|
|
|
@ -5,7 +5,7 @@
|
|
|
|
|
### this assumes three things:
|
|
|
|
|
### 1. standard mailcow-dockerized setup as per the docs
|
|
|
|
|
### 2. backups made using the backup script from this git repo
|
|
|
|
|
### 3. backups successfully written to your borg repo
|
|
|
|
|
### 3. backups already downloaded from your borg repo
|
|
|
|
|
#######
|
|
|
|
|
|
|
|
|
|
### text-formatting presets
|
|
|
|
@ -36,18 +36,6 @@ trap trapExit 1 2 3 6
|
|
|
|
|
|
|
|
|
|
### functions
|
|
|
|
|
|
|
|
|
|
badDetails() {
|
|
|
|
|
if [ "$1" = 'empty' ]; then
|
|
|
|
|
writeLog 'done' 'error'
|
|
|
|
|
writeLog 'error' '10' "details:${2} cannot be blank/empty."
|
|
|
|
|
exitError 130
|
|
|
|
|
elif [ "$1" = 'dne' ]; then
|
|
|
|
|
writeLog 'done' 'error'
|
|
|
|
|
writeLog 'error' '11' "details:${2} file or directory does not exist."
|
|
|
|
|
exitError 131
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
consoleError() {
|
|
|
|
|
printf "\n%s%s\n" "$err" "$2"
|
|
|
|
|
printf "Exiting.\n\n%s" "$norm"
|
|
|
|
@ -127,14 +115,22 @@ writeLog() {
|
|
|
|
|
# script related
|
|
|
|
|
scriptPath="$(CDPATH='' cd -- "$(dirname -- "$0")" && pwd -P)"
|
|
|
|
|
scriptName="$(basename "$0")"
|
|
|
|
|
configDetails="$scriptPath/${scriptName%.*}.details"
|
|
|
|
|
errorCount=0
|
|
|
|
|
warnCount=0
|
|
|
|
|
backupLocation=""
|
|
|
|
|
sqlBackup=""
|
|
|
|
|
restoreMail=1
|
|
|
|
|
restoreSQL=1
|
|
|
|
|
restorePostfix=1
|
|
|
|
|
restoreRedis=1
|
|
|
|
|
restoreRspamd=1
|
|
|
|
|
verbose=0
|
|
|
|
|
# logfile default: same location and name as script but with '.log' extension
|
|
|
|
|
logfile="$scriptPath/${scriptName%.*}.log"
|
|
|
|
|
# mailcow/docker related
|
|
|
|
|
mcConfig='/opt/mailcow-dockerized/mailcow.conf'
|
|
|
|
|
mcDockerCompose='/opt/mailcow-dockerized/docker-compose.yml'
|
|
|
|
|
sqlRunning=0
|
|
|
|
|
dockerStartTimeout=180
|
|
|
|
|
dockerStopTimeout=120
|
|
|
|
|
|
|
|
|
@ -146,10 +142,90 @@ fi
|
|
|
|
|
### process startup parameters
|
|
|
|
|
while [ $# -gt 0 ]; do
|
|
|
|
|
case "$1" in
|
|
|
|
|
-h | -\? | --help)
|
|
|
|
|
-h|-\?|--help)
|
|
|
|
|
# display help
|
|
|
|
|
scriptHelp
|
|
|
|
|
;;
|
|
|
|
|
-l|--log)
|
|
|
|
|
# set logfile location
|
|
|
|
|
if [ -z "$2" ]; then
|
|
|
|
|
consoleError '1' "Log file path cannot be null. Leave unspecified to save log in the same directory as this script."
|
|
|
|
|
fi
|
|
|
|
|
logfile="$2"
|
|
|
|
|
shift
|
|
|
|
|
;;
|
|
|
|
|
-v|--verbose)
|
|
|
|
|
verbose=1
|
|
|
|
|
;;
|
|
|
|
|
-d|--docker-compose)
|
|
|
|
|
# FULL path to docker-compose file
|
|
|
|
|
if [ -n "$2" ]; then
|
|
|
|
|
if [ -f "$2" ]; then
|
|
|
|
|
mcDockerCompose="$2"
|
|
|
|
|
shift
|
|
|
|
|
else
|
|
|
|
|
consoleError '1' "$1: cannot find docker-compose file as specified."
|
|
|
|
|
fi
|
|
|
|
|
else
|
|
|
|
|
consoleError '1' "$1: cannot be blank/empty."
|
|
|
|
|
fi
|
|
|
|
|
;;
|
|
|
|
|
-m|--mailcow-config)
|
|
|
|
|
# FULL path to mailcow configuration file file
|
|
|
|
|
if [ -n "$2" ]; then
|
|
|
|
|
if [ -f "$2" ]; then
|
|
|
|
|
mcConfig="$2"
|
|
|
|
|
shift
|
|
|
|
|
else
|
|
|
|
|
consoleError '1' "$1: cannot find mailcow configuration file as specified."
|
|
|
|
|
fi
|
|
|
|
|
else
|
|
|
|
|
consoleError '1' "$1: cannot be blank/empty."
|
|
|
|
|
fi
|
|
|
|
|
;;
|
|
|
|
|
-t1|--timeout-start)
|
|
|
|
|
if [ -z "$2" ]; then
|
|
|
|
|
consoleError '1' "$1: cannot be blank/empty."
|
|
|
|
|
else
|
|
|
|
|
dockerStartTimeout="$2"
|
|
|
|
|
shift
|
|
|
|
|
fi
|
|
|
|
|
;;
|
|
|
|
|
-t2|--timeout-stop)
|
|
|
|
|
if [ -z "$2" ]; then
|
|
|
|
|
consoleError '1' "$1: cannot be blank/empty."
|
|
|
|
|
else
|
|
|
|
|
dockerStopTimeout="$2"
|
|
|
|
|
shift
|
|
|
|
|
fi
|
|
|
|
|
;;
|
|
|
|
|
-b|--backup-location)
|
|
|
|
|
if [ -n "$2" ]; then
|
|
|
|
|
if [ -d "$2" ] && [ -n "$( ls -A "$2" )" ]; then
|
|
|
|
|
backupLocation="$2"
|
|
|
|
|
shift
|
|
|
|
|
else
|
|
|
|
|
consoleError '1' "$1: cannot find specified backup location directory or it is empty."
|
|
|
|
|
fi
|
|
|
|
|
else
|
|
|
|
|
consoleError '1' "$1: cannot be blank/empty."
|
|
|
|
|
fi
|
|
|
|
|
;;
|
|
|
|
|
--skip-mail)
|
|
|
|
|
restoreMail=0
|
|
|
|
|
;;
|
|
|
|
|
--skip-sql)
|
|
|
|
|
restoreSQL=0
|
|
|
|
|
;;
|
|
|
|
|
--skip-postfix)
|
|
|
|
|
restorePostfix=0
|
|
|
|
|
;;
|
|
|
|
|
--skip-redis)
|
|
|
|
|
restoreRedis=0
|
|
|
|
|
;;
|
|
|
|
|
--skip-rspamd)
|
|
|
|
|
restoreRspamd=0
|
|
|
|
|
;;
|
|
|
|
|
*)
|
|
|
|
|
printf "\n%Unknown option: %s\n" "$err" "$1"
|
|
|
|
|
printf "Use '--help' for valid options.%s\n\n" "$norm"
|
|
|
|
@ -160,18 +236,13 @@ while [ $# -gt 0 ]; do
|
|
|
|
|
done
|
|
|
|
|
|
|
|
|
|
### pre-flight checks
|
|
|
|
|
# set path so checks are valid for this script environment
|
|
|
|
|
export PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
|
|
|
|
|
|
|
|
|
|
# docker installed?
|
|
|
|
|
if ! command -v docker >/dev/null; then
|
|
|
|
|
consoleError '3' 'docker does not seem to be installed!'
|
|
|
|
|
fi
|
|
|
|
|
# borg installed?
|
|
|
|
|
if ! command -v borg >/dev/null; then
|
|
|
|
|
consoleError '3' 'borgbackup does not seem to be installed!'
|
|
|
|
|
fi
|
|
|
|
|
# details file?
|
|
|
|
|
if [ ! -f "$configDetails" ]; then
|
|
|
|
|
consoleError '1' "configuration file ($configDetails) cannot be found."
|
|
|
|
|
fi
|
|
|
|
|
# mailcow.conf?
|
|
|
|
|
if [ ! -f "$mcConfig" ]; then
|
|
|
|
|
consoleError '1' "mailcow configuration file ($mcConfig) cannot be found."
|
|
|
|
@ -180,11 +251,12 @@ fi
|
|
|
|
|
if [ ! -f "$mcDockerCompose" ]; then
|
|
|
|
|
consoleError '1' "docker-compose configuration ($mcDockerCompose) cannot be found."
|
|
|
|
|
fi
|
|
|
|
|
# change to mailcow directory so commands execute properly
|
|
|
|
|
\cd ${mcConfig%/*} || consoleError '4' 'Cannot change to mailcow directory as determined from mailcow.conf location.'
|
|
|
|
|
|
|
|
|
|
### read mailcow.conf and import vars
|
|
|
|
|
# shellcheck source=./mailcow.conf.shellcheck
|
|
|
|
|
. "$mcConfig"
|
|
|
|
|
export PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
|
|
|
|
|
export COMPOSE_HTTP_TIMEOUT="$dockerStartTimeout"
|
|
|
|
|
|
|
|
|
|
### start logging
|
|
|
|
@ -218,119 +290,62 @@ writeLog 'info' "Log located at $logfile"
|
|
|
|
|
|
|
|
|
|
### get location of docker volumes
|
|
|
|
|
dockerVolumeMail=$(docker volume inspect -f '{{ .Mountpoint }}' ${COMPOSE_PROJECT_NAME}_vmail-vol-1)
|
|
|
|
|
printf "%s[%s] -- [INFO] Using MAIL volume: %s --%s\n" \
|
|
|
|
|
"$cyan" "$(stamp)" "$dockerVolumeMail" "$norm" >>"$logfile"
|
|
|
|
|
dockerVolumeRspamd=$(docker volume inspect -f '{{ .Mountpoint }}' ${COMPOSE_PROJECT_NAME}_rspamd-vol-1)
|
|
|
|
|
printf "%s[%s] -- [INFO] Using RSPAMD volume: %s --%s\n" \
|
|
|
|
|
"$cyan" "$(stamp)" "$dockerVolumeRspamd" "$norm" >>"$logfile"
|
|
|
|
|
dockerVolumePostfix=$(docker volume inspect -f '{{ .Mountpoint }}' ${COMPOSE_PROJECT_NAME}_postfix-vol-1)
|
|
|
|
|
printf "%s[%s] -- [INFO] Using POSTFIX volume: %s --%s\n" \
|
|
|
|
|
"$cyan" "$(stamp)" "$dockerVolumePostfix" "$norm" >>"$logfile"
|
|
|
|
|
dockerVolumeRedis=$(docker volume inspect -f '{{ .Mountpoint }}' ${COMPOSE_PROJECT_NAME}_redis-vol-1)
|
|
|
|
|
printf "%s[%s] -- [INFO] Using REDIS volume: %s --%s\n" \
|
|
|
|
|
"$cyan" "$(stamp)" "$dockerVolumeRedis" "$norm" >>"$logfile"
|
|
|
|
|
writeLog 'info' "Using MAIL volume: ${dockerVolumeMail}"
|
|
|
|
|
dockerVolumeCrypt=$(docker volume inspect -f '{{ .Mountpoint }}' ${COMPOSE_PROJECT_NAME}_crypt-vol-1)
|
|
|
|
|
printf "%s[%s] -- [INFO] Using MAILCRYPT volume: %s --%s\n" \
|
|
|
|
|
"$cyan" "$(stamp)" "$dockerVolumeCrypt" "$norm" >>"$logfile"
|
|
|
|
|
writeLog 'info' "Using MAILCRYPT volume: ${dockerVolumeCrypt}"
|
|
|
|
|
dockerVolumePostfix=$(docker volume inspect -f '{{ .Mountpoint }}' ${COMPOSE_PROJECT_NAME}_postfix-vol-1)
|
|
|
|
|
writeLog 'info' "Using POSTFIX volume: ${dockerVolumePostfix}"
|
|
|
|
|
dockerVolumeRedis=$(docker volume inspect -f '{{ .Mountpoint }}' ${COMPOSE_PROJECT_NAME}_redis-vol-1)
|
|
|
|
|
writeLog 'info' "Using REDIS volume: ${dockerVolumeRedis}"
|
|
|
|
|
dockerVolumeRspamd=$(docker volume inspect -f '{{ .Mountpoint }}' ${COMPOSE_PROJECT_NAME}_rspamd-vol-1)
|
|
|
|
|
writeLog 'info' "Using RSPAMD volume: ${dockerVolumeRspamd}"
|
|
|
|
|
# exit if mail or crypt containers cannot be found (mailcow not initialized beforehand)
|
|
|
|
|
if [ -z "$dockerVolumeMail" ] || [ -z "$dockerVolumeCrypt" ]; then
|
|
|
|
|
writeLog 'error' '5' "Cannot find mail volume. Mailcow probably not initialized before running restore."
|
|
|
|
|
exitError 5
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
### source configuration details file
|
|
|
|
|
case "${configDetails}" in
|
|
|
|
|
/*)
|
|
|
|
|
# absolute path, no need to rewrite variable
|
|
|
|
|
# shellcheck source=./backup.details
|
|
|
|
|
. "${configDetails}"
|
|
|
|
|
;;
|
|
|
|
|
*)
|
|
|
|
|
# relative path, prepend './' to create absolute path
|
|
|
|
|
# shellcheck source=./backup.details
|
|
|
|
|
. "./${configDetails}"
|
|
|
|
|
;;
|
|
|
|
|
esac
|
|
|
|
|
writeLog 'info' "Configuration file: ${yellow}${configDetails}${info} imported"
|
|
|
|
|
### restore SQL
|
|
|
|
|
if [ "$restoreSQL" -eq 1 ]; then
|
|
|
|
|
writeLog 'task' "Restoring mailcow database"
|
|
|
|
|
|
|
|
|
|
### verify borg variables
|
|
|
|
|
# verify borg base directory
|
|
|
|
|
writeLog 'task' 'Verify details:borgBaseDir'
|
|
|
|
|
if [ -z "${borgBaseDir}" ]; then
|
|
|
|
|
badDetails empty 'borgBaseDir'
|
|
|
|
|
elif [ ! -d "${borgBaseDir}" ]; then
|
|
|
|
|
badDetails dne 'borgBaseDir'
|
|
|
|
|
fi
|
|
|
|
|
export BORG_BASE_DIR="${borgBaseDir%/}"
|
|
|
|
|
writeLog 'done'
|
|
|
|
|
# check path to SSH keyfile
|
|
|
|
|
writeLog 'task' 'Verify details:borgSSHKey'
|
|
|
|
|
if [ -z "${borgSSHKey}" ]; then
|
|
|
|
|
badDetails empty 'borgSSHKey'
|
|
|
|
|
elif [ ! -f "${borgSSHKey}" ]; then
|
|
|
|
|
badDetails dne 'borgSSHKey'
|
|
|
|
|
fi
|
|
|
|
|
export BORG_RSH="ssh -i ${borgSSHKey}"
|
|
|
|
|
writeLog 'done'
|
|
|
|
|
# check borg repo connect string
|
|
|
|
|
writeLog 'task' 'Verify details:borgConnectRepo'
|
|
|
|
|
if [ -z "${borgConnectRepo}" ]; then
|
|
|
|
|
badDetails empty 'borgConnectRepo'
|
|
|
|
|
fi
|
|
|
|
|
export BORG_REPO="${borgConnectRepo}"
|
|
|
|
|
writeLog 'done'
|
|
|
|
|
# check borg repo password
|
|
|
|
|
writeLog 'task' 'Verify details:borgRepoPassphrase'
|
|
|
|
|
if [ -z "${borgRepoPassphrase}" ]; then
|
|
|
|
|
# an empty repo passphrase is considered a mistake so throw an error
|
|
|
|
|
# if the user meant to enter an empty passphrase they should use 'NONE'
|
|
|
|
|
badDetails empty 'borgRepoPassphrase'
|
|
|
|
|
elif [ "${borgRepoPassphrase}" = 'NONE' ]; then
|
|
|
|
|
# password intentionally blank, use but issue warning
|
|
|
|
|
export BORG_PASSPHRASE=''
|
|
|
|
|
writeLog 'done' 'warn'
|
|
|
|
|
writeLog 'warn' 'Using a borg repo with a blank password is an insecure configuration!'
|
|
|
|
|
warnCount=$((warnCount + 1))
|
|
|
|
|
else
|
|
|
|
|
export BORG_PASSPHRASE="${borgRepoPassphrase}"
|
|
|
|
|
writeLog 'done'
|
|
|
|
|
fi
|
|
|
|
|
# check borg repo keyfile location
|
|
|
|
|
writeLog 'task' 'Verify details:borgKeyfileLocation'
|
|
|
|
|
if [ -z "${borgKeyfileLocation}" ]; then
|
|
|
|
|
# will use default location
|
|
|
|
|
writeLog 'done'
|
|
|
|
|
else
|
|
|
|
|
# verify keyfile location exists
|
|
|
|
|
if [ ! -f "${borgKeyfileLocation}" ]; then
|
|
|
|
|
badDetails dne 'bogKeyfileLocation'
|
|
|
|
|
# sql restore pre-requisites
|
|
|
|
|
sqlBackup=$(find "${backupLocation}/tmp" -iname "*.sql")
|
|
|
|
|
if [ -n "$sqlBackup" ]; then
|
|
|
|
|
# start mysql container if not already running
|
|
|
|
|
if ! docker container inspect -f '{{ .State.Running }}' ${COMPOSE_PROJECT_NAME}_mysql-mailcow_1 > /dev/null 2>&1; then
|
|
|
|
|
docker-compose up -d mysql-mailcow
|
|
|
|
|
if docker container inspect -f '{{ .State.Running }}' ${COMPOSE_PROJECT_NAME}_mysql-mailcow_1 > /dev/null 2>&1; then
|
|
|
|
|
sqlRunning=1
|
|
|
|
|
else
|
|
|
|
|
writeLog 'done' 'error'
|
|
|
|
|
writeLog 'error' '12' "Cannot start mysql-mailcow container -- cannot restore mailcow database!"
|
|
|
|
|
errorCount=$((errorCount+1))
|
|
|
|
|
fi
|
|
|
|
|
else
|
|
|
|
|
sqlRunning=1
|
|
|
|
|
fi
|
|
|
|
|
else
|
|
|
|
|
writeLog 'done' 'error'
|
|
|
|
|
writeLog 'error' '11' "Cannot locate SQL backup -- cannot restore mailcow database!"
|
|
|
|
|
errorCount=$((errorCount+1))
|
|
|
|
|
fi
|
|
|
|
|
export BORG_KEY_FILE="${borgKeyfileLocation}"
|
|
|
|
|
writeLog 'done'
|
|
|
|
|
fi
|
|
|
|
|
# export borg remote path, if specified
|
|
|
|
|
if [ -n "${borgRemote}" ]; then export BORG_REMOTE_PATH="${borgRemote}"; fi
|
|
|
|
|
|
|
|
|
|
### create borg temp dir
|
|
|
|
|
## python requires a writable temporary directory when unpacking borg and
|
|
|
|
|
## executing commands. This defaults to /tmp but many systems mount /tmp with
|
|
|
|
|
## the 'noexec' option for security. Thus, we will use/create a 'tmp' folder
|
|
|
|
|
## within the BORG_BASE_DIR and instruct python to use that instead of /tmp
|
|
|
|
|
|
|
|
|
|
# check if BORG_BASE_DIR/tmp exists, if not, create it
|
|
|
|
|
if [ ! -d "${borgBaseDir}/tmp" ]; then
|
|
|
|
|
if ! mkdir "${borgBaseDir}/tmp" 2>/dev/null; then
|
|
|
|
|
writeLog 'error' '31' "Unable to create borg temp directory (${borgBaseDir}/tmp)"
|
|
|
|
|
exitError 31
|
|
|
|
|
# restore sql
|
|
|
|
|
if [ "$sqlRunning" -eq 1 ]; then
|
|
|
|
|
if docker exec -i "$(docker-compose ps -q mysql-mailcow)" mysql -u${DBUSER} -p${DBPASS} ${DBNAME} < "${sqlBackup}" > /dev/null 2>&1; then
|
|
|
|
|
writeLog 'done'
|
|
|
|
|
else
|
|
|
|
|
writeLog 'done' 'error'
|
|
|
|
|
writeLog 'error' '13' "Something went wrong while trying to restore SQL database. Perhaps try again?"
|
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
export TMPDIR="${borgBaseDir}/tmp"
|
|
|
|
|
|
|
|
|
|
### change to mailcow directory so docker commands run properly
|
|
|
|
|
cd "$(dirname ${mcConfig})" || writeLog 'error' '100' "Could not change to mailcow directory." && exitError 100
|
|
|
|
|
|
|
|
|
|
#TODO: stop containers
|
|
|
|
|
#TODO: pull backup via borg
|
|
|
|
|
#TODO: copy backups to correct docker volumes
|
|
|
|
|
#TODO: copy additional files to correct locations
|
|
|
|
|
#TODO: restart docker containers
|
|
|
|
|
#TODO: optionally reindex dovecot (parameter)
|
|
|
|
|
#TODO: delete downloaded backup (parameter)
|
|
|
|
|
|
|
|
|
|
### exit gracefully
|
|
|
|
|
writeLog 'success' "All processes completed"
|
|
|
|
@ -348,13 +363,16 @@ exit 0
|
|
|
|
|
### error codes:
|
|
|
|
|
# 1: parameter error
|
|
|
|
|
# 2: not run as root
|
|
|
|
|
# 3: borg or docker not installed
|
|
|
|
|
# 10: null configuration variable in details file
|
|
|
|
|
# 11: invalid configuration variable in details file
|
|
|
|
|
# 3: docker not installed
|
|
|
|
|
# 4: cannot change to mailcow directory
|
|
|
|
|
# 5: mailcow not initialized before running script
|
|
|
|
|
# 1x: SQL errors
|
|
|
|
|
# 11: cannot locate SQL dump in backup directory
|
|
|
|
|
# 12: cannot start mysql-mailcow container
|
|
|
|
|
# 13: restoring SQL dump was unsuccessful
|
|
|
|
|
# 99: TERM signal trapped
|
|
|
|
|
# 100: could not change to mailcow-dockerized directory
|
|
|
|
|
# 101: could not stop container(s)
|
|
|
|
|
# 102: could not start container(s)
|
|
|
|
|
# 110: borg exited with a critical error
|
|
|
|
|
|
|
|
|
|
#EOF
|
|
|
|
|