Files
praxis/scripts/backup-pg.sh
T
Praxis CI f2a12f9fed docs(milestone): complete v0.4-operator-tier — v0.1.9 tagged, milestone release, merged to main
v0.4 (Operator Tier — Cohort Dashboard + Auth + Postgres) milestone complete.

Phases:
  ✓ P0  pre-execution (planning)        → v0.1.6
  ✓ P1  operator foundation (Postgres+auth+VC migration) → v0.1.7
  ✓ P2  cohort dashboard + aggregation   → v0.1.8
  ✓ P3  final review + ship              → v0.1.9 (= v0.4 milestone release)

Requirements covered (8/8):
  REQ-MT-01 (Postgres store), REQ-MT-02 (aggregation pipeline),
  REQ-AUTH-01 (operator auth), REQ-DASH-01 (cohort dashboard),
  REQ-NFR-AUTH-01 (auth NFRs), REQ-NFR-MT-01 (Postgres-in-LXC),
  REQ-NFR-DASH-01 (k-anonymity ≥10), REQ-NFR-DASH-02 (freshness ≤24h)

Grill MUSTs honored (6/6): G-008, G-011, G-027, G-031, G-038, G-041

Tests: 317 pytest pass, 36 skip (Postgres-requiring), 0 fail; 17/17 vitest pass
Review: APPROVE_WITH_NOTES (6/6 personas, 0 P0, 8 P1+ carry-forward)
Audit: HEALTHY (reconstruction PASS, 8/8 REQ, 6/6 grill)

---ci---
project: praxis
phase: 3
milestone: v0.4
status: complete
phase_role: final
milestone_complete: true
milestone_merged_to_main: true
tag: v0.1.9
requirements:
  covered: [REQ-MT-01, REQ-MT-02, REQ-AUTH-01, REQ-DASH-01, REQ-NFR-AUTH-01, REQ-NFR-MT-01, REQ-NFR-DASH-01, REQ-NFR-DASH-02]
  partial: []
---/ci---
2026-08-04 11:58:44 +00:00

50 lines
2.0 KiB
Bash
Executable File

#!/bin/sh
# Praxis v0.4 — Nightly Postgres backup (D-055, G-008).
#
# Host-side cron script (decoupled from praxis service uptime —
# RESEARCH-v0.4 §1.5). Runs pg_dump inside the postgres container and
# writes a compressed custom-format dump to the pgbackups volume.
#
# The %u date format = day-of-week 1..7 (Monday=1, Sunday=7) → rolling
# 7-file retention with zero cleanup logic (D-055). Re-running overwrites
# the same day-of-week file.
#
# Cron entry (host, 03:30 CT nightly):
# 30 3 * * * /opt/praxis/scripts/backup-pg.sh
#
# Restore drill (G-008 — run at least once in staging to prove the backup
# is valid; NEVER restore into a live DB without stopping praxis first):
# docker compose stop praxis
# docker compose exec postgres pg_restore -U praxis -d praxis \
# --clean --if-exists /backups/praxis-3.dump
# # verify: \d operators; SELECT count(*) FROM operators; (etc. for all 5 tables)
# docker compose start praxis
#
# POSIX-sh compatible (no bashisms). Exit 0 on success, 1 on failure.
# Args: none. Env: COMPOSE_PROJECT_DIR (default: current dir).
set -eu
PROJECT_DIR="${COMPOSE_PROJECT_DIR:-$(pwd)}"
cd "$PROJECT_DIR"
DOW="$(date +%u)"
DUMP_FILE="/backups/praxis-${DOW}.dump"
echo "backup-pg: dumping praxis DB → ${DUMP_FILE} (day-of-week ${DOW})"
# -Fc = custom compressed format (works with pg_restore --clean --if-exists).
# -T stops the container from streaming while dumping? No — pg_dump is
# consistent within a transaction; the praxis service can stay up.
docker compose exec -T postgres pg_dump -U praxis -Fc praxis -f "$DUMP_FILE"
# Verify the dump is non-empty (sanity — a 0-byte dump means failure).
SIZE=$(docker compose exec -T postgres stat -c '%s' "$DUMP_FILE" 2>/dev/null || echo 0)
if [ "$SIZE" -le 0 ]; then
echo "backup-pg: ERROR — dump file is empty (${DUMP_FILE})" >&2
exit 1
fi
echo "backup-pg: OK — ${DUMP_FILE} is ${SIZE} bytes"
echo "backup-pg: restore drill (G-008): docker compose exec postgres pg_restore -U praxis -d praxis --clean --if-exists ${DUMP_FILE}"
exit 0