hcoop-backup: More work.
[hcoop/scripts.git] / hcoop-backup
CommitLineData
6d52e269 1#!/bin/bash -e
2
3#
4b645870 4# it is dangerous to remove the "-e" above; please don't do that.
6d52e269 5#
6
4b645870 7#
8# run this script as root, on deleuze
9#
6d52e269 10
be9bd94d 11exec >& /var/log/backup-to-s3-log
44b7f284 12
4b645870 13PATH=$PATH:/bin:/usr/bin:/sbin:/usr/sbin
44b7f284 14#COMPRESS_EXT=.bz2
15#COMPRESS_PROG=bzip2
16COMPRESS_EXT=.gz
17COMPRESS_PROG=gzip
bee5bcbc 18# units for BWLIMIT are KB/s
451f65fd 19BWLIMIT=325
bac71193 20# units for CHUNKSIZE are MB/s
21CHUNKSIZE=5000
24b2faa6 22
4b645870 23IFS=$'\n'
24
be9bd94d 25SCRIPTDIR=$(dirname $0)
6d52e269 26KEYFILE=/etc/backup-encryption-key
c13b2355 27BUCKET=hcoop.net-backups
28BACKUPDIR=full
be9bd94d 29BACKUPTMP=/var/backups/hcoop-backup-testing
c13b2355 30SUBDIR=$(date +%Y.%m.%d)
bee5bcbc 31
c13b2355 32export S3_ACCESS_KEY_ID=$(cat ~mwolson_admin/.amazon/access.key)
33export S3_SECRET_ACCESS_KEY=~mwolson_admin/.amazon/secret.key
be9bd94d 34
35function s3_cmd () {
c13b2355 36 # $1: command (get|put|ls|rm)
bac71193 37 # $2: remote file
38 # $3: local file
39 local cmd=$1
40 shift
41 local bwarg
42 if test "$cmd" = "put"; then
43 bwarg="${BWLIMIT}K";
44 else
45 bwarg=
46 fi
47 $SCRIPTDIR/s3 $cmd $BUCKET "$1" "$2" $bwarg
be9bd94d 48}
bee5bcbc 49
50function copy_over () {
51 # Move file to its offsite destination
52 # $1: file, $2: relative directory (optional)
53 if test -z "$1" || test -n "$3"; then
54 echo "Bad programming"
55 exit 1
56 fi
57 local FILE=$1
58 local DEST=$BACKUPDIR/$SUBDIR
59 if test -n "$2"; then
60 DEST=$DEST/$2
61 fi
bac71193 62 split -d -b ${CHUNKSIZE}m $FILE ${FILE}.
63 for i in ${FILE}.*; do
64 s3_cmd put $DEST/$i $i
65 rm -f $i
66 done
bee5bcbc 67 rm -f $FILE
68}
24b2faa6 69
be9bd94d 70function prune_old_backups () {
71 local oldpwd=$PWD
72 cd $BACKUPDIR
73 find . -mindepth 1 -maxdepth 1 -type d -ctime +7 \
74 -execdir rm -fr '{}' \; || true
75 rm -rf $SUBDIR
76 mkdir -p $SUBDIR
77 cd $oldpwd
78}
79
bac71193 80#prune_old_backups
be9bd94d 81
bee5bcbc 82mkdir -p $BACKUPTMP
83cd $BACKUPTMP
24b2faa6 84
4b645870 85groups
24b2faa6 86echo 'I am in:'
87pwd
88echo
6d52e269 89
90echo building package lists...
24b2faa6 91dpkg-query -W -f='${Package}\n' > packages
4b645870 92(cd /; find / /usr/ /usr/local/ /var/ -xdev) | sort | uniq > allfiles
24b2faa6 93dpkg-query -W -f='${Package}\n' | xargs dpkg -L | sort | uniq > debfiles
bee5bcbc 94dpkg-query -W -f='${Conffiles}\n' | grep / | cut -b2- | \
95 sed 's_ .*__' | sort | uniq > conffiles
6d52e269 96
97diff allfiles debfiles | grep '^<' | cut -b 3- | \
98 grep -v ^/var/cache | \
99 grep -v ^/var/tmp | \
100 grep -v ^/var/lib/dpkg | \
101 grep -v ^/var/backups | \
102 grep -v ^/var/lib/changetrack | \
12e40abc 103 grep -v ^/var/local/lib/spamd | \
6d52e269 104 grep -v ^/var/run | \
105 grep -v ^/var/lock | \
106 grep -v ^/var/lib/ucf | \
107 grep -v ^/vicepa | \
108 grep -v ^/home | \
109 grep -v ^/tmp | \
110 grep -v '^/afs$' | \
111 grep -v '^/$' | \
112 grep -v '^/usr/$' | \
113 grep -v ^/usr/src | \
92a7af97 114 grep -v '^/usr/.*\.pyc' | \
115 grep -v '^/usr/.*\.elc' | \
116 grep -v '^/usr/bin/perldoc\.stub$' | \
5b84f395 117 grep -v '^/usr/bin/.*\.notslocate$' | \
d327aed8 118 grep -v '^/usr/lib/courier/.*\.rand$' | \
50f51a78 119 grep -v '^/usr/lib/gconv/gconv-modules\.cache$' | \
4df0bc18 120 grep -v '^/usr/lib/graphviz/config$' | \
50f51a78 121 grep -v '^/usr/lib/locale/locale-archive$' | \
24b2faa6 122 grep -v '^/usr/share/info/dir$' | \
50f51a78 123 grep -v '^/usr/share/info/dir\.old$' | \
24b2faa6 124 grep -v '^/usr/share/emacs21/site-lisp/' | \
125 grep -v '^/usr/share/emacs22/site-lisp/' | \
2c5daf49 126 grep -v '^/usr/share/snmp/mibs/\.index$' | \
ae0e82f0 127 grep -v '^/usr/share/vim/addons/doc/tags$' \
128 > backupfiles
6d52e269 129
24b2faa6 130cat conffiles >> backupfiles
131
6d52e269 132cat backupfiles | \
133 grep -v ^/home | \
134 grep -v ^/usr/local | \
135 grep -v ^/var/spool | \
136 grep -v ^/var/log | \
137 grep -v ^/usr/lib/python2.4/ | \
138 grep -v ^/var/lib/python-support | \
ae0e82f0 139 grep -v ^/usr/share/jed/lib | \
6d52e269 140 grep -v ^/usr/share/man | \
4df0bc18 141 grep -v ^/usr/share/perl5/IkiWiki/Plugin | \
6d52e269 142 grep -v ^/media | \
143 grep -v ^/vmlinuz | \
144 grep -v ^/vmlinuz.old | \
92a7af97 145 grep -v '^/sbin/[a-z\-]*\.modutils$' | \
6d52e269 146 grep -v ^/opt/dell/srvadmin/ | \
147 grep -v ^/boot/ | \
24b2faa6 148 grep -v ^/dev/ | \
6d52e269 149 grep -v ^/etc/ | \
150 grep -v ^/root/ | \
151 grep -v ^/var/ | \
152 grep -v ^/lib/modules/ | \
153 grep -v ^/var/domtool/ | \
154 grep -v ^/var/lib/mysql/ | \
155 grep -v ^/var/lib/postgres/ | \
156 grep -v ^/var/lib/postgresql/ | \
bee5bcbc 157 xargs -I{} -d\\n -- bash -c "test -L '{}' || echo '{}'" > complain
6d52e269 158
bee5bcbc 159F=hcoop.backup.tar$COMPRESS_EXT.aescrypt
4b645870 160tar clpf - --ignore-failed-read --no-recursion -C / -T backupfiles | \
eede979f 161 $COMPRESS_PROG | \
bee5bcbc 162 ccrypt -k $KEYFILE -e > $F
163copy_over $F
481c2d5f 164
165# Acquire lock before messing with spamd
166COUNT=0
167LOCK=/var/local/lib/spamd/.lock
168while test -f $LOCK; do
169 sleep 2m
170 COUNT=$(expr $COUNT + 1)
171 if test $COUNT -eq 10; then
172 # Enough waiting. Kill the process.
173 P=$(cat $LOCK) || :
174 test -n "$P" && kill $P || :
175 rm -f $LOCK
176 break
177 fi
178done
179touch $LOCK
180
bee5bcbc 181F=common.spamd.tar$COMPRESS_EXT.aescrypt
481c2d5f 182tar clpf - --ignore-failed-read -C / /var/local/lib/spamd | \
183 $COMPRESS_PROG | \
bee5bcbc 184 ccrypt -k $KEYFILE -e > $F.new
481c2d5f 185rm -f $LOCK
bee5bcbc 186copy_over $F.new ..
481c2d5f 187
bee5bcbc 188test -s $BACKUPDIR/$F.new && \
189 mv $BACKUPDIR/$F.new $BACKUPDIR/$F
481c2d5f 190
24b2faa6 191vos listvol deleuze | \
24b2faa6 192 tail -n +2 | \
193 head -n -3 | \
194 cut -b1-34 | \
195 grep -v "\.backup .*$" | \
eede979f 196 grep -v "\.readonly .*$" | \
4b645870 197 sed 's_^ .*__' | \
198 sed 's_ .*$__' | \
ae0e82f0 199 grep '[A-Za-z]' \
200 > volumes
24b2faa6 201
4b645870 202cat volumes | \
203 grep -v not-backed-up | \
204 xargs -I{} -d\\n -- \
205 bash -c \
bee5bcbc 206 "F={}.dump$COMPRESS_EXT.aescrypt ;
207 vos dump -id {} -localauth -clone |
208 $COMPRESS_PROG | ccrypt -k $KEYFILE -e > \$F ;
ae0e82f0 209 < \$F catsync -b $BWLIMIT $BACKUPDIR/$SUBDIR/\$F ;
bee5bcbc 210 rm -f \$F"
4b645870 211
212echo backing up databases
bee5bcbc 213F=databases.tar$COMPRESS_EXT.aescrypt
4b645870 214tar -C /var/backups/databases/ -cf - . | \
215 $COMPRESS_PROG | \
bee5bcbc 216 ccrypt -k $KEYFILE -e > $F
217copy_over $F
4b645870 218
219grep '[a-z/]' complain && \
bee5bcbc 220 mail -a 'From: The Backup Program <backups@deleuze.hcoop.net>' \
4b645870 221 -s "automated message: annoying files found on deleuze (please do something about them)" admins@hcoop.net \
222 < complain \
223 || true
44b7f284 224
225echo done
226