#!/usr/bin/env bash # Keep a second LAN copy and the matching server token on titan-0b. set -euo pipefail umask 077 [[ $EUID == 0 ]] || exit 77 root=/var/backups/atlas-k3s-replica install -d -m 0700 "$root" exec 9>/run/lock/atlas-k3s-replica.lock flock -n 9 || exit 75 [[ $(df --output=avail -k "$root" | tail -1) -gt 5242880 ]] || exit 73 stage=$(mktemp -d "$root/.pending.XXXXXXXX") trap 'rm -rf -- "$stage"' EXIT exec 2>"$root/last-error.txt" timeout 900 ssh -T -p 2277 -o BatchMode=yes -o StrictHostKeyChecking=yes \ -o UserKnownHostsFile=/root/.ssh/atlas_k3s_backup_known_hosts \ -o ConnectTimeout=10 -o ServerAliveInterval=30 -o ServerAliveCountMax=3 \ -o IdentitiesOnly=yes -i /root/.ssh/atlas_k3s_backup \ atlas@192.168.22.10 export >"$stage/snapshot.tar" # Extract only the five files provided by the fixed remote command. tar -xf "$stage/snapshot.tar" -C "$stage" --no-same-owner --no-same-permissions \ k3s.dump globals.sql server-token SHA256SUMS COMPLETE rm "$stage/snapshot.tar" (cd "$stage"; sha256sum --quiet -c SHA256SUMS) test -s "$stage/k3s.dump" # Token rotation must update the protected copy on titan-db before success. cmp -s /var/lib/rancher/k3s/server/token "$stage/server-token" final="$root/snapshot-$(date -u +%Y%m%dT%H%M%SZ)" mv "$stage" "$final" ln -sfn "$(basename "$final")" "$root/.latest" mv -Tf "$root/.latest" "$root/latest" find "$root" -mindepth 1 -maxdepth 1 -type d -name 'snapshot-*' -mtime +7 -exec rm -rf -- {} + printf 'Datastore replica complete; database and server token protected locally\n'