-
Notifications
You must be signed in to change notification settings - Fork 0
/
restore_old.sh
161 lines (138 loc) · 4.88 KB
/
restore_old.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
#!/usr/bin/env bash
######################################################################################
# Title: Saltbox Restore Service: Restore Script #
# Author(s): l3uddz, desimaniac, salty #
# URL: https://github.com/saltyorg/saltbox #
# Description: Restores encrypted config files from Saltbox Restore Service. #
# -- #
######################################################################################
# GNU General Public License v3.0 #
######################################################################################
# vars
files=( "ansible.cfg" "accounts.yml" "settings.yml" "adv_settings.yml" "backup_config.yml" "providers.yml" "hetzner_nfs.yml" "rclone.conf" "localhost.yml")
restore="crs.saltbox.dev"
folder="$HOME/.restore_service_tmp"
green="\e[1;32m"
red="\e[1;31m"
nc="\e[0m"
done="[ ${green}DONE${nc} ]"
fail="[ ${red}FAIL${nc} ]"
ignore="[ ${red}IGNORE${nc} ]"
# Print banner
echo -e "
$green┌─────────────────────────────────────────────────────────────────────┐
$green│ Title: Saltbox Restore Service: Restore Script │
$green│ Author(s): l3uddz, desimaniac, salty │
$green│ URL: https://github.com/saltyorg/saltbox │
$green│ Description: Restores encrypted config files from the │
$green│ Saltbox Restore Service. │
$green├─────────────────────────────────────────────────────────────────────┤
$green│ GNU General Public License v3.0 │
$green└─────────────────────────────────────────────────────────────────────┘
$nc"
## Functions
# validate url
# https://gist.github.com/hrwgc/7455343
function validate_url(){
if wget -S --spider "$1" 2>&1 | grep -q 'HTTP/1.1 200 OK'
then
return 0
else
return 1
fi
}
## Main
# inputs
USER=$1
PASS=$2
DIR=${3:-/srv/git/saltbox}
# validate inputs
if [ -z "$USER" ] || [ -z "$PASS" ]
then
echo "You must provide the USER & PASS as arguments"
exit 1
fi
# validate folders exist
TMP_FOLDER_RESULT=$(mkdir -p "$folder")
if [ -n "$TMP_FOLDER_RESULT" ]
then
echo "Failed to ensure $folder was created..."
exit 1
else
rm -rf "${folder:?}/"*
fi
RESTORE_FOLDER_RESULT=$(mkdir -p "$DIR")
if [ -n "$RESTORE_FOLDER_RESULT" ]
then
echo "Failed to ensure $DIR was created..."
exit 1
fi
# SHA1 username
USER_HASH=$(echo -n "$USER" | openssl dgst -sha1 | sed 's/^.*= //')
echo "User Hash: $USER_HASH"
echo ''
# Fetch files
echo "Fetching files from $restore..."
echo ''
for file in "${files[@]}"
do
:
# wget file
printf '%-20.20s' "$file"
URL=http://$restore/load/$USER_HASH/$file
if validate_url "$URL"; then
wget -qO "$folder"/"$file".enc "$URL"
# is the file encrypted?
file_header=$(head -c 10 "$folder"/"$file".enc | tr -d '\0')
if [[ $file_header == Salted* ]]; then
echo -e "$done"
else
echo -e "$fail"
exit 1
fi
else
echo -e "$ignore"
fi
done
echo ''
# Decrypt files
echo 'Decrypting fetched files...'
echo ''
for file in "$folder"/*
do
:
filename="$(basename -- "$file" .enc)"
# wget file
printf '%-20.20s' "$filename"
DECRYPT_RESULT=$(openssl enc -aes-256-cbc -d -salt -md md5 -in "$folder"/"${filename}".enc -out "$folder"/"$filename" -k "$PASS" >/dev/null 2>&1)
# was the file decryption successful?
if [ -z "$DECRYPT_RESULT" ]; then
echo -e "$done"
rm "$folder"/"${filename}".enc
else
echo -e "$fail"
exit 1
fi
done
echo ''
# Move decrypted files
echo 'Moving decrypted files...'
echo ''
for file in "$folder"/*
do
:
# move file
filename="$(basename -- "$file")"
printf '%-20.20s' "$filename"
MOVE_RESULT=$(mv "$folder"/"$filename" "$DIR"/"$filename" 2>&1)
# was the decrypted file moved successfully?
if [ -z "$MOVE_RESULT" ]; then
echo -e "$done"
else
echo -e "$fail"
exit 1
fi
done
echo ''
# finish
exit 0