Deliverable:
- Restic is deployed through core role
- We have a role, configurable by pillar, to actually use it for files
- Encryption keys are in Vault
- We have a wrapper to query Vault for an encryption key (to use with RESTIC_PASSWORD_COMMAND)
Out of scope:
- ZFS-level backups
- Databases mechanisms
References: