#!/bin/sh # install.sh — install the hub DB off-site backup units on DooPlex (R-173). Root. Idempotent. # Installs the two scripts and four units, writes /etc/felhom-hub-backup/env (no secrets) when absent, and does NOT # enable the timers — enable them by hand after the first manual run (runbook Step 7): # systemctl enable --now felhom-hub-db-backup.timer felhom-hub-db-restore-test.timer # The tokens (token-push, token-restore) and enc.key are created separately, file to file, never by this script. set -eu HERE=$(cd "$(dirname "$0")" && pwd) [ "$(id -u)" = 0 ] || { echo "install.sh: run as root" >&2; exit 1; } install -m 0755 "$HERE/felhom-hub-db-backup" /usr/local/sbin/felhom-hub-db-backup install -m 0755 "$HERE/felhom-hub-db-restore-test" /usr/local/sbin/felhom-hub-db-restore-test for u in felhom-hub-db-backup.service felhom-hub-db-backup.timer felhom-hub-db-restore-test.service felhom-hub-db-restore-test.timer; do install -m 0644 "$HERE/$u" "/etc/systemd/system/$u" done install -d -m 0700 /etc/felhom-hub-backup /var/lib/felhom-hub-backup if [ ! -f /etc/felhom-hub-backup/env ]; then umask 077 cat > /etc/felhom-hub-backup/env <<'ENV' # Not secret. The tokens are in token-push / token-restore (0600), the key in enc.key (0600). PBS_REPOSITORY_PUSH='dooplex-hub@pbs!push@127.0.0.1:18007:felhom-offsite' PBS_REPOSITORY_RESTORE='dooplex-hub@pbs!restore@127.0.0.1:18007:felhom-offsite' # ep0's PBS certificate, the same pin DooPlex's PBS remote "ep0" uses (/etc/proxmox-backup/remote.cfg) PBS_FINGERPRINT='c6:07:28:3f:5b:7b:5a:41:90:28:d7:ca:4f:37:14:70:56:39:2e:2f:0b:71:e8:06:ca:60:4a:d5:56:5f:3c:fd' ENV fi systemctl daemon-reload echo "install.sh: installed; timers NOT enabled (see the header)"