who_need_help/scripts/init-production-operations.sh

68 lines
2.1 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
umask 077
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
runtime_dir="$ROOT/tmp/production-operations"
config=${1:-"$runtime_dir/backup.env"}
if [[ "$config" != /* ]]; then
config="$ROOT/$config"
fi
password_file="$runtime_dir/restic-password"
for command in openssl ssh; do
command -v "$command" >/dev/null 2>&1 || {
echo "Required command is unavailable: $command" >&2
exit 2
}
done
if [[ -e "$config" || -e "$password_file" ]]; then
echo "Refusing to replace existing production operations configuration." >&2
printf 'Config: %s\nPassword file: %s\n' "$config" "$password_file" >&2
exit 2
fi
mkdir -p "$runtime_dir"
chmod 700 "$ROOT/tmp" "$runtime_dir"
source_target=whoneedhelp
repository_target=buyvm-maya
source_host=$(ssh -G "$source_target" | awk '$1 == "hostname" {print $2; exit}')
repository_host=$(ssh -G "$repository_target" | awk '$1 == "hostname" {print $2; exit}')
if [[ -z "$source_host" || -z "$repository_host" ]]; then
echo "Could not resolve both SSH targets." >&2
exit 2
fi
if [[ "$source_host" == "$repository_host" ]]; then
echo "The backup repository must not resolve to the production host." >&2
exit 2
fi
openssl rand -base64 48 | tr -d '\n' >"$password_file"
printf '\n' >>"$password_file"
chmod 600 "$password_file"
cat >"$config" <<EOF
PRODUCTION_SSH_TARGET=$source_target
PRODUCTION_REMOTE_ROOT=/srv/who_need_help-production
PRODUCTION_EXPECTED_ENVIRONMENT=production
OFFSITE_RESTIC_REPOSITORY=sftp:$repository_target:backups/who_need_help-production
OFFSITE_RESTIC_PASSWORD_FILE=$password_file
OFFSITE_RESTIC_HOST=who-need-help-production
OFFSITE_RESTIC_TAG=who-need-help-production
BACKUP_ON_CALENDAR=daily
EOF
chmod 600 "$config"
printf 'Created mode-0600 operations configuration: %s\n' "$config"
printf 'Created mode-0600 Restic key file: %s\n' "$password_file"
printf 'Production resolves to: %s\n' "$source_host"
printf 'Encrypted repository resolves to a different host: %s\n' "$repository_host"
echo "The Restic key is required for every restore. Copy it to an operator-controlled password manager before relying on this backup as the only recovery copy."