atlas-iac/scripts/ops/k3s_backup_replica.sh

33 lines
1.5 KiB
Bash
Executable File

#!/usr/bin/env bash
# Keep a second LAN copy and the matching server token on titan-0b.
set -euo pipefail
umask 077
[[ $EUID == 0 ]] || exit 77
root=/var/backups/atlas-k3s-replica
install -d -m 0700 "$root"
exec 9>/run/lock/atlas-k3s-replica.lock
flock -n 9 || exit 75
[[ $(df --output=avail -k "$root" | tail -1) -gt 5242880 ]] || exit 73
stage=$(mktemp -d "$root/.pending.XXXXXXXX")
trap 'rm -rf -- "$stage"' EXIT
exec 2>"$root/last-error.txt"
timeout 900 ssh -T -p 2277 -o BatchMode=yes -o StrictHostKeyChecking=yes \
-o UserKnownHostsFile=/root/.ssh/atlas_k3s_backup_known_hosts \
-o ConnectTimeout=10 -o ServerAliveInterval=30 -o ServerAliveCountMax=3 \
-o IdentitiesOnly=yes -i /root/.ssh/atlas_k3s_backup \
atlas@192.168.22.10 export >"$stage/snapshot.tar"
# Extract only the five files provided by the fixed remote command.
tar -xf "$stage/snapshot.tar" -C "$stage" --no-same-owner --no-same-permissions \
k3s.dump globals.sql server-token SHA256SUMS COMPLETE
rm "$stage/snapshot.tar"
(cd "$stage"; sha256sum --quiet -c SHA256SUMS)
test -s "$stage/k3s.dump"
# Token rotation must update the protected copy on titan-db before success.
cmp -s /var/lib/rancher/k3s/server/token "$stage/server-token"
final="$root/snapshot-$(date -u +%Y%m%dT%H%M%SZ)"
mv "$stage" "$final"
ln -sfn "$(basename "$final")" "$root/.latest"
mv -Tf "$root/.latest" "$root/latest"
find "$root" -mindepth 1 -maxdepth 1 -type d -name 'snapshot-*' -mtime +7 -exec rm -rf -- {} +
printf 'Datastore replica complete; database and server token protected locally\n'