Add three-scenario disaster recovery

This commit is contained in:
Mikei386 committed 2026-09-10 14:04:56 +02:00
1 parent e5e5d7fa4d
commit bc2ca9af7d
18 files changed
+853 -107

No files matched your search

+42 -1
View File
@@ -37,6 +37,10 @@ if (( (8#$config_mode & 077) != 0 )); then
fi
# shellcheck disable=SC1090
source "$CONFIG"
if [[ -n ${HF_TOKEN_FILE:-} && ! -r ${HF_TOKEN_FILE:-} && \
-r /etc/mike-ai/huggingface-token ]]; then
HF_TOKEN_FILE=/etc/mike-ai/huggingface-token
fi
required=(AI_HOSTNAME ADMIN_USER MODEL_DIR FAST_MODEL_FILE
FAST_MODEL_URL FAST_MODEL_SHA256 MEDIUM_MODEL_FILE MEDIUM_MODEL_URL
@@ -69,7 +73,7 @@ install_base_packages() {
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
ca-certificates curl git gnupg jq openssl wireguard-tools iptables \
iproute2 pciutils rsync unattended-upgrades ethtool age
iproute2 pciutils rsync unattended-upgrades ethtool age restic zstd
}
setup_stable_network_name() {
@@ -303,6 +307,19 @@ install_stack_files() {
printf '%s\n' "$source_head" >"$STACK_DIR/.mike-ai-source-commit"
fi
install -d -m 0700 "$SECRETS_DIR"
# Keep the exact host bootstrap inputs with the protected system
# configuration. This breaks the former recovery cycle in which a fresh
# host needed a lost /root-only install file before it could restore backup.
if [[ $(realpath "$CONFIG") != $(realpath -m "$SECRETS_DIR/install.env") ]]; then
install -m 0600 "$CONFIG" "$SECRETS_DIR/install.env"
else
chmod 0600 "$SECRETS_DIR/install.env"
fi
if [[ -n ${HF_TOKEN_FILE:-} && -r $HF_TOKEN_FILE && \
$(realpath "$HF_TOKEN_FILE") != $(realpath -m "$SECRETS_DIR/huggingface-token") ]]; then
install -m 0600 "$HF_TOKEN_FILE" "$SECRETS_DIR/huggingface-token"
HF_TOKEN_FILE=$SECRETS_DIR/huggingface-token
fi
[[ -s $SECRETS_DIR/router-api-key ]] || openssl rand -base64 48 >$SECRETS_DIR/router-api-key
[[ -s $SECRETS_DIR/controller-token ]] || openssl rand -base64 48 >$SECRETS_DIR/controller-token
chmod 0600 "$SECRETS_DIR"/*
@@ -366,6 +383,29 @@ EOF
chmod 0600 $SECRETS_DIR/stack.env
}
install_disaster_backup() {
log "Externes Disaster-Backup installieren"
install -m 0755 "$ROOT_DIR/platform/backup/athena-disaster-backup" \
/usr/local/sbin/athena-disaster-backup
install -m 0644 "$ROOT_DIR/platform/backup/athena-disaster-backup.service" \
/etc/systemd/system/athena-disaster-backup.service
install -m 0644 "$ROOT_DIR/platform/backup/athena-disaster-backup.timer" \
/etc/systemd/system/athena-disaster-backup.timer
install -m 0755 "$ROOT_DIR/platform/backup/athena-export-backup" \
/usr/local/sbin/athena-export-backup
install -m 0644 "$ROOT_DIR/platform/backup/athena-export-backup.service" \
/etc/systemd/system/athena-export-backup.service
install -m 0644 "$ROOT_DIR/platform/backup/athena-export-backup.timer" \
/etc/systemd/system/athena-export-backup.timer
if [[ ! -e $SECRETS_DIR/disaster-backup.env ]]; then
install -m 0600 "$ROOT_DIR/config/disaster-backup.env.example" \
"$SECRETS_DIR/disaster-backup.env.example"
fi
systemctl daemon-reload
systemctl enable --now athena-disaster-backup.timer
systemctl enable --now athena-export-backup.timer
}
download_one() {
local relative=$1 url=$2 expected=$3 target="$MODEL_DIR/$1"
install -d -m 0755 "$(dirname "$target")"
@@ -569,6 +609,7 @@ install_stack_files
download_models
install_routing_guard
build_and_start
install_disaster_backup
log "Installation abgeschlossen"
if [[ ${WIREGUARD_MODE:-container} == container ]]; then