68 lines
2.1 KiB
Bash
Executable File
68 lines
2.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
umask 077
|
|
|
|
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
|
|
runtime_dir="$ROOT/tmp/production-operations"
|
|
config=${1:-"$runtime_dir/backup.env"}
|
|
|
|
if [[ "$config" != /* ]]; then
|
|
config="$ROOT/$config"
|
|
fi
|
|
|
|
password_file="$runtime_dir/restic-password"
|
|
|
|
for command in openssl ssh; do
|
|
command -v "$command" >/dev/null 2>&1 || {
|
|
echo "Required command is unavailable: $command" >&2
|
|
exit 2
|
|
}
|
|
done
|
|
|
|
if [[ -e "$config" || -e "$password_file" ]]; then
|
|
echo "Refusing to replace existing production operations configuration." >&2
|
|
printf 'Config: %s\nPassword file: %s\n' "$config" "$password_file" >&2
|
|
exit 2
|
|
fi
|
|
|
|
mkdir -p "$runtime_dir"
|
|
chmod 700 "$ROOT/tmp" "$runtime_dir"
|
|
|
|
source_target=whoneedhelp
|
|
repository_target=buyvm-maya
|
|
|
|
source_host=$(ssh -G "$source_target" | awk '$1 == "hostname" {print $2; exit}')
|
|
repository_host=$(ssh -G "$repository_target" | awk '$1 == "hostname" {print $2; exit}')
|
|
|
|
if [[ -z "$source_host" || -z "$repository_host" ]]; then
|
|
echo "Could not resolve both SSH targets." >&2
|
|
exit 2
|
|
fi
|
|
|
|
if [[ "$source_host" == "$repository_host" ]]; then
|
|
echo "The backup repository must not resolve to the production host." >&2
|
|
exit 2
|
|
fi
|
|
|
|
openssl rand -base64 48 | tr -d '\n' >"$password_file"
|
|
printf '\n' >>"$password_file"
|
|
chmod 600 "$password_file"
|
|
|
|
cat >"$config" <<EOF
|
|
PRODUCTION_SSH_TARGET=$source_target
|
|
PRODUCTION_REMOTE_ROOT=/srv/who_need_help-production
|
|
PRODUCTION_EXPECTED_ENVIRONMENT=production
|
|
OFFSITE_RESTIC_REPOSITORY=sftp:$repository_target:backups/who_need_help-production
|
|
OFFSITE_RESTIC_PASSWORD_FILE=$password_file
|
|
OFFSITE_RESTIC_HOST=who-need-help-production
|
|
OFFSITE_RESTIC_TAG=who-need-help-production
|
|
BACKUP_ON_CALENDAR=daily
|
|
EOF
|
|
chmod 600 "$config"
|
|
|
|
printf 'Created mode-0600 operations configuration: %s\n' "$config"
|
|
printf 'Created mode-0600 Restic key file: %s\n' "$password_file"
|
|
printf 'Production resolves to: %s\n' "$source_host"
|
|
printf 'Encrypted repository resolves to a different host: %s\n' "$repository_host"
|
|
echo "The Restic key is required for every restore. Copy it to an operator-controlled password manager before relying on this backup as the only recovery copy."
|