70a9e64f050549287543b017c73b08009ac9cbad
[hcoop/scripts.git] / hcoop-backup
1 #!/bin/bash -e
2
3 #
4 # it is dangerous to remove the "-e" above; please don't do that.
5 #
6
7 #
8 # run this script as root, on deleuze
9 #
10
11 exec >& /var/log/backup-to-megacz.com-log
12
13 PATH=$PATH:/bin:/usr/bin:/sbin:/usr/sbin
14 #COMPRESS_EXT=.bz2
15 #COMPRESS_PROG=bzip2
16 COMPRESS_EXT=.gz
17 COMPRESS_PROG=gzip
18 BWLIMIT=250
19 # units for BWLIMIT are KB/s
20
21 IFS=$'\n'
22
23 KEYFILE=/etc/backup-encryption-key
24 BACKUPDIR=/afs/megacz.com/private/hcoop-backup
25 BACKUPTMP=/var/backups/hcoop-backup
26 SUBDIR=`date +%Y.%m.%d`
27
28 #SYNC_CMD="rsync --bwlimit=$BWLIMIT --remove-source-files"
29
30 function copy_over () {
31 # Move file to its offsite destination
32 # $1: file, $2: relative directory (optional)
33 if test -z "$1" || test -n "$3"; then
34 echo "Bad programming"
35 exit 1
36 fi
37 local FILE=$1
38 local DEST=$BACKUPDIR/$SUBDIR
39 if test -n "$2"; then
40 DEST=$DEST/$2
41 fi
42 cat $FILE | catsync -b $BWLIMIT $DEST/$FILE
43 rm -f $FILE
44 }
45
46 cd $BACKUPDIR
47 find . -mindepth 1 -maxdepth 1 -type d -ctime +3 -delete || true
48
49 rm -rf $SUBDIR
50 mkdir -p $SUBDIR
51 mkdir -p $BACKUPTMP
52 cd $BACKUPTMP
53
54 groups
55 echo 'I am in:'
56 pwd
57 echo
58
59 echo building package lists...
60 dpkg-query -W -f='${Package}\n' > packages
61 (cd /; find / /usr/ /usr/local/ /var/ -xdev) | sort | uniq > allfiles
62 dpkg-query -W -f='${Package}\n' | xargs dpkg -L | sort | uniq > debfiles
63 dpkg-query -W -f='${Conffiles}\n' | grep / | cut -b2- | \
64 sed 's_ .*__' | sort | uniq > conffiles
65
66 diff allfiles debfiles | grep '^<' | cut -b 3- | \
67 grep -v ^/var/cache | \
68 grep -v ^/var/tmp | \
69 grep -v ^/var/lib/dpkg | \
70 grep -v ^/var/backups | \
71 grep -v ^/var/lib/changetrack | \
72 grep -v ^/var/local/lib/spamd | \
73 grep -v ^/var/run | \
74 grep -v ^/var/lock | \
75 grep -v ^/var/lib/ucf | \
76 grep -v ^/vicepa | \
77 grep -v ^/home | \
78 grep -v ^/tmp | \
79 grep -v '^/afs$' | \
80 grep -v '^/$' | \
81 grep -v '^/usr/$' | \
82 grep -v ^/usr/src | \
83 grep -v '^/usr/.*\.pyc' | \
84 grep -v '^/usr/.*\.elc' | \
85 grep -v '^/usr/bin/perldoc\.stub$' | \
86 grep -v '^/usr/bin/.*\.notslocate$' | \
87 grep -v '^/usr/lib/courier/.*\.rand$' | \
88 grep -v '^/usr/lib/gconv/gconv-modules\.cache$' | \
89 grep -v '^/usr/lib/graphviz/config$' | \
90 grep -v '^/usr/lib/locale/locale-archive$' | \
91 grep -v '^/usr/share/info/dir$' | \
92 grep -v '^/usr/share/info/dir\.old$' | \
93 grep -v '^/usr/share/emacs21/site-lisp/' | \
94 grep -v '^/usr/share/emacs22/site-lisp/' | \
95 grep -v '^/usr/share/vim/addons/doc/tags$' | \
96 cat > backupfiles
97
98 cat conffiles >> backupfiles
99
100 cat backupfiles | \
101 grep -v ^/home | \
102 grep -v ^/usr/local | \
103 grep -v ^/var/spool | \
104 grep -v ^/var/log | \
105 grep -v ^/usr/lib/python2.4/ | \
106 grep -v ^/var/lib/python-support | \
107 grep -v ^/usr/share/man | \
108 grep -v ^/usr/share/perl5/IkiWiki/Plugin | \
109 grep -v ^/media | \
110 grep -v ^/vmlinuz | \
111 grep -v ^/vmlinuz.old | \
112 grep -v '^/sbin/[a-z\-]*\.modutils$' | \
113 grep -v ^/opt/dell/srvadmin/ | \
114 grep -v ^/boot/ | \
115 grep -v ^/dev/ | \
116 grep -v ^/etc/ | \
117 grep -v ^/root/ | \
118 grep -v ^/var/ | \
119 grep -v ^/lib/modules/ | \
120 grep -v ^/var/domtool/ | \
121 grep -v ^/var/lib/mysql/ | \
122 grep -v ^/var/lib/postgres/ | \
123 grep -v ^/var/lib/postgresql/ | \
124 xargs -I{} -d\\n -- bash -c "test -L '{}' || echo '{}'" > complain
125
126 F=hcoop.backup.tar$COMPRESS_EXT.aescrypt
127 tar clpf - --ignore-failed-read --no-recursion -C / -T backupfiles | \
128 $COMPRESS_PROG | \
129 ccrypt -k $KEYFILE -e > $F
130 copy_over $F
131
132 # Acquire lock before messing with spamd
133 COUNT=0
134 LOCK=/var/local/lib/spamd/.lock
135 while test -f $LOCK; do
136 sleep 2m
137 COUNT=$(expr $COUNT + 1)
138 if test $COUNT -eq 10; then
139 # Enough waiting. Kill the process.
140 P=$(cat $LOCK) || :
141 test -n "$P" && kill $P || :
142 rm -f $LOCK
143 break
144 fi
145 done
146 touch $LOCK
147
148 F=common.spamd.tar$COMPRESS_EXT.aescrypt
149 tar clpf - --ignore-failed-read -C / /var/local/lib/spamd | \
150 $COMPRESS_PROG | \
151 ccrypt -k $KEYFILE -e > $F.new
152 rm -f $LOCK
153 copy_over $F.new ..
154
155 test -s $BACKUPDIR/$F.new && \
156 mv $BACKUPDIR/$F.new $BACKUPDIR/$F
157
158 vos listvol deleuze | \
159 tail -n +2 | \
160 head -n -3 | \
161 cut -b1-34 | \
162 grep -v "\.backup .*$" | \
163 grep -v "\.readonly .*$" | \
164 sed 's_^ .*__' | \
165 sed 's_ .*$__' | \
166 grep '[A-Za-z]' | \
167 cat > volumes
168
169 cat volumes | \
170 grep -v not-backed-up | \
171 xargs -I{} -d\\n -- \
172 bash -c \
173 "F={}.dump$COMPRESS_EXT.aescrypt ;
174 vos dump -id {} -localauth -clone |
175 $COMPRESS_PROG | ccrypt -k $KEYFILE -e > \$F ;
176 cat \$F | catsync -b $BWLIMIT $BACKUPDIR/$SUBDIR/\$F ;
177 rm -f \$F"
178
179 echo backing up databases
180 F=databases.tar$COMPRESS_EXT.aescrypt
181 tar -C /var/backups/databases/ -cf - . | \
182 $COMPRESS_PROG | \
183 ccrypt -k $KEYFILE -e > $F
184 copy_over $F
185
186 grep '[a-z/]' complain && \
187 mail -a 'From: The Backup Program <backups@deleuze.hcoop.net>' \
188 -s "automated message: annoying files found on deleuze (please do something about them)" admins@hcoop.net \
189 < complain \
190 || true
191
192 echo done
193