R-232 (a) — DooPlex's backup mails the operator when it fails (2026-10-08)
Operator word: "Yes" in chat (2026-10-08, asked: "May I change DooPlex's backup notification so a failed run sends a mail? One setting, plus one test mail. I will not start a backup run.").
What changed (DooPlex, unversioned scripts — R-231):
/opt/backup/scripts/backup-config.sh:notify_failurenow also sends a mail through Resend (the API the CI failure mail uses) frommonitoring@felhom.eutoadmin@felhom.eu. The webhook branch is unchanged. The mail never changes a backup's exit code (return 0) and logs its outcome tobackup.log. Before/after:backup-config.sh.before,backup-config.sh.after(no secret in either). The old file is also kept beside it asbackup-config.sh.bak-20261008-080524./etc/backup/resend-api-key: new,600 root, 36 bytes, copied from the k3s Secretfelhom-system/resend-apiwithumask 077and never printed.- Nothing else in DooPlex's backup changed. No backup run was started.
Proof (two channels):
- The function's own output (
test-mail.txt):sudo bash -c 'source …/backup-config.sh; notify_failure "TEST - R-232 wiring check, no backup ran"'→notify_failure: mail accepted id=01a11a1d-…,rc=0, and the line[INFO] notify_failure: failure mail sent to admin@felhom.euinbackup.log. - The inbox (Gmail connector, which reads the admin@ catch-all): one message, 2026-10-08T06:05:25Z, from
monitoring@felhom.eu, subject[DooPlex backup] FAILED: TEST - R-232 wiring check, no backup ran, label INBOX.
Not proven: a real failure path end to end (no backup was forced to fail, by the brief). The callers are the
existing ERR traps and backup-all.sh's component check, unchanged.
Rollback: sudo cp -p /opt/backup/scripts/backup-config.sh.bak-20261008-080524 /opt/backup/scripts/backup-config.sh
and sudo rm /etc/backup/resend-api-key.
If the Resend key is rotated: this file must be refreshed too (a second consumer of Secret/resend-api, beside the
hub and contact-mailer).