Root cause of a real production failure on the first live install
(wap-proxy, 2026-07-25): DB_PASSWORD was generated with
`openssl rand -base64 24`, which can produce '/', '+', or '=' --
docker-compose.yml then naively interpolated the raw password into
postgres://postgres:${DB_PASSWORD}@db:5432/..., and a generated
password containing '/' broke the connection string outright. The API
never became healthy; log ingestion failed completely.
- install.sh now generates with `openssl rand -hex 32` (always
[0-9a-f], can't produce this class of character). Same fix applied
everywhere else openssl-rand-base64-24 was referenced.
- docker-compose.yml no longer builds DATABASE_URL by string
interpolation -- DB_PASSWORD is passed as its own var and the API
assembles the connection string safely internally using
net/url.UserPassword (proper percent-encoding), a second,
independent layer so the installer doesn't rely on the password
generator alone. See the matching argus-appliance commit for the
Go-side change and its regression test.
- backup.sh/healthcheck.sh/restore.sh/uninstall.sh still defaulted
ARGUS_INSTALL_DIR to $HOME/argus, inconsistent with install.sh/
update.sh's own /opt/argus default (changed in an earlier commit
this session) -- confirmed live on the same install: healthcheck.sh
and uninstall.sh reported "no installation found" when run from the
real, correct directory. All five scripts now agree on /opt/argus.
Corresponding argus-appliance fix (config.go's buildDatabaseURL, v3.73.1)
already built and pushed to git-cloud.weboria.eu/weboria/argus-api.
40 lines
1.2 KiB
Bash
Executable File
40 lines
1.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
#
|
|
# ARGUS backup — dumps the database and application data (certificates,
|
|
# uploaded config) into a single, timestamped archive.
|
|
#
|
|
# cd /opt/argus && ./backup.sh [output-directory]
|
|
#
|
|
set -euo pipefail
|
|
|
|
INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
|
|
OUT_DIR="${1:-$PWD}"
|
|
STAMP="$(date +%Y%m%d-%H%M%S)"
|
|
ARCHIVE="${OUT_DIR}/argus-backup-${STAMP}.tar.gz"
|
|
|
|
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
|
|
ok() { printf ' \033[32m✓\033[0m %s\n' "$1"; }
|
|
fail() { printf ' \033[31m✗\033[0m %s\n' "$1" >&2; exit 1; }
|
|
|
|
[ -f "$INSTALL_DIR/docker-compose.yml" ] || fail "No ARGUS installation found at $INSTALL_DIR (set ARGUS_INSTALL_DIR if you installed elsewhere)."
|
|
cd "$INSTALL_DIR"
|
|
|
|
bold "Backing up ARGUS..."
|
|
|
|
WORKDIR="$(mktemp -d)"
|
|
trap 'rm -rf "$WORKDIR"' EXIT
|
|
|
|
docker compose exec -T db pg_dump -U postgres argus | gzip > "$WORKDIR/db.sql.gz"
|
|
ok "Database dumped"
|
|
|
|
docker run --rm -v argus_api_data:/data -v "$WORKDIR":/backup alpine \
|
|
tar czf /backup/api-data.tar.gz -C /data . >/dev/null 2>&1
|
|
ok "Application data archived"
|
|
|
|
mkdir -p "$OUT_DIR"
|
|
tar czf "$ARCHIVE" -C "$WORKDIR" db.sql.gz api-data.tar.gz
|
|
ok "Backup written to ${ARCHIVE}"
|
|
|
|
echo
|
|
printf ' %s\n' "Restore with: ./restore.sh ${ARCHIVE}"
|