-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathgit-backup.sh
More file actions
executable file
·22 lines (19 loc) · 1.17 KB
/
Copy pathgit-backup.sh
File metadata and controls
executable file
·22 lines (19 loc) · 1.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
#!/bin/bash
# Nightly repo backup. The repo is PUBLIC: refuse to push anything that looks
# like a secret, and regenerate the per-tab exports in flows/ first.
cd /opt/node-red || exit 1
python3 split_flows.py > /dev/null
PATTERNS='PVEAPIToken=|\$2[aby]\$[0-9]{2}\$|eyJ[A-Za-z0-9_-]{20,}|ghp_[A-Za-z0-9]{10,}|github_pat_|nabu\.casa|AKIA[0-9A-Z]{16}|xox[baprs]-|-----BEGIN .*PRIVATE KEY'
HITS=$(grep -InE "$PATTERNS" data/flows.json data/settings.js docker-compose.yml flows/*.json README.md .env.example 2>/dev/null \
| grep -vE 'env\.get|process\.env|zZWtXTja|PVEAPIToken=<|your-id>?\.ui\.nabu\.casa|substringAfter\(url,')
if [ -n "$HITS" ]; then
echo "$HITS" > /opt/node-red/secret-scan-blocked.txt
curl -s -m 10 -X POST -H 'Content-Type: application/json' \
-d '{"message":"Secret-scan HIT - nightly git push BLOCKED. Details in /opt/node-red/secret-scan-blocked.txt - clean the flow, then re-run git-backup.sh."}' \
http://localhost:1880/nr-backup-alert > /dev/null
exit 1
fi
rm -f /opt/node-red/secret-scan-blocked.txt
git add -A
git -c user.email=node-red-lxc@localhost -c user.name=node-red-lxc commit -q -m "auto backup $(date +%F\ %H:%M)" || exit 0
git push -q