Add three-scenario disaster recovery
This commit is contained in:
1 parent
e5e5d7fa4d
commit
bc2ca9af7d
18 files changed
+853
-107
No files matched your search
+42
-1
@@ -37,6 +37,10 @@ if (( (8#$config_mode & 077) != 0 )); then
|
||||
fi
|
||||
# shellcheck disable=SC1090
|
||||
source "$CONFIG"
|
||||
if [[ -n ${HF_TOKEN_FILE:-} && ! -r ${HF_TOKEN_FILE:-} && \
|
||||
-r /etc/mike-ai/huggingface-token ]]; then
|
||||
HF_TOKEN_FILE=/etc/mike-ai/huggingface-token
|
||||
fi
|
||||
|
||||
required=(AI_HOSTNAME ADMIN_USER MODEL_DIR FAST_MODEL_FILE
|
||||
FAST_MODEL_URL FAST_MODEL_SHA256 MEDIUM_MODEL_FILE MEDIUM_MODEL_URL
|
||||
@@ -69,7 +73,7 @@ install_base_packages() {
|
||||
apt-get update
|
||||
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
|
||||
ca-certificates curl git gnupg jq openssl wireguard-tools iptables \
|
||||
iproute2 pciutils rsync unattended-upgrades ethtool age
|
||||
iproute2 pciutils rsync unattended-upgrades ethtool age restic zstd
|
||||
}
|
||||
|
||||
setup_stable_network_name() {
|
||||
@@ -303,6 +307,19 @@ install_stack_files() {
|
||||
printf '%s\n' "$source_head" >"$STACK_DIR/.mike-ai-source-commit"
|
||||
fi
|
||||
install -d -m 0700 "$SECRETS_DIR"
|
||||
# Keep the exact host bootstrap inputs with the protected system
|
||||
# configuration. This breaks the former recovery cycle in which a fresh
|
||||
# host needed a lost /root-only install file before it could restore backup.
|
||||
if [[ $(realpath "$CONFIG") != $(realpath -m "$SECRETS_DIR/install.env") ]]; then
|
||||
install -m 0600 "$CONFIG" "$SECRETS_DIR/install.env"
|
||||
else
|
||||
chmod 0600 "$SECRETS_DIR/install.env"
|
||||
fi
|
||||
if [[ -n ${HF_TOKEN_FILE:-} && -r $HF_TOKEN_FILE && \
|
||||
$(realpath "$HF_TOKEN_FILE") != $(realpath -m "$SECRETS_DIR/huggingface-token") ]]; then
|
||||
install -m 0600 "$HF_TOKEN_FILE" "$SECRETS_DIR/huggingface-token"
|
||||
HF_TOKEN_FILE=$SECRETS_DIR/huggingface-token
|
||||
fi
|
||||
[[ -s $SECRETS_DIR/router-api-key ]] || openssl rand -base64 48 >$SECRETS_DIR/router-api-key
|
||||
[[ -s $SECRETS_DIR/controller-token ]] || openssl rand -base64 48 >$SECRETS_DIR/controller-token
|
||||
chmod 0600 "$SECRETS_DIR"/*
|
||||
@@ -366,6 +383,29 @@ EOF
|
||||
chmod 0600 $SECRETS_DIR/stack.env
|
||||
}
|
||||
|
||||
install_disaster_backup() {
|
||||
log "Externes Disaster-Backup installieren"
|
||||
install -m 0755 "$ROOT_DIR/platform/backup/athena-disaster-backup" \
|
||||
/usr/local/sbin/athena-disaster-backup
|
||||
install -m 0644 "$ROOT_DIR/platform/backup/athena-disaster-backup.service" \
|
||||
/etc/systemd/system/athena-disaster-backup.service
|
||||
install -m 0644 "$ROOT_DIR/platform/backup/athena-disaster-backup.timer" \
|
||||
/etc/systemd/system/athena-disaster-backup.timer
|
||||
install -m 0755 "$ROOT_DIR/platform/backup/athena-export-backup" \
|
||||
/usr/local/sbin/athena-export-backup
|
||||
install -m 0644 "$ROOT_DIR/platform/backup/athena-export-backup.service" \
|
||||
/etc/systemd/system/athena-export-backup.service
|
||||
install -m 0644 "$ROOT_DIR/platform/backup/athena-export-backup.timer" \
|
||||
/etc/systemd/system/athena-export-backup.timer
|
||||
if [[ ! -e $SECRETS_DIR/disaster-backup.env ]]; then
|
||||
install -m 0600 "$ROOT_DIR/config/disaster-backup.env.example" \
|
||||
"$SECRETS_DIR/disaster-backup.env.example"
|
||||
fi
|
||||
systemctl daemon-reload
|
||||
systemctl enable --now athena-disaster-backup.timer
|
||||
systemctl enable --now athena-export-backup.timer
|
||||
}
|
||||
|
||||
download_one() {
|
||||
local relative=$1 url=$2 expected=$3 target="$MODEL_DIR/$1"
|
||||
install -d -m 0755 "$(dirname "$target")"
|
||||
@@ -569,6 +609,7 @@ install_stack_files
|
||||
download_models
|
||||
install_routing_guard
|
||||
build_and_start
|
||||
install_disaster_backup
|
||||
|
||||
log "Installation abgeschlossen"
|
||||
if [[ ${WIREGUARD_MODE:-container} == container ]]; then
|
||||
|
||||
Reference in new issue
Block a user