Files
Cloud-Tour-to-Libo/scripts/verify_mysql_backup.sh

38 lines
1.5 KiB
Bash
Executable File
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

#!/usr/bin/env bash
set -Eeuo pipefail
archive_path="${1:-}"
passphrase_file="${DATA_BACKUP_PASSPHRASE_FILE:-}"
fail() {
echo "错误:$*" >&2
exit 2
}
[[ -n "${archive_path}" ]] || fail "用法:DATA_BACKUP_PASSPHRASE_FILE=/安全路径/密钥 $0 /备份/mysql-all-*.enc"
[[ "${archive_path}" == /* && ! -L "${archive_path}" && -f "${archive_path}" ]] || fail "备份必须是现有绝对路径,且不能是符号链接"
[[ "${passphrase_file}" == /* && ! -L "${passphrase_file}" && -f "${passphrase_file}" && -r "${passphrase_file}" ]] || fail "缺少安全、可读的 DATA_BACKUP_PASSPHRASE_FILE"
archive_path="$(realpath -e -- "${archive_path}")"
passphrase_file="$(realpath -e -- "${passphrase_file}")"
checksum_file="${archive_path}.sha256"
[[ ! -L "${checksum_file}" && -f "${checksum_file}" ]] || fail "缺少安全的校验文件:${checksum_file}"
expected="$(awk 'NR==1 {print $1}' "${checksum_file}")"
[[ "${expected}" =~ ^[0-9a-fA-F]{64}$ ]] || fail "SHA-256校验文件格式错误"
if command -v sha256sum >/dev/null 2>&1; then
actual="$(sha256sum "${archive_path}" | awk '{print $1}')"
else
actual="$(shasum -a 256 "${archive_path}" | awk '{print $1}')"
fi
if [[ "${actual,,}" != "${expected,,}" ]]; then
echo "备份 SHA-256 校验失败" >&2
exit 1
fi
openssl enc -d -aes-256-cbc -pbkdf2 -iter 200000 \
-pass "file:${passphrase_file}" -in "${archive_path}" | gzip -t
echo "备份加密、SHA-256校验和与压缩结构验证通过。"
echo "生产环境仍应定期恢复到隔离MySQL实例进行完整恢复演练。"