#!/usr/bin/env bash # Restore Athena's non-reproducible Docker state from the latest /data backup. set -Eeuo pipefail umask 077 ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" ARCHIVE=${1:-/data/docker-backups/athena-latest.tar.gz} die() { printf 'FEHLER: %s\n' "$*" >&2; exit 1; } [[ $EUID -eq 0 ]] || die "Bitte als root ausführen." [[ -s $ARCHIVE ]] || die "Backup fehlt: $ARCHIVE" command -v docker >/dev/null || die "Docker fehlt. Zuerst ./install.sh ausführen." work=$(mktemp -d /tmp/athena-restore.XXXXXX) trap 'rm -rf "$work"' EXIT # Refuse absolute paths and parent traversal before extracting as root. if tar -tzf "$ARCHIVE" | grep -Eq '(^/|(^|/)\.\.(/|$))'; then die "Unsichere Pfade im Backup." fi tar -xzf "$ARCHIVE" -C "$work" [[ -d $work/etc-mike-ai ]] || die "Backup enthält etc-mike-ai nicht." [[ -d $work/volumes ]] || die "Backup enthält keine Docker-Volumes." # Stop only users of the restored volumes. WireGuard, SSH and networking stay up. for container in mike-ai-open-webui mike-ai-router mike-ai-profile-controller \ mike-ai-piper mike-ai-tools-tinysearch; do if [[ $(docker inspect -f '{{.State.Running}}' "$container" 2>/dev/null || true) == true ]]; then docker stop "$container" >/dev/null fi done install -d -m 0700 /etc/mike-ai rsync -a --delete "$work/etc-mike-ai/" /etc/mike-ai/ restore_volume() { local volume=$1 source=$2 mountpoint [[ -d $source ]] || return 0 docker volume create "$volume" >/dev/null mountpoint=$(docker volume inspect -f '{{.Mountpoint}}' "$volume") [[ -n $mountpoint && -d $mountpoint ]] || die "Volume nicht zugreifbar: $volume" rsync -a --delete "$source/" "$mountpoint/" } restore_volume mike-ai_open-webui-data "$work/volumes/open-webui-data" restore_volume mike-ai_piper-data "$work/volumes/piper-data" restore_volume mike-ai_router-state "$work/volumes/router-state" restore_volume mike-ai_router-images "$work/volumes/router-images" restore_volume mike-ai-tools_tinysearch-models "$work/volumes/tinysearch-models" cd "$ROOT_DIR" docker compose --env-file /etc/mike-ai/stack.env \ --profile homeassistant --profile arr --profile navidrome --profile deemix --profile github \ up -d python3 platform/mcp/sync-clients.py \ --registry config/mcp-registry.json \ --hermes /data/hermes/config.yaml \ --openwebui-db "$(docker volume inspect -f '{{.Mountpoint}}' mike-ai_open-webui-data)/webui.db" printf 'ATHENA_RESTORE_OK %s\n' "$ARCHIVE"