Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
10 results
label:backup

Aws/backup

@swamp/aws/backup · v2026.10.06.1

AWS BACKUP infrastructure models

upd Oct 615 pullsA100/100

Nextcloud

@sntxrr/nextcloud · v2026.09.30.1

Health, version drift, setup checks, app updates and compatibility, verified backups and occ maintenance for a self-hosted Nextcloud. `sync` reads status.php and, with a serverinfo token, storage and user statistics; `drift` compares the running version against stable GitHub releases and reports the patch target and the next major separately, because Nextcloud refuses to skip a major and the newest release is often not a legal target; `setupchecks` records the admin overview's warnings as data; `talkBots` flags a Nextcloud Talk bot that is not enabled, whose webhook delivery errors rose since the last reading (Talk drops a message whose delivery fails and never resets the count, so the rise is the signal, not the total), or that is expected and missing; `apps` lists app store updates and, given a targetVersion, which enabled store apps have no release for it. `backup` dumps MySQL/MariaDB and archives the web-root directories an upgrade changes onto the machine swamp runs on, then reads both back (dump completion line and table count, tar header checksums and gzip CRC) and renames a backup that fails `.FAILED`; the database password stays in the container's environment and never reaches a command line. `maintenance`, `dbRepair`, `updateApps` and `backup` change state and are dry runs unless apply=true; each apply path re-reads the state afterwards and fails if the change did not take. occ runs through `docker exec`, locally or on a host over SSH with BatchMode. Four behaviours shape the implementation. Nextcloud 34 enforces trusted_domains on status.php and answers HTTP 400/code 15 when probed by IP, and Deno's fetch silently drops a Host header override, so baseUrl must be a trusted name and the error is named rather than reported as a bare 400. `occ setupchecks` exits 1 whenever any check warns, so exit 1 with a JSON report is data, not failure. Prerelease tags are spelled inconsistently (`rc2` and `RC2` both exist), so any suffixed tag is excluded, not parsed. And updates.nextcloud.com answers an empty 200 both for `nothing to offer` and for a query it did not understand, so it is not used. A failure to measure is raised, never reported as healthy, current or `no updates`.

upd Sep 3035 pullsA100/100

Restic

@magistr/restic · v2026.09.29.1

Drive restic backups from swamp: read repository state, initialize,

upd Sep 2915 pullsA100/100

Backrest

@sntxrr/backrest · v2026.09.23.2

Keep a Backrest server's snapshot index current for restic repositories it does not itself back up, and report how fresh each one is. Backrest indexes snapshots only for repositories it runs backups for; one that is merely configured — the normal shape when restic runs from systemd timers on each host and Backrest is only the console — is never indexed at all, and reports no error while doing so. The repository simply stays empty in the UI, which reads as `no backups` for a host whose backups are in fact current. `sync` reads the operation log and reports each repository's newest indexed snapshot. `reindex` triggers Backrest's own TASK_INDEX_SNAPSHOTS for every configured repository, waits for them to appear, and reports the same shape; it reads repositories and never creates, forgets or prunes a snapshot, so it is safe to schedule. Four server behaviours shape the implementation because each one silently produces a wrong answer if ignored. GetOperations' repoId selector does not filter — a selector matching nothing returns the ENTIRE operation log rather than an empty set, so a per-repository query makes every repository report the whole fleet's totals; operations are therefore fetched once and grouped on each operation's own repoId. A failed index task leaves no trace in the operation log, only successes being recorded, so a repository the server cannot read is indistinguishable through the API from one whose task has not run yet — both are reported as `unindexed` with the reason named as the server log rather than invented. The task queue is serial, so triggering N repositories enqueues N tasks behind each other and one whose credentials were revoked does not fail fast but retries with exponential backoff for six minutes or more while everything behind it waits, which is why the wait is a deadline over the whole set rather than a per-task timeout. And a repository with no indexed snapshot at all is a different failure from one whose snapshots have stopped advancing — the first is a credential this server holds that no longer exists, the second is a backup that has stopped running — so they are counted separately as `unindexed` and `stale` instead of being folded into one unhelpful total. Because it reaches repositories through the server's own stored credentials rather than the ones the backup hosts use, disagreement with a host-side view is informative: it means exactly one of the two credential sets has gone bad.

upd Sep 2338 pullsA100/100

Azure

@dougschaefer/azure · v2026.09.15.1

Azure infrastructure management via az CLI — 43 model types covering compute, networking, data, security, RBAC, Azure Policy, Defender for Cloud, Entra directory, monitoring, DNS, DevOps, Azure AI Foundry (accounts, model deployments, projects, quota), AI Search, Cosmos DB, PostgreSQL Flexible Server, Static Web Apps, Service Bus, Event Grid, Recovery Services, Log Analytics, subscription-wide topology with Mermaid diagrams and cost estimation, actual-spend cost analysis and waste auditing via Cost Management/Resource Graph/Advisor, and the Azure AI Vision Face REST API for identity-aware room services.

upd Sep 16119 pullsA100/100

Rclone Archive

@sntxrr/rclone-archive · v2026.08.19.5

Archive a Synology share to S3 Glacier Deep Archive with rclone, driven over SSH into a container on the NAS so no binary is installed on DSM. A cost-ordered ladder — inventory and cost projection, copy, metadata verification, then a two-phase restore drill that is the only rung proving recovery. Never deletes: sync, move and purge are refused at the runner, because a source that fails to mount presents as empty and sync would empty the destination unrecoverably while still billing the 180-day minimum.

upd Aug 1937 pullsA100/100

Restic Readiness

@sntxrr/restic-readiness · v2026.08.19.1

Rank a restic fleet by what has actually been proven restorable. A workflow-scope report that joins every @sntxrr/restic/repository step in a run — freshness, structural check, read-data verification, canary dump and restore drill — into one ranked findings list, where a rung that has never run is itself a finding. Read-only: it reads what the steps already wrote and never touches a repository.

upd Aug 1940 pullsA100/100

Restic Repository

@sntxrr/restic-repository · v2026.08.07.2

Validate one restic repository from a neutral host — snapshot freshness and backup-scope drift, structural check, read-data verification against bitrot, a dump canary, and a size-capped restore drill that proves the backup can actually be restored. Strictly read-only: it refuses every restic write command and never takes a repository lock, so it can never break the backup it validates.

upd Aug 822 pullsA100/100

Pbs

@lint/pbs · v2026.05.21.1

Proxmox Backup Server check — classify guests as fresh / stale / missing against a PBS datastore using API token auth.

upd May 2125 pullsA100/100

Rsync

@wendy/rsync · v2026.04.11.2

rsync model — configure any number of src→dst pairs with optional flags; supports one-way (src→dst) and two-way (src↔dst) sync. Requires rsync to be installed on the host system.

upd Apr 1125 pullsunscored