# esh-docker-vm: install the pre-backup hook without the paperless pg_dump # block (operator decision 2026-09-23). # # paperless-ngx's Postgres is backed up at the source by esh-vm-db's # fail-closed pg_dumpall. This host's second copy had been failing auth on a # stale password for months behind a WARN. That block was the only consumer of # /etc/restic/dbcreds.env, so the creds file is MOVED (not deleted) into the # repair dir, out of the live config path. # # Rerunnable: the preserve/move steps are `creates:`-guarded; the chown step # re-applies root ownership after every upload. steps: - name: Preserve the pre-change hook sudo: true shell: | set -eu install -d -m 0700 /var/lib/restic/repair-20260923 cp -p /etc/restic/pre-backup.sh /var/lib/restic/repair-20260923/pre-backup.sh.pre-paperless creates: /var/lib/restic/repair-20260923/pre-backup.sh.pre-paperless - name: Move the now-unused dbcreds.env out of /etc/restic sudo: true shell: mv /etc/restic/dbcreds.env /var/lib/restic/repair-20260923/dbcreds.env creates: /var/lib/restic/repair-20260923/dbcreds.env - name: Install the hook without the paperless block sudo: true upload: src: configs/restic/esh-docker-vm/pre-backup.sh dest: /etc/restic/pre-backup.sh mode: '0700' # Belt and braces: elway's sudo upload defaults to root:root since # 2026-09-23 (before that it kept the SSH user's ownership). This hook is # executed by root, so the verify below checks it either way. - name: Make the hook root-owned sudo: true shell: chown root:root /etc/restic/pre-backup.sh /var/lib/restic/repair-20260923/pre-backup.sh.pre-paperless verify: - name: Hook parses under bash sudo: true shell: bash -n /etc/restic/pre-backup.sh - name: No paperless dump or creds loader left in the live hook sudo: true shell: "! grep -q -E 'PAPERLESS_PG|dbcreds.env\"?$|pg_dump \\\\' /etc/restic/pre-backup.sh" - name: dbcreds.env is gone from /etc/restic sudo: true shell: test ! -e /etc/restic/dbcreds.env - name: Hook runs to completion with no WARN lines sudo: true shell: | out=$(/etc/restic/pre-backup.sh 2>&1) printf '%s\n' "$out" | grep -q 'stage ready:' && ! printf '%s\n' "$out" | grep -q 'WARN' - name: Hook is root:root 0700 sudo: true shell: test "$(stat -c '%U:%G %a' /etc/restic/pre-backup.sh)" = "root:root 700"