1707c928a9
gates / gates (push) Successful in 5m4s
Part A plan + readings, Part E read-backs (R-861 a, R-518) in audits/dooplex-survival-2026-10-09/. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
25 lines
1.5 KiB
Bash
Executable File
25 lines
1.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# install.sh — install the Gitea + secrets off-site units on DooPlex (R-232). Root. Idempotent.
|
|
# Installs the three scripts and five units, writes /etc/felhom-dooplex-offsite/env (no secrets) when absent, and does
|
|
# NOT enable the timers — enable them by hand after the first manual run:
|
|
# systemctl enable --now felhom-dooplex-offsite.timer felhom-dooplex-offsite-restore-test.timer
|
|
# The tokens are the hub-DB ones (/etc/felhom-hub-backup/token-push, token-restore), read in place. enc.key is created
|
|
# separately (proxmox-backup-client key create --kdf none), never by this script.
|
|
set -eu
|
|
HERE=$(cd "$(dirname "$0")" && pwd)
|
|
[ "$(id -u)" = 0 ] || { echo "install.sh: run as root" >&2; exit 1; }
|
|
for s in felhom-dooplex-offsite felhom-dooplex-offsite-restore-test felhom-backup-failmail; do
|
|
install -m 0755 "$HERE/$s" "/usr/local/sbin/$s"
|
|
done
|
|
for u in felhom-dooplex-offsite.service felhom-dooplex-offsite.timer felhom-dooplex-offsite-restore-test.service \
|
|
felhom-dooplex-offsite-restore-test.timer felhom-backup-failmail@.service; do
|
|
install -m 0644 "$HERE/$u" "/etc/systemd/system/$u"
|
|
done
|
|
install -d -m 0700 /etc/felhom-dooplex-offsite /var/lib/felhom-dooplex-offsite
|
|
if [ ! -f /etc/felhom-dooplex-offsite/env ]; then
|
|
umask 077
|
|
grep -E '^(PBS_REPOSITORY_PUSH|PBS_REPOSITORY_RESTORE|PBS_FINGERPRINT)=' /etc/felhom-hub-backup/env > /etc/felhom-dooplex-offsite/env
|
|
fi
|
|
systemctl daemon-reload
|
|
echo "install.sh: installed; timers NOT enabled (see the header)"
|