#!/usr/bin/env bash # Restore one trusted application dump into a disposable, local-only PG16 server. set -euo pipefail umask 077 [[ $EUID == 0 && $# == 1 && -f $1 ]] || exit 64 dump=$(readlink -f "$1") bin=/usr/lib/postgresql/16/bin stage=$(mktemp -d /var/tmp/atlas-application-restore.XXXXXXXX) started=$(date +%s) cleanup() { if [[ -f $stage/data/postmaster.pid ]]; then runuser -u postgres -- "$bin/pg_ctl" -D "$stage/data" -m immediate -w stop >/dev/null 2>&1 || true fi rm -rf -- "$stage" } trap cleanup EXIT chown postgres:postgres "$stage" install -o postgres -g postgres -m 0600 "$dump" "$stage/input.dump" exec 2>"$dump.restore-error.txt" runuser -u postgres -- "$bin/initdb" -D "$stage/data" -A trust --no-locale >"$stage/init.log" runuser -u postgres -- "$bin/pg_ctl" -D "$stage/data" -l "$stage/server.log" \ -o "-k $stage -p 55433 -c listen_addresses=''" -w start >/dev/null runuser -u postgres -- "$bin/createdb" -h "$stage" -p 55433 restore_check timeout 1800 runuser -u postgres -- "$bin/pg_restore" --exit-on-error --no-owner --no-privileges \ -h "$stage" -p 55433 -d restore_check "$stage/input.dump" tables=$(runuser -u postgres -- "$bin/psql" -XAt -h "$stage" -p 55433 -d restore_check \ -c "SELECT count(*) FROM pg_tables WHERE schemaname NOT IN ('pg_catalog','information_schema')") [[ $tables =~ ^[0-9]+$ && $tables -gt 0 ]] printf 'verified_utc=%s\nelapsed_seconds=%s\napplication_tables=%s\nmethod=isolated_pg16_restore_without_role_acl_replay\n' \ "$(date -u +%FT%TZ)" "$(( $(date +%s) - started ))" "$tables" >"$dump.RESTORE_CHECK" cat "$dump.RESTORE_CHECK"