#!/bin/bash # vm-esh-nas: move restic from env-file to repository-file (2026-09-27). # The same change playbooks/restic-repository-file.yaml made on the seven hosts # where infra-ops has sudo. vm-esh-nas has no infra-ops account, so run it as: # ssh -t vm-esh-nas 'sudo bash ~/restic-repofile-migrate.sh' # It edits the env-file line IN PLACE (the live profile cannot be diffed without # root, so any drift is preserved), and restores the old profile if a check fails. set -eu cd /etc/restic grep -q '^ *env-file: /etc/restic/restic.env' profiles.yaml \ || { echo "no env-file line: already migrated, or the profile differs; nothing done"; exit 1; } val=$(sh -c 'set -a; . /etc/restic/restic.env; printf %s "$RESTIC_REPOSITORY"') case "$val" in rest:http*) ;; *) echo "RESTIC_REPOSITORY is not a rest: URL; nothing done"; exit 1;; esac umask 077 printf '%s\n' "$val" > repository.new chown root:root repository.new; chmod 0400 repository.new; mv repository.new repository unset val cp -p profiles.yaml profiles.yaml.bak-20260927-envfile trap 'cp -p profiles.yaml.bak-20260927-envfile profiles.yaml; resticprofile --no-ansi --config /etc/restic/profiles.yaml --name default schedule >/dev/null 2>&1 || true; echo "FAILED: old profile restored"' ERR sed -i 's|^\( *\)env-file: /etc/restic/restic.env.*$|\1repository-file: /etc/restic/repository # not env-file: schedule copies env-file values into world-readable units|' profiles.yaml resticprofile --no-ansi --config /etc/restic/profiles.yaml --name default cat config >/dev/null resticprofile --no-ansi --config /etc/restic/profiles.yaml --name default schedule >/dev/null for u in backup check; do f=/etc/systemd/system/resticprofile-$u@profile-default.service test -f "$f" ! grep -q 'rest:http' "$f" done systemctl is-active --quiet resticprofile-backup@profile-default.timer trap - ERR echo "vm-esh-nas migrated: units carry no repository URL, backup timer active"