atlas-iac/scripts/ops/k3s_backup_verify.sh

33 lines
1.6 KiB
Bash
Executable File

#!/usr/bin/env bash
# Restore a backup into a disposable PostgreSQL 16 cluster with no TCP listener.
set -euo pipefail
umask 077
[[ $EUID == 0 && $# == 1 ]] || exit 64
snapshot=$(readlink -f "$1")
[[ -f $snapshot/COMPLETE && -f $snapshot/k3s.dump ]] || exit 66
(cd "$snapshot"; sha256sum --quiet -c SHA256SUMS)
bin=/usr/lib/postgresql/16/bin
stage=$(mktemp -d /var/tmp/atlas-k3s-restore.XXXXXXXX)
started=$(date +%s)
cleanup() {
if [[ -f $stage/data/postmaster.pid ]]; then
runuser -u postgres -- "$bin/pg_ctl" -D "$stage/data" -m immediate -w stop >/dev/null 2>&1 || true
fi
rm -rf -- "$stage"
}
trap cleanup EXIT
chown postgres:postgres "$stage"
install -o postgres -g postgres -m 0600 "$snapshot/k3s.dump" "$stage/k3s.dump"
exec 2>"$snapshot/restore-error.txt"
runuser -u postgres -- "$bin/initdb" -D "$stage/data" -A trust --no-locale >"$stage/init.log"
runuser -u postgres -- "$bin/pg_ctl" -D "$stage/data" -l "$stage/server.log" \
-o "-k $stage -p 55432 -c listen_addresses=''" -w start >/dev/null
runuser -u postgres -- "$bin/createdb" -h "$stage" -p 55432 k3s
timeout 900 runuser -u postgres -- "$bin/pg_restore" --exit-on-error --no-owner --no-privileges \
-h "$stage" -p 55432 -d k3s "$stage/k3s.dump"
rows=$(runuser -u postgres -- "$bin/psql" -XAt -h "$stage" -p 55432 -d k3s -c 'SELECT count(*) FROM kine')
[[ $rows =~ ^[0-9]+$ && $rows -gt 0 ]]
printf 'verified_utc=%s\nelapsed_seconds=%s\nkine_rows=%s\nmethod=isolated_pg16_restore_without_role_acl_replay\n' \
"$(date -u +%FT%TZ)" "$(( $(date +%s) - started ))" "$rows" >"$snapshot/RESTORE_CHECK"
cat "$snapshot/RESTORE_CHECK"