- move the relational data center to MySQL and a standalone workbench\n- add Interface Center API credentials, policies, logs, and DBeaver SSH guidance\n- harden authentication and deployment while retiring unused management surfaces
37 lines
1.2 KiB
Bash
Executable File
37 lines
1.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -Eeuo pipefail
|
|
|
|
archive_path="${1:-}"
|
|
passphrase_file="${DATA_BACKUP_PASSPHRASE_FILE:-}"
|
|
|
|
if [[ -z "${archive_path}" || ! -f "${archive_path}" ]]; then
|
|
echo "用法:DATA_BACKUP_PASSPHRASE_FILE=/安全路径/密钥 $0 /备份/mysql-all-*.enc" >&2
|
|
exit 2
|
|
fi
|
|
if [[ -z "${passphrase_file}" || ! -r "${passphrase_file}" ]]; then
|
|
echo "缺少可读的 DATA_BACKUP_PASSPHRASE_FILE" >&2
|
|
exit 2
|
|
fi
|
|
|
|
checksum_file="${archive_path}.sha256"
|
|
if [[ ! -f "${checksum_file}" ]]; then
|
|
echo "缺少校验文件:${checksum_file}" >&2
|
|
exit 2
|
|
fi
|
|
expected="$(awk 'NR==1 {print $1}' "${checksum_file}")"
|
|
if command -v sha256sum >/dev/null 2>&1; then
|
|
actual="$(sha256sum "${archive_path}" | awk '{print $1}')"
|
|
else
|
|
actual="$(shasum -a 256 "${archive_path}" | awk '{print $1}')"
|
|
fi
|
|
if [[ -z "${expected}" || "${actual}" != "${expected}" ]]; then
|
|
echo "备份 SHA-256 校验失败" >&2
|
|
exit 1
|
|
fi
|
|
|
|
openssl enc -d -aes-256-cbc -pbkdf2 -iter 200000 \
|
|
-pass "file:${passphrase_file}" -in "${archive_path}" | gzip -t
|
|
|
|
echo "备份加密、校验和与压缩结构验证通过。"
|
|
echo "生产环境仍应定期恢复到隔离 MySQL 实例进行完整恢复演练。"
|