ca-sign: Tell clients using our CA cert to update CRL every 30 days
[clinton/scripts.git] / hcoop-backup
1 #!/bin/bash -e
2
3 #
4 # run this script as root, on deleuze, in a directory that WILL NOT be
5 # part of the backup (/tmp is a good choice).
6 #
7
8 # FIXME:
9 # postgres dumps
10 # mysql dumps
11
12 # for catsync
13 PATH=$PATH:/home/megacz_admin/
14 COMPRESS_EXT=.bz2
15 COMPRESS_PROG=bzip2
16
17 #KEYFILE=$1
18 KEYFILE=/etc/backup-encryption-key
19 BACKUPDIR=/afs/megacz.com/hcoop-backup/
20
21 cd $BACKUPDIR
22 find * -prune -ctime +5 -exec rm -rf {} \;
23
24 SUBDIR=`date +%Y.%m.%d`
25 rm -rf $SUBDIR
26 mkdir -p $SUBDIR
27 cd $SUBDIR
28
29 echo 'I am in:'
30 pwd
31 echo
32
33 echo building package lists...
34 dpkg-query -W -f='${Package}\n' > packages
35 (cd /; sudo find / /usr/ /usr/local/ /var/ -xdev) | sort | uniq > allfiles
36 dpkg-query -W -f='${Package}\n' | xargs dpkg -L | sort | uniq > debfiles
37 dpkg-query -W -f='${Conffiles}\n' | grep / | cut -b2- | sed 's_ .*__' | sort | uniq > conffiles
38
39 diff allfiles debfiles | grep '^<' | cut -b 3- | \
40 grep -v ^/var/cache | \
41 grep -v ^/var/tmp | \
42 grep -v ^/var/lib/dpkg | \
43 grep -v ^/var/backups | \
44 grep -v ^/var/lib/changetrack | \
45 grep -v ^/var/run | \
46 grep -v ^/var/lock | \
47 grep -v ^/var/lib/ucf | \
48 grep -v ^/vicepa | \
49 grep -v ^/home | \
50 grep -v ^/tmp | \
51 grep -v '^/afs$' | \
52 grep -v '^/$' | \
53 grep -v '^/usr/$' | \
54 grep -v ^/usr/src | \
55 grep -v '^/usr/.*\.pyc' | \
56 grep -v '^/usr/.*\.elc' | \
57 grep -v '^/usr/bin/perldoc\.stub$' | \
58 grep -v '^/usr/lib/courier/.*\.rand$' | \
59 grep -v '^/usr/lib/gconv/gconv-modules\.cache$' | \
60 grep -v '^/usr/lib/graphviz/config$' | \
61 grep -v '^/usr/lib/locale/locale-archive$' | \
62 grep -v '^/usr/share/info/dir$' | \
63 grep -v '^/usr/share/info/dir\.old$' | \
64 grep -v '^/usr/share/emacs21/site-lisp/' | \
65 grep -v '^/usr/share/emacs22/site-lisp/' | \
66 grep -v '^/usr/share/vim/addons/doc/tags$' | \
67 cat > backupfiles
68
69 cat conffiles >> backupfiles
70
71 cat backupfiles | \
72 grep -v ^/home | \
73 grep -v ^/usr/local | \
74 grep -v ^/var/spool | \
75 grep -v ^/var/log | \
76 grep -v ^/usr/lib/python2.4/ | \
77 grep -v ^/var/lib/python-support | \
78 grep -v ^/usr/share/man | \
79 grep -v ^/usr/share/perl5/IkiWiki/Plugin | \
80 grep -v ^/media | \
81 grep -v ^/vmlinuz | \
82 grep -v ^/vmlinuz.old | \
83 grep -v '^/sbin/[a-z\-]*\.modutils$' | \
84 cat > annoyingfiles-
85
86 for A in `cat annoyingfiles-`
87 do \
88 test -L "$A" || echo "$A"
89 done > annoyingfiles
90
91 cat annoyingfiles | \
92 grep -v ^/opt/dell/srvadmin/ | \
93 grep -v ^/boot/ | \
94 grep -v ^/dev/ | \
95 grep -v ^/etc/ | \
96 grep -v ^/root/ | \
97 grep -v ^/var/ | \
98 grep -v ^/lib/modules/ | \
99 grep -v ^/var/domtool/ | \
100 grep -v ^/var/lib/mysql/ | \
101 grep -v ^/var/lib/postgres/ | \
102 grep -v ^/var/lib/postgresql/ | \
103 cat > complain
104
105 grep '[a-z/]' complain && \
106 mail -a 'From: Adam Megacz <megacz@hcoop.net>' \
107 -s "automated message: annoying files found on deleuze (please do something about them)" admins@hcoop.net \
108 < complain
109
110 cp backupfiles /tmp/backupfiles
111 (cd /; sudo tar cvlpjf - --ignore-failed-read --no-recursion -C / -T /tmp/backupfiles) | \
112 $COMPRESS_PROG | \
113 ccrypt -k $KEYFILE -e | \
114 catsync hcoop.backup.tar$COMPRESS_EXT.aescrypt
115 du -chs hcoop.backup.tar$COMPRESS_EXT.aescrypt
116
117 vos listvol deleuze | \
118 tail -n +2 | \
119 head -n -3 | \
120 cut -b1-34 | \
121 grep -v "\.backup .*$" | \
122 grep -v "\.readonly .*$" | \
123 cat > volumes
124
125 echo backing up databases
126 tar -C /var/backups/databases/ -cf - . | \
127 $COMPRESS_PROG | \
128 ccrypt -k $KEYFILE -e \
129 | catsync databases.tar$COMPRESS_EXT.aescrypt
130
131 for A in `cat volumes | grep -v not-backed-up`
132 do \
133 echo "dumping afs volume $A..."
134 time (cd /; sudo vos dump -id $A -localauth -clone) | \
135 $COMPRESS_PROG | \
136 ccrypt -k $KEYFILE -e | \
137 catsync $A.dump$COMPRESS_EXT.aescrypt
138 done