|
|
|
@@ -107,23 +107,28 @@ service_alternative_alias() {
|
|
|
|
service_backup() {
|
|
|
|
service_backup() {
|
|
|
|
declare desc="Creates a backup of a service to an existing s3 bucket"
|
|
|
|
declare desc="Creates a backup of a service to an existing s3 bucket"
|
|
|
|
declare SERVICE="$1" BUCKET_NAME="$2" USE_IAM_OPTIONAL_FLAG="$3"
|
|
|
|
declare SERVICE="$1" BUCKET_NAME="$2" USE_IAM_OPTIONAL_FLAG="$3"
|
|
|
|
local BACKUP_CONFIG_ROOT="$PLUGIN_DATA_ROOT/$SERVICE/backup"
|
|
|
|
local SERVICE_BACKUP_ROOT="$PLUGIN_DATA_ROOT/$SERVICE/backup"
|
|
|
|
local BACKUP_ENCRYPTION_CONFIG_ROOT="$PLUGIN_DATA_ROOT/$SERVICE/backup-encryption"
|
|
|
|
local BACKUP_ENCRYPTION_CONFIG_ROOT="$PLUGIN_DATA_ROOT/$SERVICE/backup-encryption"
|
|
|
|
local AWS_ACCESS_KEY_ID_FILE="$BACKUP_CONFIG_ROOT/AWS_ACCESS_KEY_ID"
|
|
|
|
local AWS_ACCESS_KEY_ID_FILE="$SERVICE_BACKUP_ROOT/AWS_ACCESS_KEY_ID"
|
|
|
|
local AWS_SECRET_ACCESS_KEY_FILE="$BACKUP_CONFIG_ROOT/AWS_SECRET_ACCESS_KEY"
|
|
|
|
local AWS_SECRET_ACCESS_KEY_FILE="$SERVICE_BACKUP_ROOT/AWS_SECRET_ACCESS_KEY"
|
|
|
|
|
|
|
|
local SERVICE_ROOT="$PLUGIN_DATA_ROOT/$SERVICE"
|
|
|
|
|
|
|
|
local ID="$(cat "$SERVICE_ROOT/ID")"
|
|
|
|
local BACKUP_PARAMETERS=""
|
|
|
|
local BACKUP_PARAMETERS=""
|
|
|
|
|
|
|
|
|
|
|
|
if [[ "$USE_IAM_OPTIONAL_FLAG" != "--use-iam" ]] && [[ "$USE_IAM_OPTIONAL_FLAG" != "-u" ]]; then
|
|
|
|
if [[ -z "$USE_IAM_OPTIONAL_FLAG" ]]; then
|
|
|
|
[[ ! -f "$AWS_ACCESS_KEY_ID_FILE" ]] && dokku_log_fail "Missing AWS_ACCESS_KEY_ID file"
|
|
|
|
[[ ! -f "$AWS_ACCESS_KEY_ID_FILE" ]] && dokku_log_fail "Missing AWS_ACCESS_KEY_ID file"
|
|
|
|
[[ ! -f "$AWS_SECRET_ACCESS_KEY_FILE" ]] && dokku_log_fail "Missing AWS_SECRET_ACCESS_KEY file"
|
|
|
|
[[ ! -f "$AWS_SECRET_ACCESS_KEY_FILE" ]] && dokku_log_fail "Missing AWS_SECRET_ACCESS_KEY file"
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e AWS_ACCESS_KEY_ID=$(cat "$AWS_ACCESS_KEY_ID_FILE") -e AWS_SECRET_ACCESS_KEY=$(cat "$AWS_SECRET_ACCESS_KEY_FILE")"
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e AWS_ACCESS_KEY_ID=$(cat "$AWS_ACCESS_KEY_ID_FILE") -e AWS_SECRET_ACCESS_KEY=$(cat "$AWS_SECRET_ACCESS_KEY_FILE")"
|
|
|
|
else
|
|
|
|
elif [[ "$USE_IAM_OPTIONAL_FLAG" != "--use-iam" ]] && [[ "$USE_IAM_OPTIONAL_FLAG" != "-u" ]]; then
|
|
|
|
dokku_log_fail "Provide AWS credentials or use the --use-iam flag"
|
|
|
|
dokku_log_fail "Provide AWS credentials or use the --use-iam flag"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
TMPDIR=$(mktemp -d)
|
|
|
|
TMPDIR=$(mktemp -d)
|
|
|
|
trap 'rm -rf "$TMPDIR" > /dev/null' RETURN INT TERM EXIT
|
|
|
|
trap 'rm -rf "$TMPDIR" > /dev/null' RETURN INT TERM EXIT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
docker inspect "$ID" &> /dev/null || dokku_log_fail "Service container does not exist"
|
|
|
|
|
|
|
|
is_container_status "$ID" "Running" || dokku_log_fail "Service container is not running"
|
|
|
|
|
|
|
|
|
|
|
|
(service_export "$SERVICE" > "${TMPDIR}/export")
|
|
|
|
(service_export "$SERVICE" > "${TMPDIR}/export")
|
|
|
|
|
|
|
|
|
|
|
|
# Build parameter list for s3backup tool
|
|
|
|
# Build parameter list for s3backup tool
|
|
|
|
@@ -131,16 +136,16 @@ service_backup() {
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e BACKUP_NAME=${PLUGIN_COMMAND_PREFIX}-${SERVICE}"
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e BACKUP_NAME=${PLUGIN_COMMAND_PREFIX}-${SERVICE}"
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -v ${TMPDIR}:/backup"
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -v ${TMPDIR}:/backup"
|
|
|
|
|
|
|
|
|
|
|
|
if [[ -f "$BACKUP_CONFIG_ROOT/AWS_DEFAULT_REGION" ]]; then
|
|
|
|
if [[ -f "$SERVICE_BACKUP_ROOT/AWS_DEFAULT_REGION" ]]; then
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e AWS_DEFAULT_REGION=$(cat "$BACKUP_CONFIG_ROOT/AWS_DEFAULT_REGION")"
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e AWS_DEFAULT_REGION=$(cat "$SERVICE_BACKUP_ROOT/AWS_DEFAULT_REGION")"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
if [[ -f "$BACKUP_CONFIG_ROOT/AWS_SIGNATURE_VERSION" ]]; then
|
|
|
|
if [[ -f "$SERVICE_BACKUP_ROOT/AWS_SIGNATURE_VERSION" ]]; then
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e AWS_SIGNATURE_VERSION=$(cat "$BACKUP_CONFIG_ROOT/AWS_SIGNATURE_VERSION")"
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e AWS_SIGNATURE_VERSION=$(cat "$SERVICE_BACKUP_ROOT/AWS_SIGNATURE_VERSION")"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
if [[ -f "$BACKUP_CONFIG_ROOT/ENDPOINT_URL" ]]; then
|
|
|
|
if [[ -f "$SERVICE_BACKUP_ROOT/ENDPOINT_URL" ]]; then
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e ENDPOINT_URL=$(cat "$BACKUP_CONFIG_ROOT/ENDPOINT_URL")"
|
|
|
|
BACKUP_PARAMETERS="$BACKUP_PARAMETERS -e ENDPOINT_URL=$(cat "$SERVICE_BACKUP_ROOT/ENDPOINT_URL")"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
if [[ -f "$BACKUP_ENCRYPTION_CONFIG_ROOT/ENCRYPTION_KEY" ]]; then
|
|
|
|
if [[ -f "$BACKUP_ENCRYPTION_CONFIG_ROOT/ENCRYPTION_KEY" ]]; then
|
|
|
|
@@ -154,23 +159,22 @@ service_backup() {
|
|
|
|
service_backup_auth() {
|
|
|
|
service_backup_auth() {
|
|
|
|
declare desc="Sets up authentication"
|
|
|
|
declare desc="Sets up authentication"
|
|
|
|
declare SERVICE="$1" AWS_ACCESS_KEY_ID="$2" AWS_SECRET_ACCESS_KEY="$3" AWS_DEFAULT_REGION="$4" AWS_SIGNATURE_VERSION="$5" ENDPOINT_URL="$6"
|
|
|
|
declare SERVICE="$1" AWS_ACCESS_KEY_ID="$2" AWS_SECRET_ACCESS_KEY="$3" AWS_DEFAULT_REGION="$4" AWS_SIGNATURE_VERSION="$5" ENDPOINT_URL="$6"
|
|
|
|
local SERVICE_ROOT="${PLUGIN_DATA_ROOT}/${SERVICE}"
|
|
|
|
local SERVICE_BACKUP_ROOT="$PLUGIN_DATA_ROOT/$SERVICE/backup"
|
|
|
|
local SERVICE_BACKUP_ROOT="${SERVICE_ROOT}/backup/"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
mkdir -p "$SERVICE_BACKUP_ROOT"
|
|
|
|
mkdir -p "$SERVICE_BACKUP_ROOT"
|
|
|
|
echo "$AWS_ACCESS_KEY_ID" > "${SERVICE_BACKUP_ROOT}/AWS_ACCESS_KEY_ID"
|
|
|
|
echo "$AWS_ACCESS_KEY_ID" > "$SERVICE_BACKUP_ROOT/AWS_ACCESS_KEY_ID"
|
|
|
|
echo "$AWS_SECRET_ACCESS_KEY" > "${SERVICE_BACKUP_ROOT}/AWS_SECRET_ACCESS_KEY"
|
|
|
|
echo "$AWS_SECRET_ACCESS_KEY" > "$SERVICE_BACKUP_ROOT/AWS_SECRET_ACCESS_KEY"
|
|
|
|
|
|
|
|
|
|
|
|
if [[ -n "$AWS_DEFAULT_REGION" ]]; then
|
|
|
|
if [[ -n "$AWS_DEFAULT_REGION" ]]; then
|
|
|
|
echo "$AWS_DEFAULT_REGION" > "${SERVICE_BACKUP_ROOT}/AWS_DEFAULT_REGION"
|
|
|
|
echo "$AWS_DEFAULT_REGION" > "$SERVICE_BACKUP_ROOT/AWS_DEFAULT_REGION"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
if [[ -n "$AWS_SIGNATURE_VERSION" ]]; then
|
|
|
|
if [[ -n "$AWS_SIGNATURE_VERSION" ]]; then
|
|
|
|
echo "$AWS_SIGNATURE_VERSION" > "${SERVICE_BACKUP_ROOT}/AWS_SIGNATURE_VERSION"
|
|
|
|
echo "$AWS_SIGNATURE_VERSION" > "$SERVICE_BACKUP_ROOT/AWS_SIGNATURE_VERSION"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
if [[ -n "$ENDPOINT_URL" ]]; then
|
|
|
|
if [[ -n "$ENDPOINT_URL" ]]; then
|
|
|
|
echo "$ENDPOINT_URL" > "${SERVICE_BACKUP_ROOT}/ENDPOINT_URL"
|
|
|
|
echo "$ENDPOINT_URL" > "$SERVICE_BACKUP_ROOT/ENDPOINT_URL"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
@@ -185,12 +189,16 @@ service_backup_deauth() {
|
|
|
|
|
|
|
|
|
|
|
|
service_backup_schedule() {
|
|
|
|
service_backup_schedule() {
|
|
|
|
declare desc="schedules a backup of the service"
|
|
|
|
declare desc="schedules a backup of the service"
|
|
|
|
declare SERVICE="$1" SCHEDULE="$2" BUCKET_NAME="$3"
|
|
|
|
declare SERVICE="$1" SCHEDULE="$2" BUCKET_NAME="$3" USE_IAM_OPTIONAL_FLAG="$4"
|
|
|
|
local DOKKU_BIN="$(which dokku)"
|
|
|
|
local DOKKU_BIN="$(which dokku)"
|
|
|
|
local CRON_FILE="/etc/cron.d/dokku-${PLUGIN_COMMAND_PREFIX}-${SERVICE}"
|
|
|
|
local CRON_FILE="/etc/cron.d/dokku-${PLUGIN_COMMAND_PREFIX}-${SERVICE}"
|
|
|
|
local TMP_CRON_FILE="${PLUGIN_DATA_ROOT}/.TMP_CRON_FILE"
|
|
|
|
local TMP_CRON_FILE="${PLUGIN_DATA_ROOT}/.TMP_CRON_FILE"
|
|
|
|
|
|
|
|
|
|
|
|
echo "${SCHEDULE} dokku ${DOKKU_BIN} ${PLUGIN_COMMAND_PREFIX}:backup ${SERVICE} ${BUCKET_NAME}" > "$TMP_CRON_FILE"
|
|
|
|
if [[ -n "$USE_IAM_OPTIONAL_FLAG" ]] && [[ "$USE_IAM_OPTIONAL_FLAG" != "--use-iam" ]] && [[ "$USE_IAM_OPTIONAL_FLAG" != "-u" ]]; then
|
|
|
|
|
|
|
|
dokku_log_fail "Invalid flag provided, only '--use-iam' allowed"
|
|
|
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
echo "${SCHEDULE} dokku ${DOKKU_BIN} ${PLUGIN_COMMAND_PREFIX}:backup ${SERVICE} ${BUCKET_NAME} ${USE_IAM_OPTIONAL_FLAG}" > "$TMP_CRON_FILE"
|
|
|
|
sudo /bin/mv "$TMP_CRON_FILE" "$CRON_FILE"
|
|
|
|
sudo /bin/mv "$TMP_CRON_FILE" "$CRON_FILE"
|
|
|
|
sudo /bin/chown root:root "$CRON_FILE"
|
|
|
|
sudo /bin/chown root:root "$CRON_FILE"
|
|
|
|
sudo /bin/chmod 644 "$CRON_FILE"
|
|
|
|
sudo /bin/chmod 644 "$CRON_FILE"
|
|
|
|
@@ -241,8 +249,8 @@ service_enter() {
|
|
|
|
local SERVICE_ROOT="$PLUGIN_DATA_ROOT/$SERVICE"
|
|
|
|
local SERVICE_ROOT="$PLUGIN_DATA_ROOT/$SERVICE"
|
|
|
|
local ID="$(cat "$SERVICE_ROOT/ID")"
|
|
|
|
local ID="$(cat "$SERVICE_ROOT/ID")"
|
|
|
|
|
|
|
|
|
|
|
|
docker inspect "$ID" &> /dev/null || dokku_log_fail "Container does not exist"
|
|
|
|
docker inspect "$ID" &> /dev/null || dokku_log_fail "Service container does not exist"
|
|
|
|
is_container_status "$ID" "Running" || dokku_log_fail "Container is not running"
|
|
|
|
is_container_status "$ID" "Running" || dokku_log_fail "Service container is not running"
|
|
|
|
|
|
|
|
|
|
|
|
local EXEC_CMD=""
|
|
|
|
local EXEC_CMD=""
|
|
|
|
has_tty && local DOKKU_RUN_OPTS+=" -i -t"
|
|
|
|
has_tty && local DOKKU_RUN_OPTS+=" -i -t"
|
|
|
|
@@ -387,6 +395,7 @@ service_logs() {
|
|
|
|
DOKKU_LOGS_ARGS="--follow"
|
|
|
|
DOKKU_LOGS_ARGS="--follow"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
docker inspect "$ID" &> /dev/null || dokku_log_fail "Service container does not exist"
|
|
|
|
is_container_status "$ID" "Running" || dokku_log_warn "Service logs may not be output as service is not running"
|
|
|
|
is_container_status "$ID" "Running" || dokku_log_warn "Service logs may not be output as service is not running"
|
|
|
|
|
|
|
|
|
|
|
|
# shellcheck disable=SC2086
|
|
|
|
# shellcheck disable=SC2086
|
|
|
|
|