Check restic-check¶
Overview¶
Verifies the integrity of a restic backup repository by running restic check. Alerts when the repository contains errors or inconsistencies. In contrast to the interactive restic check sub-command, it cannot be used to read all data and therefore simulate a restore.
Important Notes:
- Requires root or sudo
- Refer to the online manual for more details about restic
Data Collection:
- Executes
restic --json --repo=... --password-file=... check - Always loads all data directly from the repository and does not use a local cache, so execution may take several minutes, especially if the repository is corrupted
- If the output exceeds 10 lines, it is shortened to the first 5 and last 5 lines
Fact Sheet¶
| Fact | Value |
|---|---|
| Check Plugin Download | https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/restic-check |
| Nagios/Icinga Check Name | check_restic_check |
| Check Interval Recommendation | Every day |
| Can be called without parameters | No (--repo is required) |
| Runs on | Cross-platform |
| Compiled for Windows | No (runs with Python interpreter) |
Help¶
usage: restic-check [-h] [-V] [--always-ok] [--password-file PASSWORD_FILE]
[--repo REPO] [--repository-file REPOSITORY_FILE]
Verifies the integrity of a restic backup repository by running "restic
check". Alerts when the repository contains errors or inconsistencies.
Requires root or sudo.
options:
-h, --help show this help message and exit
-V, --version show program's version number and exit
--always-ok Always returns OK.
--password-file PASSWORD_FILE
Path to the file containing the repository password.
Must be a file that only root can change.
--repo REPO Restic repository location. Give exactly one of --repo
and --repository-file.
--repository-file REPOSITORY_FILE
Path to a file whose first line is the repository
location. Use this instead of --repo for a repository
whose location selects an external helper (an
`rclone:` repository): the file must be one that only
root can change, so an unprivileged caller cannot
choose what runs. Give exactly one of --repo and
--repository-file.
Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/restic-check/
Usage Examples¶
./restic-check --repo=/path/to/restic-repo --password-file=/path/to/restic-pwd
Output on a healthy repository:
Everything is ok.
Output on a damaged repository:
There are errors.
pack 764fcd1a: does not exist
error for tree 5e730b1a:
ReadFull(<data/764fcd1a>): open /path/to/restic-repo/data/76/764fcd1a...: no such file or directory
Fatal: repository contains errors
States¶
- OK if the repository has no errors.
- WARN if the repository has errors. With restic v0.18 and newer this is read from the
num_errorsfield of restic's JSON summary; on older restic, which prints plain text forcheck, it is read from the exit code and the absence of "no errors" in the output. - UNKNOWN if
--reponames anrclone:repository, or if--repository-fileor--password-filecan be changed by anybody but root.
Perfdata / Metrics¶
There is no perfdata.
Credits, License¶
- Authors: Linuxfabrik GmbH, Zurich
- License: The Unlicense, see LICENSE file.