Wire the backup service against the Synology share over SMB/CIFS (the NAS
authenticates with a user/password; NFS is IP-allowlist only). Also fixes
three defects found bringing the service up live:
- entrypoint crash-loop: dcron's crond fails "setpgid: Operation not
permitted" in this runtime -> use busybox crond; make repo-init idempotent
(check via `restic cat config`, tolerate init-on-existing) so a transient
CIFS/lock hiccup can't kill PID 1.
- OOM: pg_dump of a ~276MB DB + tar + restic exceeded the 256M cap -> 1G.
- live tar abort: GNU tar exits 1 when TDLib files change mid-read (worker is
live); per design this is best-effort, so tolerate exit 1, fatal only >=2.
Kuma push is now optional (empty URL disables alerting) since it's deferred.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Previously the dump/tar cleanup only ran after restic forget succeeded,
so a plaintext Postgres dump could be left behind in /tmp if tar or
restic failed partway through. Add an EXIT trap that unconditionally
removes both temp files on any exit path, and drop the now-redundant
explicit rm -f from the success path.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>