- name: get list of disks changed_when: false shell: > lsblk --json --paths --filter 'MIN == 0 && TYPE == "disk" && MOUNTPOINT != "[SWAP]"' | jq '.blockdevices' register: disks - name: backup partition tables become: true shell: | if [ {{ item.type }} != disk ]; then exit 0; fi sfdisk --dump {{ item.name }} >{{ backup_directory }}/disks/{{ item.name | basename }}.sfdisk loop: "{{ disks.stdout }}" - name: get list of luks devices changed_when: false shell: > lsblk --json --paths | jq '[ .blockdevices[]|.children[]?|select(recurse(.children[]?)|.type == "crypt") ]' register: cryptdisks - name: backup luks2 headers become: true loop: "{{ cryptdisks.stdout }}" shell: | rm -f {{ backup_directory }}/disks/{{ item.children[0].name | basename }}.luks2header cryptsetup luksHeaderBackup {{ item.name }} \ --header-backup-file {{ backup_directory }}/disks/{{ item.children[0].name | basename }}.luks2header - name: backup lvm volume groups become: true shell: | if [ ! -d /etc/lvm/backup ]; then exit 0; fi for vg in /etc/lvm/backup/*; do cp $vg {{backup_directory}}/disks/${vg##*/}.volumegroup done # get list of disks # run sfdisk on it # get list of partitions with luks2 # # backup their headers # get list of partitions with lvm2 # # copy the metadata