{
  config,
  pkgs,
  ...
}: {
  services.restic.backups = let
    snapshots = "/srv/snapshots";
    boxUser = "u384702-sub2";
    postgresUser = "postgres";
  in {
    storagebox = {
      initialize = true;
      backupPrepareCommand = ''
        ${pkgs.sudo}/bin/sudo -u ${postgresUser} ${pkgs.postgresql}/bin/pg_dumpall --clean --if-exists --quote-all-identifiers > /srv/db_backup.sql

        [ -d /srv/snapshots ] || ${pkgs.btrfs-progs}/bin/btrfs subvolume create /srv/snapshots;
        [ -d /srv/snapshots/srv ] && ${pkgs.btrfs-progs}/bin/btrfs subvolume delete /srv/snapshots/srv;
        ${pkgs.btrfs-progs}/bin/btrfs subvolume snapshot -r /srv /srv/snapshots/srv;

        # dump() {
        #   # compression:
        #   # pg_dump -F t -v "$1" | xz -z -9 -e -T0 > "db_$1.tar.xz"
        #   pg_dump -v "$1" > "db_$1.tar.xz"
        # }
        # # List all databases, and dump each of them in its own file
        # # psql --list --csv | while read -r line; do echo "$line" | grep ','; done | while IFS=, read -r name _; do  echo "$name"; done | sed '1d' | while read -r db_name; do dump "$db_name"; done
      '';
      paths = [
        snapshots
      ];
      exclude = [
        ".snapshots"
        "/var/lib/postgresql" # included in the db dump
      ];
      extraBackupArgs = [
        "--verbose" # spam log
      ];
      passwordFile = config.age.secrets.resticpass.path;
      extraOptions = [
        "rclone.program='ssh -p 23 ${boxUser}@${boxUser}.your-storagebox.de -i ${config.age.secrets.resticssh.path}'"
      ];
      repository = "rclone: "; # There is only one repository served
      timerConfig = {
        Requires = "network-online.target";
        OnCalendar = "daily";
        Persistent = true;
      };
    };
  };
}