]> git.somenet.org - root/pub/somesible.git/blob - roles/base/backup/files/default/backup.sh
roles/base/backup/files
[root/pub/somesible.git] / roles / base / backup / files / default / backup.sh
1 #!/bin/bash
2 ################################################
3 ### Managed by someone's ansible provisioner ###
4 ################################################
5 # Part of: https://git.somenet.org/root/pub/somesible.git
6 # 2017-2026 by someone <someone@somenet.org>
7 #
8
9 umask 0077
10 cd /tmp
11 export ERRCODE=0
12
13 export BORG_UNKNOWN_UNENCRYPTED_REPO_ACCESS_IS_OK="yes"
14 export BORG_RELOCATED_REPO_ACCESS_IS_OK="yes"
15 export BORG_PACK_MAX_SIZE="8000000"
16
17
18 function backup {
19     export BKPREPO=${1} # backup repo (should be: "/bkp/storage-local/$host/$path" or for ssh: "user@server:$path")
20     export BKPHOST=${2} # src-host
21     export BKPPATH=${3} # abs-path on src-host
22     export BKPKEEP=${4} # pruning-settings
23     export BKPPASS=${5} # borg key passphrase
24
25     BKPPATH_ESCAPED=$(echo -n "$BKPPATH"|sed -e 's#/#-#g') # contains first "/"
26
27     # Override if exists, but also allow to have BORG_PASSPHRASE set elsewhere.
28     if [[ -n "$BKPPASS" ]]; then
29         export BORG_PASSPHRASE=${BKPPASS}
30     fi
31     if [[ -n "$BORG_PASSPHRASE" ]]; then
32         borg info "$BKPREPO" >/dev/null 2>&1 || borg init --umask 0077 -e repokey-blake2 --make-parent-dirs "$BKPREPO"
33     else
34         borg info "$BKPREPO" >/dev/null 2>&1 || borg init --umask 0077 -e none --make-parent-dirs "$BKPREPO"
35     fi
36
37     echo "# Merged on: $(date -Isec)" > "/bkp/local/exclude.conf.d/.merged.$BKPHOST-$BKPPATH_ESCAPED"
38     for file in /bkp/local/exclude.conf.d/$BKPHOST-$BKPPATH_ESCAPED*; do
39         echo -e "\n\n# $file" >> "/bkp/local/exclude.conf.d/.merged.$BKPHOST-$BKPPATH_ESCAPED"
40         cat "$file" >> "/bkp/local/exclude.conf.d/.merged.$BKPHOST-$BKPPATH_ESCAPED"
41     done
42
43     borg create --umask 0077 --info --list --stats --noctime --nobirthtime --exclude-caches --exclude-from "/bkp/local/exclude.conf.d/.merged.$BKPHOST-$BKPPATH_ESCAPED" "$BKPREPO::$BKPHOST-$BKPPATH_ESCAPED--{now}" "$BKPPATH"
44         exit_status=$?;
45         if [ $exit_status -ne 0 ]; then
46             export ERRCODE="$exit_status";
47             echo "** backup.sh (backup:create): non-zero exitcode: $exit_status"
48         fi
49
50     backup_prune "$BKPREPO" "$BKPKEEP" "$BKPPASS"
51 }
52
53 function backup2 {
54     export BKPREPO=${1} # backup repo (should be: "/bkp/storage-local/$host/$path" or for ssh: "ssh://user@server/$path")
55     export BKPHOST=${2} # src-host
56     export BKPPATH=${3} # abs-path on src-host
57     export BKPKEEP=${4} # pruning-settings
58     export BKPPASS=${5} # borg key passphrase
59
60     BKPPATH_ESCAPED=$(echo -n "$BKPPATH"|sed -e 's#/#-#g') # contains first "/"
61
62     # Override if exists, but also allow to have BORG_PASSPHRASE set elsewhere.
63     if [[ -n "$BKPPASS" ]]; then
64         export BORG_PASSPHRASE=${BKPPASS}
65     fi
66     if [[ -n "$BORG_PASSPHRASE" ]]; then
67         borg2 repo-info --repo "$BKPREPO" >/dev/null 2>&1 || borg2 repo-create --umask 0077 -e repokey-blake2-chacha20-poly1305 --repo "$BKPREPO"
68     else
69         borg2 repo-info --repo "$BKPREPO" >/dev/null 2>&1 || borg2 repo-create --umask 0077 -e none --repo "$BKPREPO"
70     fi
71
72     echo "# Merged on: $(date -Isec)" > "/bkp/local/exclude.conf.d/.merged.$BKPHOST-$BKPPATH_ESCAPED"
73     for file in /bkp/local/exclude.conf.d/$BKPHOST-$BKPPATH_ESCAPED*; do
74         echo -e "\n\n# $file" >> "/bkp/local/exclude.conf.d/.merged.$BKPHOST-$BKPPATH_ESCAPED"
75         cat "$file" >> "/bkp/local/exclude.conf.d/.merged.$BKPHOST-$BKPPATH_ESCAPED"
76     done
77
78     echo "** backup.sh(backup2:create) ********************************************************************************************************************************"
79     borg2 create --umask 0077 --info --list --stats --nobirthtime --compression zstd --exclude-caches --exclude-from "/bkp/local/exclude.conf.d/.merged.$BKPHOST-$BKPPATH_ESCAPED" --repo "$BKPREPO" "$BKPHOST-$BKPPATH_ESCAPED" "$BKPPATH"
80         exit_status=$?;
81         if [ $exit_status -ne 0 ]; then
82             export ERRCODE="$exit_status";
83             echo "** backup.sh (backup2:create): non-zero exitcode: $exit_status"
84         fi
85
86     backup_prune2 "$BKPREPO" "$BKPKEEP" "$BKPPASS"
87 }
88
89 function backup_cmd {
90     export BKPREPO=${1} # backup repo (should be: "/bkp/storage-local/$host/$path" or for ssh: "user@server:$path")
91     export BKPNAME=${2} # backup name
92     export BKPCMD=${3}  # command to run
93     export BKPKEEP=${4} # pruning-settings
94     export BKPPASS=${5} # borg key passphrase
95
96     BKPPATH_ESCAPED=$(echo -n "$BKPPATH"|sed -e 's#/#-#g') # contains first "/"
97
98     # Override if exists, but also allow to have BORG_PASSPHRASE set elsewhere.
99     if [[ -n "$BKPPASS" ]]; then
100         export BORG_PASSPHRASE=${BKPPASS}
101     fi
102     if [[ -n "$BORG_PASSPHRASE" ]]; then
103         borg info "$BKPREPO" >/dev/null 2>&1 || borg init --umask 0077 -e repokey-blake2 --make-parent-dirs "$BKPREPO"
104     else
105         borg info "$BKPREPO" >/dev/null 2>&1 || borg init --umask 0077 -e none --make-parent-dirs "$BKPREPO"
106     fi
107
108     borg create --umask 0077 --info --stats --noctime --nobirthtime --compression zstd --files-cache disabled --content-from-command -- "$BKPREPO::$BKPNAME--{now}" $BKPCMD
109         exit_status=$?;
110         if [ $exit_status -ne 0 ]; then
111             export ERRCODE="$exit_status";
112             echo "** backup.sh (backup_cmd:create): non-zero exitcode: $exit_status"
113         fi
114
115     backup_prune "$BKPREPO" "$BKPKEEP" "$BKPPASS"
116 }
117
118 function backup_cmd2 {
119     export BKPREPO=${1} # backup repo (should be: "/bkp/storage-local/$host/$path" or for ssh: "ssh://user@server/$path")
120     export BKPNAME=${2} # backup name
121     export BKPCMD=${3}  # command to run
122     export BKPKEEP=${4} # pruning-settings
123     export BKPPASS=${5} # borg key passphrase
124
125     BKPPATH_ESCAPED=$(echo -n "$BKPPATH"|sed -e 's#/#-#g') # contains first "/"
126
127     # Override if exists, but also allow to have BORG_PASSPHRASE set elsewhere.
128     if [[ -n "$BKPPASS" ]]; then
129         export BORG_PASSPHRASE=${BKPPASS}
130     fi
131     if [[ -n "$BORG_PASSPHRASE" ]]; then
132         borg2 repo-info --repo "$BKPREPO" >/dev/null 2>&1 || borg2 repo-create --umask 0077 -e repokey-blake2-chacha20-poly1305 --repo "$BKPREPO"
133     else
134         borg2 repo-info --repo "$BKPREPO" >/dev/null 2>&1 || borg2 repo-create --umask 0077 -e none --repo "$BKPREPO"
135     fi
136
137     echo "** backup.sh(backup_cmd2:create) ********************************************************************************************************************************"
138     borg2 create --umask 0077 --info --stats --nobirthtime --compression zstd --files-cache disabled --content-from-command --repo "$BKPREPO" "$BKPNAME" -- $BKPCMD
139         exit_status=$?;
140         if [ $exit_status -ne 0 ]; then
141             export ERRCODE="$exit_status";
142             echo "** backup.sh (backup_cmd2:create): non-zero exitcode: $exit_status"
143         fi
144
145     backup_prune2 "$BKPREPO" "$BKPKEEP" "$BKPPASS"
146 }
147
148 function backup_prune {
149     export BKPREPO=${1} # backup repo (should be: "/bkp/storage-local/$host/$path" or for ssh: "user@server:$path")
150     export BKPKEEP=${2} # pruning-settings
151     export BKPPASS=${3} # borg key passphrase
152
153     # Override if exists, but also allow to have BORG_PASSPHRASE set elsewhere.
154     if [[ -n "$BKPPASS" ]]; then
155         export BORG_PASSPHRASE=${BKPPASS}
156     fi
157
158     if [[ -z "$BKPKEEP" ]]; then
159         echo "** backup.sh(backup_prune): No prune settings, skipping"
160     else
161         borg prune --umask 0077 --list --stats --save-space --keep-last 1 $BKPKEEP "$BKPREPO"
162             exit_status=$?;
163             if [ $exit_status -ne 0 ]; then
164                 export ERRCODE="$exit_status";
165                 echo "** backup.sh (backup_prune:prune): non-zero exitcode: $exit_status"
166             fi
167        borg compact --umask 0077 -v --cleanup-commits "$BKPREPO"
168             exit_status=$?;
169             if [ $exit_status -ne 0 ]; then
170                 export ERRCODE="$exit_status";
171                 echo "** backup.sh (backup_prune:compact): non-zero exitcode: $exit_status"
172             fi
173     fi
174 }
175
176 function backup_prune2 {
177     export BKPREPO=${1} # backup repo (should be: "/bkp/storage-local/$host/$path" or for ssh: "ssh://user@server/$path")
178     export BKPKEEP=${2} # pruning-settings
179     export BKPPASS=${3} # borg key passphrase
180
181     # Override if exists, but also allow to have BORG_PASSPHRASE set elsewhere.
182     if [[ -n "$BKPPASS" ]]; then
183         export BORG_PASSPHRASE=${BKPPASS}
184     fi
185
186     if [[ -z "$BKPKEEP" ]]; then
187         echo "** backup.sh(backup_prune2): No prune settings, skipping"
188     else
189         echo "** backup.sh(backup_prune2:prune) ********************************************************************************************************************************"
190         time borg2 prune --umask 0077 --list --keep-last 1 $BKPKEEP --repo "$BKPREPO"
191             exit_status=$?;
192             if [ $exit_status -ne 0 ]; then
193                 export ERRCODE="$exit_status";
194                 echo "** backup.sh (backup_prune2:prune): non-zero exitcode: $exit_status"
195             fi
196         echo "** backup.sh(backup_prune2:compact) ********************************************************************************************************************************"
197         time borg2 compact --umask 0077 -v --stats --repo "$BKPREPO"
198             exit_status=$?;
199             if [ $exit_status -ne 0 ]; then
200                 export ERRCODE="$exit_status";
201                 echo "** backup.sh (backup_prune2:compact): non-zero exitcode: $exit_status"
202             fi
203     fi
204 }
205
206
207 # run local pre managed
208 if [ -e "/bkp/local/backup.conf.local-pre" ]; then
209     echo "** backup.sh: running /bkp/local/backup.conf.local-pre"
210     source /bkp/local/backup.conf.local-pre
211 fi
212
213 # run managed
214 echo "** backup.sh: BEGIN: $(date -Isec)"
215 echo "** backup.sh: running /bkp/local/backup.conf.managed"
216 source /bkp/local/backup.conf.managed
217
218 # run local additions
219 if [ -e "/bkp/local/backup.conf.local" ]; then
220     echo "** backup.sh: running /bkp/local/backup.conf.local"
221     source /bkp/local/backup.conf.local
222 fi
223 echo "** backup.sh: DONE: $(date -Isec)"
224
225
226 unset BORG_UNKNOWN_UNENCRYPTED_REPO_ACCESS_IS_OK
227 unset BORG_RELOCATED_REPO_ACCESS_IS_OK
228
229 exit $ERRCODE