#!/bin/sh set -eu # PostgreSQL backup triggered through the Docker Engine unix socket. # Example: ./postgres-dump-zstd-docker-sock.sh --container=postgres17 --backup-prefix=pgvector17_all_databases_zstd_ --socket=/var/run/docker.sock --api-version=v1.51 --backup-dir=/backups # Remote example: curl -fsSL https://git.1-h.cc/Scripts/Linux/raw/branch/main/postgres-dump-zstd-docker-sock.sh | sh -s -- --container=postgres17 --backup-prefix=pgvector17_all_databases_zstd_ --socket=/var/run/docker.sock --api-version=v1.51 --backup-dir=/backups log() { printf '%s\n' "[cron] $(date -u '+%Y-%m-%dT%H:%M:%SZ') $*" } log_stream() { log_stream_prefix=$1 log_stream_payload=$2 if [ -n "$log_stream_payload" ]; then printf '%s\n' "$log_stream_payload" | while IFS= read -r log_stream_line; do log "$log_stream_prefix: $log_stream_line" done fi } print_usage() { cat <&2 Usage: $0 [--socket=PATH] [--api-version=VERSION] --container=NAME [--backup-dir=DIR] --backup-prefix=PREFIX Options: --socket=PATH Docker Engine unix socket path (default: /var/run/docker.sock) --api-version=VERSION Docker API version (default: v1.51) --container=NAME PostgreSQL container name --backup-dir=DIR Directory to store backups (default: /backups) --backup-prefix=PREFIX Backup filename prefix --help Show this help message EOF } DOCKER_SOCKET="/var/run/docker.sock" DOCKER_API_VERSION="v1.51" PG_CONTAINER_NAME="" BACKUP_DIR="/backups" BACKUP_PREFIX="" require_command() { if ! command -v "$1" >/dev/null 2>&1; then printf '%s requires %s in PATH\n' "$0" "$1" >&2 exit 1 fi } missing_value() { printf 'Missing value for %s\n' "$1" >&2 print_usage exit 1 } docker_exec_create() { docker_exec_create_desc=$1 docker_exec_create_cmd=$2 docker_exec_create_payload=$(jq -n --arg cmd "$docker_exec_create_cmd" '{ AttachStdin: false, AttachStdout: true, AttachStderr: true, Tty: true, Cmd: ["bash", "-lc", $cmd] }') DOCKER_LAST_RESPONSE=$(curl --fail --silent --show-error --unix-socket "$DOCKER_SOCKET" \ -X POST \ -H "Content-Type: application/json" \ -d "$docker_exec_create_payload" \ "$exec_create_endpoint") docker_exec_create_id=$(printf '%s' "$DOCKER_LAST_RESPONSE" | jq -r '.Id // empty') if [ -z "$docker_exec_create_id" ]; then log "failed to create $docker_exec_create_desc exec for $PG_CONTAINER_NAME" log "docker response: $DOCKER_LAST_RESPONSE" return 1 fi printf '%s' "$docker_exec_create_id" } docker_exec_start() { docker_exec_start_id=$1 docker_exec_start_desc=$2 docker_exec_start_endpoint="${docker_api_base}/exec/${docker_exec_start_id}/start" DOCKER_LAST_RESPONSE=$(curl --fail --show-error --silent --unix-socket "$DOCKER_SOCKET" \ -X POST \ -H "Content-Type: application/json" \ -d '{"Detach": false, "Tty": true}' \ "$docker_exec_start_endpoint") log_stream "$docker_exec_start_desc output" "$DOCKER_LAST_RESPONSE" printf '%s' "$DOCKER_LAST_RESPONSE" } docker_exec_exit_code() { docker_exec_exit_id=$1 docker_exec_inspect_endpoint="${docker_api_base}/exec/${docker_exec_exit_id}/json" DOCKER_LAST_RESPONSE=$(curl --fail --silent --show-error --unix-socket "$DOCKER_SOCKET" "$docker_exec_inspect_endpoint") docker_exec_exit_code_value=$(printf '%s' "$DOCKER_LAST_RESPONSE" | jq -r '.ExitCode // empty') if [ -z "$docker_exec_exit_code_value" ]; then return 1 fi printf '%s' "$docker_exec_exit_code_value" } while [ "$#" -gt 0 ]; do case $1 in --socket=*) DOCKER_SOCKET="${1#*=}" ;; --socket) if [ "$#" -lt 2 ]; then missing_value '--socket' fi shift DOCKER_SOCKET="$1" ;; --api-version=*) DOCKER_API_VERSION="${1#*=}" ;; --api-version) if [ "$#" -lt 2 ]; then missing_value '--api-version' fi shift DOCKER_API_VERSION="$1" ;; --container=*) PG_CONTAINER_NAME="${1#*=}" ;; --container) if [ "$#" -lt 2 ]; then missing_value '--container' fi shift PG_CONTAINER_NAME="$1" ;; --backup-dir=*) BACKUP_DIR="${1#*=}" ;; --backup-dir) if [ "$#" -lt 2 ]; then missing_value '--backup-dir' fi shift BACKUP_DIR="$1" ;; --backup-prefix=*) BACKUP_PREFIX="${1#*=}" ;; --backup-prefix) if [ "$#" -lt 2 ]; then missing_value '--backup-prefix' fi shift BACKUP_PREFIX="$1" ;; --help) print_usage exit 0 ;; --) shift break ;; *) printf 'Unknown option: %s\n' "$1" >&2 print_usage exit 1 ;; esac shift done if [ "$#" -gt 0 ]; then printf 'Unexpected positional arguments: %s\n' "$*" >&2 print_usage exit 1 fi require_command curl require_command jq if [ -z "$DOCKER_SOCKET" ] || [ -z "$DOCKER_API_VERSION" ] || [ -z "$PG_CONTAINER_NAME" ] || [ -z "$BACKUP_DIR" ] || [ -z "$BACKUP_PREFIX" ]; then print_usage exit 1 fi if [ ! -S "$DOCKER_SOCKET" ]; then log "docker socket $DOCKER_SOCKET not found" exit 1 fi timestamp=$(date +%Y-%m-%d_%H-%M-%S) backup_path="$BACKUP_DIR/${BACKUP_PREFIX}${timestamp}.sql.zst" docker_api_base="http://localhost/${DOCKER_API_VERSION}" exec_create_endpoint="${docker_api_base}/containers/${PG_CONTAINER_NAME}/exec" log "preparing database backup at $backup_path via docker unix socket" cmd="set -o pipefail && pg_dumpall --username=\"\${POSTGRES_USER:-postgres}\" --clean | zstd > ${backup_path}" if ! exec_id=$(docker_exec_create "backup" "$cmd"); then exit 1 fi log "starting exec $exec_id" if ! start_output=$(docker_exec_start "$exec_id" "exec"); then exit 1 fi if ! exit_code=$(docker_exec_exit_code "$exec_id"); then log "could not determine exec exit code" log "docker inspect response: $DOCKER_LAST_RESPONSE" exit 1 fi if [ "$exit_code" != "0" ]; then log "backup exec exited with status $exit_code" log "docker inspect response: $DOCKER_LAST_RESPONSE" exit "$exit_code" fi if [ -f "$backup_path" ]; then size=$(du -h "$backup_path" 2>/dev/null | awk '{print $1}') if [ -n "$size" ]; then log "backup completed: $backup_path ($size)" else log "backup completed: $backup_path" fi else log "backup file not found on host; verifying inside container $PG_CONTAINER_NAME" verify_cmd="set -eo pipefail && if [ -f \"${backup_path}\" ]; then du -h \"${backup_path}\" 2>/dev/null | awk 'NR==1{print \$1}' || printf 'exists'; else exit 44; fi" if ! verify_exec_id=$(docker_exec_create "verification" "$verify_cmd"); then log "backup command succeeded, but file $backup_path not found" log "database backup finished" exit 0 fi log "starting verification exec $verify_exec_id" if ! verify_start_output=$(docker_exec_start "$verify_exec_id" "verify"); then log "backup command succeeded, but file $backup_path not confirmed" log "database backup finished" exit 0 fi if ! verify_exit_code=$(docker_exec_exit_code "$verify_exec_id"); then log "could not determine verification exec exit code" log "docker inspect response: $DOCKER_LAST_RESPONSE" log "backup command succeeded, but file $backup_path not found" elif [ "$verify_exit_code" = "0" ]; then verify_size=$(printf '%s' "$verify_start_output" | awk 'NF {last=$0} END {print last}') verify_size=$(printf '%s' "$verify_size" | tr -d '\r') if [ -n "$verify_size" ]; then log "backup completed inside container: $backup_path ($verify_size)" else log "backup completed inside container: $backup_path" fi elif [ "$verify_exit_code" = "44" ]; then log "backup command succeeded, but file $backup_path not found inside container $PG_CONTAINER_NAME" else log "verification exec exited with status $verify_exit_code" log "docker inspect response: $DOCKER_LAST_RESPONSE" log "backup command succeeded, but file $backup_path not confirmed" fi fi log "database backup finished"