository contains errors or inconsistencies.
Requires root or sudo.

options:
  -h, --help            show this help message and exit
  -V, --version         show program's version number and exit
  --always-ok           Always returns OK.
  --password-file PASSWORD_FILE
                        Path to the file containing the repository password.
                        Must be a file that only root can change.
  --repo REPO           Restic repository location. Give exactly one of --repo
                        and --repository-file.
  --repository-file REPOSITORY_FILE
                        Path to a file whose first line is the repository
                        location. Use this instead of --repo for a repository
                        whose location selects an external helper (an
                        `rclone:` repository): the file must be one that only
                        root can change, so an unprivileged caller cannot
                        choose what runs. Give exactly one of --repo and
                        --repository-file.

Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/restic-check/

Usage Examples

./restic-check --repo=/path/to/restic-repo --password-file=/path/to/restic-pwd

Output on a healthy repository:

Everything is ok.

Output on a damaged repository:

There are errors.

pack 764fcd1a: does not exist
error for tree 5e730b1a:
  ReadFull(<data/764fcd1a>): open /path/to/restic-repo/data/76/764fcd1a...: no such file or directory
Fatal: repository contains errors

States

  • OK if the repository has no errors.
  • WARN if the repository has errors. With restic v0.18 and newer this is read from the num_errors field of restic's JSON summary; on older restic, which prints plain text for check, it is read from the exit code and the absence of "no errors" in the output.
  • UNKNOWN if --repo names an rclone: repository, or if --repository-file or --password-file can be changed by anybody but root.

Perfdata / Metrics

There is no perfdata.

Credits, License