Proxmox Backup Server
10 posts on Proxmox Backup Server: design decisions and how-to guides from small infrastructure estates run on a very low budget.
- PBS: a lot of "verify failed", and the protect-latest trick
When a verify job lights up dozens of snapshots at once, the first job is to stop prune from making it worse. Protect the newest snapshot in every group, read the log for the one chunk that is shared, then decide between re-uploading from the source, re-syncing from the other site, and fixing the disk.
- PBS: fix the fingerprint mismatch after a rename or reinstall
Rename or reinstall a PBS host and it presents a new self-signed certificate. Every PVE storage entry and every remote on the other PBS has the old fingerprint pinned and refuses to connect. Where the pins live, how to read the new fingerprint, and the order to update them in.
- Proxmox: move VMs between two clusters
qm remote-migrate exists and is fussy. The path that works every time is a Proxmox Backup Server backup, already replicated to the other site, restored on the other cluster from a read-only storage entry with a new guest ID.
- PBS: a restore drill for one file, one guest and one site
A backup you have not restored from is a hope. Three rehearsed restores, each with its commands and its evidence: one file from a pxar archive, one guest to a new VMID on the local PBS, and one guest on the other cluster from the replica namespace. What the first drill found, how often to run it, and what to write down.
- PBS: back up a directory with proxmox-backup-client from a snapshot
vzdump skips bind mounts, so the files a container serves from CephFS never reach the backup server. A nightly proxmox-backup-client run takes a pxar archive of the latest CephFS snapshot into the tenant's namespace. The token, the command, the timer, and the one-file restore that proves it.
CephFS subvolumes under LXC: snapshots your backups can seeGuests are disposable; the data is not in them. Put user files on a CephFS subvolume, bind-mount it into an unprivileged container, snapshot on a schedule, and back the snapshot up, because vzdump skips bind mounts.
- PBS: prune, verify and garbage collection that do not fight
Prune decides what to keep, garbage collection reclaims what nothing references, verify checks that what is kept is still readable. Each is harmless alone and all three get in each other's way when they overlap. A weekly calendar that keeps them apart, and apart from the backup window and the restore drill.
- PBS: sync job says TASK OK but the datastore is empty
A pull sync that finishes green and copies nothing has one of three causes: the namespaces do not line up, an earlier run is still holding the locks, or the token cannot see anything upstream. One check for each, and a way to see what the job sees before running it.
- PBS: pull replication between two sites with a read-only token
The remote PBS pulls, with a token that can only read one datastore, a pinned fingerprint, and a per-source namespace so guest IDs from two clusters never collide. Every command, in order, then the storage entry that lets the surviving cluster restore.
Proxmox Backup Server that leaves the buildingA standalone PBS per site is the easy part. The part most setups skip is getting a copy to the other site, verified, with a token that cannot do damage.