Files
felhom.eu/scripts/hub-db-backup/install.sh
T

28 lines
1.7 KiB
Bash
Executable File

#!/bin/sh
# install.sh — install the hub DB off-site backup units on DooPlex (R-173). Root. Idempotent.
# Installs the two scripts and four units, writes /etc/felhom-hub-backup/env (no secrets) when absent, and does NOT
# enable the timers — enable them by hand after the first manual run (runbook Step 7):
# systemctl enable --now felhom-hub-db-backup.timer felhom-hub-db-restore-test.timer
# The tokens (token-push, token-restore) and enc.key are created separately, file to file, never by this script.
set -eu
HERE=$(cd "$(dirname "$0")" && pwd)
[ "$(id -u)" = 0 ] || { echo "install.sh: run as root" >&2; exit 1; }
install -m 0755 "$HERE/felhom-hub-db-backup" /usr/local/sbin/felhom-hub-db-backup
install -m 0755 "$HERE/felhom-hub-db-restore-test" /usr/local/sbin/felhom-hub-db-restore-test
for u in felhom-hub-db-backup.service felhom-hub-db-backup.timer felhom-hub-db-restore-test.service felhom-hub-db-restore-test.timer; do
install -m 0644 "$HERE/$u" "/etc/systemd/system/$u"
done
install -d -m 0700 /etc/felhom-hub-backup /var/lib/felhom-hub-backup
if [ ! -f /etc/felhom-hub-backup/env ]; then
umask 077
cat > /etc/felhom-hub-backup/env <<'ENV'
# Not secret. The tokens are in token-push / token-restore (0600), the key in enc.key (0600).
PBS_REPOSITORY_PUSH='dooplex-hub@pbs!push@127.0.0.1:18007:felhom-offsite'
PBS_REPOSITORY_RESTORE='dooplex-hub@pbs!restore@127.0.0.1:18007:felhom-offsite'
# ep0's PBS certificate, the same pin DooPlex's PBS remote "ep0" uses (/etc/proxmox-backup/remote.cfg)
PBS_FINGERPRINT='c6:07:28:3f:5b:7b:5a:41:90:28:d7:ca:4f:37:14:70:56:39:2e:2f:0b:71:e8:06:ca:60:4a:d5:56:5f:3c:fd'
ENV
fi
systemctl daemon-reload
echo "install.sh: installed; timers NOT enabled (see the header)"