restic/ana-ml2: fix verification snippet to run inside sudo shell
Original used `sudo env \$(cat /etc/restic/restic.env) …` but the `cat` in command substitution runs as the login user, not root. Since the env-file is root:600, the substitution silently yielded an empty RESTIC_REPOSITORY and restic errored with "Please specify repository location". Wrap the whole dance in `sudo bash -c "…"` so the env-file read and the restic call both happen as root.
This commit is contained in:
@@ -61,13 +61,20 @@ EOF
|
|||||||
|
|
||||||
### 2. Verify creds against the existing repo
|
### 2. Verify creds against the existing repo
|
||||||
|
|
||||||
Before deploying the profile, prove the secrets are correct:
|
Before deploying the profile, prove the secrets are correct. The
|
||||||
|
`/etc/restic/restic.env` and `/etc/restic/password` files are root:600,
|
||||||
|
so the env-file read AND the restic invocation both need to run inside
|
||||||
|
the same sudo shell — otherwise `$(cat …)` runs as the login user,
|
||||||
|
fails silently, and restic complains about a missing repository:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
ssh -t ana-ml2 '
|
ssh -t ana-ml2 '
|
||||||
sudo env $(cat /etc/restic/restic.env) \
|
sudo bash -c "
|
||||||
RESTIC_PASSWORD_FILE=/etc/restic/password \
|
set -a
|
||||||
restic snapshots
|
. /etc/restic/restic.env
|
||||||
|
set +a
|
||||||
|
RESTIC_PASSWORD_FILE=/etc/restic/password restic snapshots
|
||||||
|
"
|
||||||
'
|
'
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user