URBM - Unraid Restic Backup Manager
URBM is a native Unraid 7 plugin that manages encrypted, deduplicated and versioned backups through Restic. It supports shares, appdata, Docker metadata and data, VM definitions and disks, and the Unraid boot drive. Destinations can be local, SFTP, SMB or NFS.
USB flash jobs always back up the browsable /boot file tree and can optionally stream the complete physical boot device into Restic as urbm-usb-flash.img for block-level recovery to an equal-sized or larger replacement device.
URBM also supports scheduled direct Rsync copies. Sources and the destination are selected with folder browsers; overwrite, destination deletion, permissions, ownership, timestamps, links, ACLs, extended attributes, checksum comparison, and dry-run behavior are configured without free-form shell arguments.
URBM is an independent community plugin and is not affiliated with or endorsed by Lime Technology, Inc.
Architecture
urbmdis a static Go daemon with a single global task queue and an HTTP API on/run/urbm/urbm.sock.- The Unraid PHP page proxies authenticated WebGUI requests to that Unix socket.
- Persistent configuration and AES-256-GCM encrypted secrets live in
/boot/config/plugins/urbm. - Runtime secrets and transient metadata live below
/run/urbmand are deleted after each operation. - Restic 0.19.0 is pinned and checksum-verified by the package build.
Development
Requirements: Go 1.23+, Node.js, curl, bzip2, tar, and sha256sum.
./scripts/check.sh
./packaging/build-package.sh
The package is written to dist/. Replace REPLACE_DURING_RELEASE in the copied PLG manifest with the generated package checksum before publishing a release.
Unraid installation
Install the generated manifest URL through Unraid's Plugins page:
https://git.casaderoll.de/michael/URBM/raw/branch/main/dist/urbm.plg
Configuration is retained when uninstalling so repositories remain recoverable.
Security model
The daemon has no TCP listener. Restic passwords are passed through root-only temporary files, never command-line arguments. Automatic boot unlock protects against accidental disclosure but does not protect against root compromise or theft of the complete flash drive. In-place restores require explicit confirmation and protected system roots are rejected.
Current scope
The code implements the MVP control plane and adapters. Docker and VM operations require the standard Unraid docker and virsh commands. Managed SMB/NFS mounts require the corresponding Unraid mount helpers. Hardware and end-to-end compatibility must be validated on supported Unraid 7 releases before a stable publication.
Backup safety (2026.09.21.r001)
Repository checks report success/failure through configured notification targets. The standard check verifies repository structure; it is not a full data-read or restore test. Docker jobs discover bind mounts and named volumes. Live backups do not guarantee application/database consistency. Use stop mode for coordinated offline backups. Stop mode restarts only workloads that were running before preparation; ambiguous paused/restarting states fail safely. Each restart has a 120-second deadline and recovery continues after individual failures. Shutdown waits for cleanup; the rc script refuses a forced kill or overlapping restart if cleanup exceeds five minutes. Hard crashes or power loss still require checking workload state and backup results.
Mirror an array disk to a mounted USB disk (2026.09.27.r001)
Create an Rsync job and select the mounted array disk, for example /mnt/disk1,
as the source. Select the USB disk under /mnt/disks, for example
/mnt/disks/USB-Backup, as the target. URBM copies the selected directory, so this
creates /mnt/disks/USB-Backup/disk1 and copies its contents there. Select the USB
root, not its existing disk1 subdirectory, to avoid nesting another disk1.
Enable overwrite to update existing files. Enable destination deletion for a mirror that also removes files deleted from the source; deletion is off by default. Use the dry-run option to preview a job without changing files. The USB disk must already be mounted, for example through Unassigned Devices. URBM checks array and USB mounts before starting the job and refuses leftover directories after an unmount. Keep the USB disk connected throughout the run. Reload the page after mounting a new array disk to refresh the available sources.
Rsync diagnostics (2026.09.27.r002)
Run logs start collapsed and retain your open/closed selection during refresh. New Rsync runs log the source paths, target, dry-run mode, overwrite/delete and comparison options, exclusions, execution phases, up to 20 itemized change examples, and final file/byte/deletion totals. Deletion counts include directories and symlinks. Byte totals describe the contents of transferred files, not protocol traffic. A dry run reports planned changes and records zero bytes actually copied; its notification explicitly states that no changes were made. Historical logs cannot be reconstructed with these additional details.
For an integration test against Rsync 3.x, run
URBM_TEST_RSYNC=/path/to/rsync go test ./internal/rsync -run TestRealRsync -v.
The test uses temporary directories only and checks that a dry run changes nothing,
that a subsequent copy matches the planned counts, and that another comparison
then finds no changes.