c7aade4079
gates / gates (push) Successful in 3m43s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
31 lines
2.1 KiB
Markdown
31 lines
2.1 KiB
Markdown
# R-232 (a) — DooPlex's backup mails the operator when it fails (2026-10-08)
|
|
|
|
**Operator word:** "Yes" in chat (2026-10-08, asked: "May I change DooPlex's backup notification so a failed run sends a
|
|
mail? One setting, plus one test mail. I will not start a backup run.").
|
|
|
|
**What changed (DooPlex, unversioned scripts — R-231):**
|
|
- `/opt/backup/scripts/backup-config.sh`: `notify_failure` now also sends a mail through Resend (the API the CI failure
|
|
mail uses) from `monitoring@felhom.eu` to `admin@felhom.eu`. The webhook branch is unchanged. The mail never changes a
|
|
backup's exit code (`return 0`) and logs its outcome to `backup.log`. Before/after: `backup-config.sh.before`,
|
|
`backup-config.sh.after` (no secret in either). The old file is also kept beside it as
|
|
`backup-config.sh.bak-20261008-080524`.
|
|
- `/etc/backup/resend-api-key`: new, `600 root`, 36 bytes, copied from the k3s Secret `felhom-system/resend-api` with
|
|
`umask 077` and never printed.
|
|
- Nothing else in DooPlex's backup changed. **No backup run was started.**
|
|
|
|
**Proof (two channels):**
|
|
1. The function's own output (`test-mail.txt`): `sudo bash -c 'source …/backup-config.sh; notify_failure "TEST - R-232
|
|
wiring check, no backup ran"'` → `notify_failure: mail accepted id=01a11a1d-…`, `rc=0`, and the line
|
|
`[INFO] notify_failure: failure mail sent to admin@felhom.eu` in `backup.log`.
|
|
2. The inbox (Gmail connector, which reads the admin@ catch-all): one message, 2026-10-08T06:05:25Z, from
|
|
`monitoring@felhom.eu`, subject `[DooPlex backup] FAILED: TEST - R-232 wiring check, no backup ran`, label INBOX.
|
|
|
|
**Not proven:** a real failure path end to end (no backup was forced to fail, by the brief). The callers are the
|
|
existing `ERR` traps and `backup-all.sh`'s component check, unchanged.
|
|
|
|
**Rollback:** `sudo cp -p /opt/backup/scripts/backup-config.sh.bak-20261008-080524 /opt/backup/scripts/backup-config.sh`
|
|
and `sudo rm /etc/backup/resend-api-key`.
|
|
|
|
**If the Resend key is rotated:** this file must be refreshed too (a second consumer of `Secret/resend-api`, beside the
|
|
hub and contact-mailer).
|