# esh-docker-vm: install the pre-backup hook without the uptime-kuma block. # # Kuma moved to ana-docker on 2026-09-22. The old block's unguarded # `docker ps | grep uptime.kuma` lookup then matched nothing, exited 1, and # set -euo pipefail aborted the hook. resticprofile treats a failed run-before # as fatal, so every nightly backup since 2026-09-22 01:00 was skipped. # # Rerunnable: the preserve step is `creates:`-guarded, and the upload only # changes the file when the content differs. steps: - name: Preserve the pre-fix hook sudo: true shell: | set -eu install -d -m 0700 /var/lib/restic/repair-20260923 cp -p /etc/restic/pre-backup.sh /var/lib/restic/repair-20260923/pre-backup.sh creates: /var/lib/restic/repair-20260923/pre-backup.sh - name: Install the hook without the uptime-kuma block sudo: true upload: src: configs/restic/esh-docker-vm/pre-backup.sh dest: /etc/restic/pre-backup.sh mode: '0700' # Belt and braces: elway's sudo upload defaults to root:root since # 2026-09-23 (before that it kept the SSH user's ownership). This hook is # executed by root, so the verify below checks it either way. - name: Make the hook root-owned sudo: true shell: chown root:root /etc/restic/pre-backup.sh verify: - name: Hook parses under bash sudo: true shell: bash -n /etc/restic/pre-backup.sh - name: No uptime-kuma lookup left in the live hook sudo: true shell: "! grep -q 'UK_CONTAINER' /etc/restic/pre-backup.sh" - name: Hook runs to completion (stage summary line reached) sudo: true shell: /etc/restic/pre-backup.sh 2>&1 | grep -q 'stage ready:' - name: Hook is root:root 0700 sudo: true shell: test "$(stat -c '%U:%G %a' /etc/restic/pre-backup.sh)" = "root:root 700"