#!/usr/bin/env bash set -euo pipefail umask 077 ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) runtime_dir="$ROOT/tmp/production-operations" config=${1:-"$runtime_dir/backup.env"} if [[ "$config" != /* ]]; then config="$ROOT/$config" fi password_file="$runtime_dir/restic-password" for command in openssl ssh; do command -v "$command" >/dev/null 2>&1 || { echo "Required command is unavailable: $command" >&2 exit 2 } done if [[ -e "$config" || -e "$password_file" ]]; then echo "Refusing to replace existing production operations configuration." >&2 printf 'Config: %s\nPassword file: %s\n' "$config" "$password_file" >&2 exit 2 fi mkdir -p "$runtime_dir" chmod 700 "$ROOT/tmp" "$runtime_dir" source_target=whoneedhelp repository_target=buyvm-maya source_host=$(ssh -G "$source_target" | awk '$1 == "hostname" {print $2; exit}') repository_host=$(ssh -G "$repository_target" | awk '$1 == "hostname" {print $2; exit}') if [[ -z "$source_host" || -z "$repository_host" ]]; then echo "Could not resolve both SSH targets." >&2 exit 2 fi if [[ "$source_host" == "$repository_host" ]]; then echo "The backup repository must not resolve to the production host." >&2 exit 2 fi openssl rand -base64 48 | tr -d '\n' >"$password_file" printf '\n' >>"$password_file" chmod 600 "$password_file" cat >"$config" <