Files
blog/scripts/backup-task.cmd
T
zqlit 5f27ad321d chore(备份): 异地备份定案为 OpenList 离线 bundle,撤销全部 git 辅仓
用户定案:「辅助仓就用 openlist,其他不再考虑」。
据此把前一轮为 Gitee 铺的路全部收回,git 远端只剩 CNB 一个。

一、git 配置收口
- `pushall` 别名 `origin + gitee` → `!git push origin main`(只推唯一远端)
- 移除 `gitea` remote(自建 23.254.236.47:3001)—— 远端仓库本身没删,
  需要时可 `git remote add` 恢复;改动前配置存
  `.workbuddy-backup/git-remotes.20261006-211516.txt`
- 确认无 gitee 相关 credential 残留

二、发布链路去 Gitee 化(6 处)
- `deploy/editor-api/bootstrap.sh`
    · 删掉 GITEE_URL / GITEE_SSH_KEY 两个变量与「没给私钥就降级」的分支
    · PUSH_REMOTES 默认 → origin
    · 原「配 gitee 辅仓远端」一节改为「清理退役远端」循环(gh/gitee/gitea),
      让从旧部署续用的工作区自动恢复干净
- `docker-compose.editor.yml`、`editor-api/server.mjs` → 默认值 origin
- `editor-api/README.md` → 变量表同步
- `editor-api/Dockerfile` → 注释里的「CNB / GitHub」改「CNB」
- `blog-admin/src/routes/rss/tools.ts` → deploy-notify 的注释里
  「与 Gitea Actions 的构建通知配套」改为中性描述
  (该轮询链路 2026-10-04 起已被 CNB 国内节点直传取代)

三、`scripts/setup-cnb-remotes.sh` 重写为单远端模式
- 去掉 GITEE_URL / GITEE_TOKEN 参数、校验、凭据写入与自检提示
- 新增「清理退役远端」步骤
- 凭据处理改为「已存在空的 credential.helper 就不再添加」,
  不再用 --replace-all —— 本仓另有一个从 `$HOME/.workbuddy/secrets/cnb-token`
  读令牌的自定义 helper,那是有效的,不能被脚本抹掉

四、备份升级为「唯一辅仓」的配置
- 保留份数 3 → 7(一周窗口;每份 605.5 MB ≈ 4.2 GB,F50 有 256 GB)
    · `scripts/backup-task.cmd` 默认参数 --keep 7
    · `scripts/backup-bundle.mjs` 的 KEEP 默认值同步为 7
      (原先写的是 2,一直被命令行参数掩盖着)
- 远端目录 `/本地/备份` → `/本地/备份/blog-bundle`:
  根目录是用户自己在用的(放着 github-zqlit-*、local-repos-* 等手工备份),
  实测发现直接放根下的 bundle 已被清掉 —— 改子目录隔离,避免混放与误删

五、新增 `scripts/backup-run.mjs`:备份的推荐入口 + 失败告警
- 读 `.workbuddy-backup/openlist-backup.env`(只补空缺,环境变量优先)
- 跑 backup-bundle.mjs 并实时透传输出,同时留一份日志尾部
- 退出码非 0 → 经 `scripts/send_mail.js` 发告警邮件(附日志尾部与常见原因);
  成功默认不发,`--notify-success` 才发
- 退出用 `process.exitCode` 而非 `process.exit()`,避免截断未排干的 stdout
- 发信失败不改判备份退出码 —— 通知不该掩盖真正的故障
- 理由:这是当前**唯一**的异地备份,而「每天自动跑」的任务最典型的失败模式
  恰恰是静默的(F50 被带出门、换了网段、OpenList 没起来、口令改过……),
  没有告警就要等到真要用备份那天才发现
- `scripts/backup-task.cmd` 改调它

六、文档
- `架构总览.md`
    · §1.2 地址地图:备份行改指 F50/OpenList;通知行补「兼做备份失败告警」
    · §2 旅程图:双推改单推,并说明备份换了介质
    · §5.1 / §5.2 推送与远端:只剩 origin;补「已移除远端」表与恢复命令;
      GitHub 退役记录保留并补上「CI 定义也已删除」
    · §5.3 由「辅仓选型」改为「异地备份的定案」—— 明确不走 git 远端;
      平台对比数据保留备查,并注明 `bin/linux/hugo` 出库不必再做了
    · §5.6 补「唯一备份」定位、专属子目录、失败告警、keep 7、SMTP 配置键,
      实测数据更新为本次复测值
    · §6 待办:#2 定案、#3 不必做、#4 已移除、#8 已更新、#10 定位升级,
      新增 #11(F50 目录使用约定)
- `CNB构建落地方案.md` §4.0:双远端改单远端,脚本示例去掉 Gitee 参数
- `README.md`:推送说明改单推;脚本表补 backup-run.mjs

实测(2026-10-06,本轮复测):
  bundle 7.4s / AES-256-GCM 加密 1.3s / 上传 19.2s(31.6 MB/s)
  / 读回 sha256 一致 → 端到端 60.6s,退出码 0
  告警邮件链路已实测(发出一封「备份成功」验证信)

★ 一处过程记录,供以后避免重复踩坑:
  中途我把「本机沙箱里 `env -u ... cmd > file` 会让输出整个消失」
  误判成 process.exit 截断 stdout,并据此改了日志实现;
  随后用 `env -u FOO echo hi > file`(同样零输出)证伪 ——
  那是沙箱文件重定向的伪影,与脚本无关。相关改动已回滚,
  只留下本身无害的 process.exitCode 写法。
2026-10-06 21:27:28 +08:00

74 lines
3.6 KiB
Batchfile

@echo off
rem ============================================================================
rem blog full-repo backup - entry point for Windows Task Scheduler
rem
rem scripts/backup-run.mjs is what gets invoked. It:
rem - loads .workbuddy-backup\openlist-backup.env
rem - runs scripts/backup-bundle.mjs (git bundle --all -> AES-256-GCM encrypt
rem -> WebDAV upload to OpenList on the ZTE F50 -> sha256 readback check)
rem - emails an alert through scripts/send_mail.js when the backup fails
rem
rem OpenList is the ONLY off-site copy, so a silent failure would mean running
rem with no backup at all. Hence failures raise an email instead of just
rem appending to a log nobody reads.
rem
rem Notes:
rem * This file is intentionally pure ASCII. cmd.exe parses a .bat/.cmd using
rem the *current* code page (GBK on zh-CN) while node emits UTF-8. A UTF-8
rem Chinese comment can swallow the CR/LF and break the following line
rem (seen in practice: a rem line got executed as a command). ASCII is a
rem subset of UTF-8, so plain-English text mixes safely with node output.
rem For the same reason the alert subject/body (which is Chinese) is built
rem inside backup-run.mjs, never here.
rem * node resolution order: PATH -> WorkBuddy managed -> D:\nodejs
rem * Log appends to .workbuddy-backup\logs\backup.log, rotated at 5 MB
rem * .workbuddy-backup is git-ignored; logs, passphrase and SMTP creds
rem never enter git
rem * Exit code is passed through (0 = success), visible in Task Scheduler
rem ============================================================================
setlocal
set "REPO=%~dp0.."
if "%REPO:~-1%"=="\" set "REPO=%REPO:~0,-1%"
set "LOG=%REPO%\.workbuddy-backup\logs"
set "SCRIPT=%REPO%\scripts\backup-run.mjs"
if not exist "%LOG%" mkdir "%LOG%"
rem --- rotate log at 5 MB. Guarded by if exist: on the very first run the file
rem does not exist yet and for/f would fail with a "path not found" error ---
if exist "%LOG%\backup.log" for %%F in ("%LOG%\backup.log") do if %%~zF GTR 5242880 move /y "%LOG%\backup.log" "%LOG%\backup.prev.log" >nul 2>&1
rem --- locate node ---
set "NODE="
for %%P in (node.exe) do if not defined NODE set "NODE=%%~$PATH:P"
if not defined NODE if exist "%USERPROFILE%\.workbuddy\binaries\node\versions\22.22.2-6\node.exe" set "NODE=%USERPROFILE%\.workbuddy\binaries\node\versions\22.22.2-6\node.exe"
if not defined NODE if exist "D:\nodejs\node.exe" set "NODE=D:\nodejs\node.exe"
if not defined NODE call :fail "node not found in PATH, WorkBuddy managed dir, or D:\nodejs"
if not exist "%SCRIPT%" call :fail "script not found: %SCRIPT%"
rem --- ASCII timestamp. Do NOT use %date%: on zh-CN it carries localized
rem weekday text (e.g. Chinese "Tuesday") which would mix encodings ---
set "STAMP=%TIME%"
for /f "delims=" %%I in ('powershell -NoProfile -Command "[DateTime]::Now.ToString('yyyy-MM-dd HH:mm:ss')" 2^>nul') do set "STAMP=%%I"
rem --- arguments: use %* when given (handy for manual runs, e.g. --dry / --list) ---
rem keep 7 = one week of daily snapshots (~600 MB each, ~4.2 GB total, the
rem F50 has 256 GB). OpenList is the only off-site copy, so a wider window
rem is worth the space. Pass --notify-success to also get a daily OK mail.
set "ARGS=%*"
if "%ARGS%"=="" set "ARGS=--verify --keep 7"
echo. >> "%LOG%\backup.log"
echo [%STAMP%] ===== backup start ===== >> "%LOG%\backup.log"
"%NODE%" "%SCRIPT%" %ARGS% >> "%LOG%\backup.log" 2>&1
set "RC=%ERRORLEVEL%"
echo [%STAMP%] ===== backup end, exit=%RC% ===== >> "%LOG%\backup.log"
endlocal & exit /b %RC%
:fail
echo [%TIME%] ERROR: %~1 >> "%LOG%\backup.log"
endlocal & exit /b 1