25 Commits
Author SHA1 Message Date
ucef 0be2b5cc52 Merge remote-tracking branch 'origin/prod/v1.8' into prod/v1.8
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Failing after 13m27s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Skipped
2026-09-04 09:37:24 +02:00
ucef 5b4ad0f070 feat(ci): add automated DB backup, UAT RGPD restoration and Gitea CI SSH deployment 2026-09-04 09:33:30 +02:00
ucef b1d897a3c8 fix(backup): handle SIGPIPE exit code 141 in pg_dump pipeline
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m2s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Successful in 1m20s
2026-09-04 09:19:13 +02:00
ucef f6c853068f fix(backup): purge pg_largeobject metadata prior to UAT schema reset
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m15s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Successful in 1m29s
2026-09-04 09:07:31 +02:00
ucef 19e969eb09 fix(backup): clean UAT schema before restore and add --no-owner --no-privileges to pg_dump
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m1s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Successful in 1m25s
2026-09-04 08:54:48 +02:00
ucef e933218443 feat(backup): update DB UAT port
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m7s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Successful in 1m23s
2026-09-04 08:43:24 +02:00
ucef c994cbe155 feat(backup): add automatic database restoration and RGPD anonymization for UAT environment (10.8.0.2) 2026-09-04 08:39:21 +02:00
ucef c778dea9a0 fix(ci): combine --net=host with Base64 payload transfer for key, script, and env to resolve VPN routing and file isolation
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 1m59s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Successful in 1m19s
2026-09-04 08:10:08 +02:00
ucef 2720a2193d fix(ci): execute deployment directly in runner step environment without nested container
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 1m59s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m27s
2026-09-04 08:03:23 +02:00
ucef e1d797eb01 fix(ci): use GITHUB_WORKSPACE for repository volume mount and absolute path /workspace/ for rsync
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m1s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m16s
2026-09-04 07:26:53 +02:00
ucef c06abb1d17 fix(ci): re-wrap PEM payload to 64 chars with explicit trailing newline
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 1m56s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m18s
2026-09-04 07:18:12 +02:00
ucef 0a56944daa fix(ci): validate SSH key header format and provide explicit guidance for Gitea secret value
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m3s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m13s
2026-09-04 07:04:21 +02:00
ucef 292c2bb8ec fix(ci): handle file paths in RAW_KEY and add key line count diagnostic logs
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m9s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m14s
2026-09-03 15:55:13 +02:00
ucef a991fd9f35 fix(ci): pass SSH key as base64 environment variable to completely eliminate volume mount issues
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m9s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m14s
2026-09-03 15:47:40 +02:00
ucef 5fb6356f8a fix(ci): strict regular file check and explicit error message when PROD_DB_SSH_KEY is missing
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m7s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m14s
2026-09-03 15:39:35 +02:00
ucef 9990bba799 fix(ci): write secret key to runner file before docker run to preserve multi-line format
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m4s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m14s
2026-09-03 15:26:22 +02:00
ucef 494fcfbf8a fix(ci): use PROD_DB_SSH_KEY Gitea secret for reliable cross-runner authentication
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m1s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m13s
2026-09-03 15:19:28 +02:00
ucef 5e7e5c461c security: replace key header log with safe public ssh-keygen fingerprint display
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m13s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m20s
2026-09-03 15:11:16 +02:00
ucef 63bc5da40c ci: add comprehensive diagnostic logs and ssh -vv trace to step 2026-09-03 15:09:07 +02:00
ucef a4c852d254 fix(ci): mount /home/ucef/.ssh and prioritize gitea_ci_key over generic host keys
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m5s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m22s
2026-09-03 15:02:09 +02:00
ucef 815eb72834 fix(ci): copy key to /tmp/id_rsa instead of ~/.ssh/id_rsa to avoid read-only mount error
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m6s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m23s
2026-09-03 14:56:31 +02:00
ucef 881a81f53b fix(ci): robust SSH key resolution supporting both file paths and Gitea secrets
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m6s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m15s
2026-09-03 14:49:33 +02:00
ucef 747cf1a0fa refactor(ci): simplify SSH step to directly copy and use /root/.ssh/gitea_ci_key with 600 permissions
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m8s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m14s
2026-09-03 14:40:45 +02:00
ucef 2472407cca fix(ci): prioritize /root/.ssh/gitea_ci_key mount
AS Talange CI/CD Pipeline - Production / Build & Run Unit Tests (push) Successful in 2m15s
AS Talange CI/CD Pipeline - Production / Deploy to Prod Environment (push) Failing after 1m27s
2026-09-03 14:29:20 +02:00
ucef 02f9674b7a fix(ci): mount /home/ubuntu/.ssh and auto-detect gitea_ci_key location 2026-09-03 14:26:53 +02:00
2 changed files with 152 additions and 21 deletions
+56 -15
View File
@@ -120,34 +120,75 @@ jobs:
DB_SERVER_HOST: ${{ secrets.PROD_DB_HOST }} DB_SERVER_HOST: ${{ secrets.PROD_DB_HOST }}
DB_SERVER_USER: ${{ secrets.PROD_DB_SSH_USER }} DB_SERVER_USER: ${{ secrets.PROD_DB_SSH_USER }}
REMOTE_PORT: ${{ secrets.REMOTE_PORT }} REMOTE_PORT: ${{ secrets.REMOTE_PORT }}
PROD_DB_SSH_KEY: ${{ secrets.PROD_DB_SSH_KEY }}
SSH_KEY_PATH_SECRET: ${{ secrets.SSH_KEY_PATH }}
SSH_KEY_SECRET: ${{ secrets.SSH_KEY }}
run: | run: |
TARGET_HOST="${DB_SERVER_HOST:-10.8.0.3}" TARGET_HOST="${DB_SERVER_HOST:-10.8.0.3}"
TARGET_USER="${DB_SERVER_USER:-root}" TARGET_USER="${DB_SERVER_USER:-root}"
PORT="${REMOTE_PORT:-22}" PORT="${REMOTE_PORT:-22}"
DEST_DIR="/opt/as-talange" DEST_DIR="/opt/as-talange"
RAW_KEY="${PROD_DB_SSH_KEY:-${SSH_KEY_PATH_SECRET:-${SSH_KEY_SECRET}}}"
if [ -n "${RAW_KEY}" ] && [ -f "${RAW_KEY}" ]; then
RAW_KEY=$(cat "${RAW_KEY}")
fi
if [ -z "${RAW_KEY}" ]; then
if [ -f /root/.ssh/gitea_ci_key ]; then
RAW_KEY=$(cat /root/.ssh/gitea_ci_key)
elif [ -f /home/ucef/.ssh/gitea_ci_key ]; then
RAW_KEY=$(cat /home/ucef/.ssh/gitea_ci_key)
fi
fi
if [ -z "${RAW_KEY}" ]; then
echo "========================================================================="
echo "ERREUR : Le secret PROD_DB_SSH_KEY est totalement vide dans Gitea !"
echo "========================================================================="
exit 1
fi
KEY_B64=$(printf "%s" "${RAW_KEY}" | tr -d '\r' | base64 | tr -d '\r\n')
SCRIPT_B64=$(base64 scripts/backup_db.sh | tr -d '\r\n')
[ -f .env ] && ENV_B64=$(base64 .env | tr -d '\r\n') || ENV_B64=""
docker run --rm --net=host \ docker run --rm --net=host \
-v "$(pwd):/workspace" -w /workspace \
-v "${HOME}/.ssh:/root/.ssh:ro" \
-e TARGET_HOST="${TARGET_HOST}" \ -e TARGET_HOST="${TARGET_HOST}" \
-e TARGET_USER="${TARGET_USER}" \ -e TARGET_USER="${TARGET_USER}" \
-e PORT="${PORT}" \ -e PORT="${PORT}" \
-e DEST_DIR="${DEST_DIR}" \ -e DEST_DIR="${DEST_DIR}" \
-e KEY_B64="${KEY_B64}" \
-e SCRIPT_B64="${SCRIPT_B64}" \
-e ENV_B64="${ENV_B64}" \
alpine:latest sh -c ' alpine:latest sh -c '
apk add --no-cache openssh-client rsync && \ apk add --no-cache openssh-client rsync coreutils && \
KEY_ARG="" && \ (echo "$KEY_B64" | base64 -d 2>/dev/null || echo "$KEY_B64" | base64 --decode) > /tmp/raw_key && \
if [ -f /root/.ssh/gitea_ci_key ]; then \ HEADER=$(grep "BEGIN" /tmp/raw_key) && \
KEY_ARG="-i /root/.ssh/gitea_ci_key -o IdentitiesOnly=yes" ; \ FOOTER=$(grep "END" /tmp/raw_key) && \
elif [ -f /root/.ssh/id_ed25519 ]; then \ BODY=$(grep -v "BEGIN" /tmp/raw_key | grep -v "END" | tr -d " \r\n") && \
KEY_ARG="-i /root/.ssh/id_ed25519 -o IdentitiesOnly=yes" ; \ printf "%s\n" "$HEADER" > /tmp/working_key && \
elif [ -f /root/.ssh/id_rsa ]; then \ printf "%s\n" "$BODY" | fold -w 64 >> /tmp/working_key && \
KEY_ARG="-i /root/.ssh/id_rsa -o IdentitiesOnly=yes" ; \ printf "%s\n" "$FOOTER" >> /tmp/working_key && \
echo "" >> /tmp/working_key && \
chmod 600 /tmp/working_key && \
(echo "$SCRIPT_B64" | base64 -d 2>/dev/null || echo "$SCRIPT_B64" | base64 --decode) > /tmp/backup_db.sh && \
if [ -n "$ENV_B64" ]; then \
(echo "$ENV_B64" | base64 -d 2>/dev/null || echo "$ENV_B64" | base64 --decode) > /tmp/.env ; \
else \
touch /tmp/.env ; \
fi && \ fi && \
SSH_CMD="ssh -p ${PORT} ${KEY_ARG} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no -o ConnectTimeout=15" && \ echo "=== 🔍 DIAGNOSTIC DETAILS ===" && \
echo "Deploying backup script and .env to DB Server (${TARGET_USER}@${TARGET_HOST}:${DEST_DIR})..." && \ echo "Target Host: ${TARGET_USER}@${TARGET_HOST} (Port: ${PORT})" && \
echo "Destination Directory: ${DEST_DIR}" && \
echo "=== 🔑 KEY FINGERPRINT ===" && \
ssh-keygen -l -f /tmp/working_key && \
SSH_CMD="ssh -p ${PORT} -i /tmp/working_key -o IdentitiesOnly=yes -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no -o ConnectTimeout=15" && \
echo "=== 🚀 EXECUTING REMOTE COMMAND ===" && \
$SSH_CMD "${TARGET_USER}@${TARGET_HOST}" "mkdir -p ${DEST_DIR}/scripts" && \ $SSH_CMD "${TARGET_USER}@${TARGET_HOST}" "mkdir -p ${DEST_DIR}/scripts" && \
rsync -avz -e "$SSH_CMD" scripts/backup_db.sh "${TARGET_USER}@${TARGET_HOST}:${DEST_DIR}/scripts/" && \ echo "=== 📦 RSYNC TRANSFER SCRIPT & ENV ===" && \
rsync -avz -e "$SSH_CMD" .env "${TARGET_USER}@${TARGET_HOST}:${DEST_DIR}/.env" && \ rsync -avz -e "$SSH_CMD" /tmp/backup_db.sh "${TARGET_USER}@${TARGET_HOST}:${DEST_DIR}/scripts/backup_db.sh" && \
rsync -avz -e "$SSH_CMD" /tmp/.env "${TARGET_USER}@${TARGET_HOST}:${DEST_DIR}/.env" && \
$SSH_CMD "${TARGET_USER}@${TARGET_HOST}" "chmod +x ${DEST_DIR}/scripts/backup_db.sh" && \ $SSH_CMD "${TARGET_USER}@${TARGET_HOST}" "chmod +x ${DEST_DIR}/scripts/backup_db.sh" && \
echo "Backup script and .env deployed successfully to ${DEST_DIR} on DB Server!" echo "SUCCESS: Backup script and .env deployed successfully to ${DEST_DIR} on DB Server!"
' '
+96 -6
View File
@@ -31,6 +31,14 @@ DB_HOST="${POSTGRES_HOST:-localhost}"
DB_PORT="${POSTGRES_PORT:-5432}" DB_PORT="${POSTGRES_PORT:-5432}"
CONTAINER_NAME="${DOCKER_CONTAINER_NAME:-astalange_db}" CONTAINER_NAME="${DOCKER_CONTAINER_NAME:-astalange_db}"
# Variables UAT
ENABLE_UAT_RESTORE="${ENABLE_UAT_RESTORE:-true}"
UAT_DB_HOST="${UAT_DB_HOST:-10.8.0.2}"
UAT_DB_PORT="${UAT_DB_PORT:-5433}"
UAT_DB_NAME="${UAT_DB_NAME:-astalange}"
UAT_DB_USER="${UAT_DB_USER:-myuser}"
UAT_DB_PASSWORD="${UAT_DB_PASSWORD:-mypassword}"
# Configuration du transfert distant vers le VPS (optionnel) # Configuration du transfert distant vers le VPS (optionnel)
ENABLE_REMOTE_COPY="${ENABLE_REMOTE_COPY:-false}" ENABLE_REMOTE_COPY="${ENABLE_REMOTE_COPY:-false}"
REMOTE_HOST="${REMOTE_HOST:-}" REMOTE_HOST="${REMOTE_HOST:-}"
@@ -80,24 +88,106 @@ if [ "$STATUS" = "SUCCESS" ]; then
# Vérification si le conteneur Docker est actif # Vérification si le conteneur Docker est actif
if command -v docker >/dev/null 2>&1 && docker ps --format '{{.Names}}' | grep -q "^${CONTAINER_NAME}$"; then if command -v docker >/dev/null 2>&1 && docker ps --format '{{.Names}}' | grep -q "^${CONTAINER_NAME}$"; then
log "Mode détection: Conteneur Docker '${CONTAINER_NAME}' trouvé. Utilisation de pg_dump via docker exec." log "Mode détection: Conteneur Docker '${CONTAINER_NAME}' trouvé. Utilisation de pg_dump via docker exec."
docker exec -e PGPASSWORD="${DB_PASSWORD}" "${CONTAINER_NAME}" pg_dump -U "${DB_USER}" -d "${DB_NAME}" | gzip > "$DUMP_PATH" 2>> "$LOG_FILE" docker exec -e PGPASSWORD="${DB_PASSWORD}" "${CONTAINER_NAME}" pg_dump --no-owner --no-privileges -U "${DB_USER}" -d "${DB_NAME}" | gzip > "$DUMP_PATH" 2>> "$LOG_FILE"
DUMP_EXIT_CODE=${PIPESTATUS[0]} DUMP_EXIT_CODE=${PIPESTATUS[0]}
else else
log "Mode détection: Exécution directe de pg_dump (hôte local)." log "Mode détection: Exécution directe de pg_dump (hôte local)."
PGPASSWORD="${DB_PASSWORD}" pg_dump -h "${DB_HOST}" -p "${DB_PORT}" -U "${DB_USER}" -d "${DB_NAME}" | gzip > "$DUMP_PATH" 2>> "$LOG_FILE" PGPASSWORD="${DB_PASSWORD}" pg_dump --no-owner --no-privileges -h "${DB_HOST}" -p "${DB_PORT}" -U "${DB_USER}" -d "${DB_NAME}" | gzip > "$DUMP_PATH" 2>> "$LOG_FILE"
DUMP_EXIT_CODE=${PIPESTATUS[0]} DUMP_EXIT_CODE=${PIPESTATUS[0]}
fi fi
if [ ${DUMP_EXIT_CODE} -eq 0 ] && [ -s "$DUMP_PATH" ]; then if [ ${DUMP_EXIT_CODE} -eq 0 ] || [ ${DUMP_EXIT_CODE} -eq 141 ]; then
DUMP_SIZE=$(du -h "$DUMP_PATH" | cut -f1) if [ -s "$DUMP_PATH" ]; then
log "✅ Dump généré avec succès ! Taille du fichier : ${DUMP_SIZE}" DUMP_SIZE=$(du -h "$DUMP_PATH" | cut -f1)
else log "✅ Dump généré avec succès ! Taille du fichier : ${DUMP_SIZE}"
DUMP_EXIT_CODE=0
fi
fi
if [ ${DUMP_EXIT_CODE} -ne 0 ]; then
log "❌ ERREUR lors de l'extraction de la base de données (code de sortie: ${DUMP_EXIT_CODE})." log "❌ ERREUR lors de l'extraction de la base de données (code de sortie: ${DUMP_EXIT_CODE})."
STATUS="FAILURE" STATUS="FAILURE"
rm -f "$DUMP_PATH" rm -f "$DUMP_PATH"
fi fi
fi fi
# 2b. Restauration et Anonymisation vers la BDD UAT (10.8.0.2)
if [ "$STATUS" = "SUCCESS" ] && [ "$ENABLE_UAT_RESTORE" = "true" ]; then
log "Démarrage de la restauration et l'anonymisation sur UAT (${UAT_DB_USER}@${UAT_DB_HOST}:${UAT_DB_PORT}/${UAT_DB_NAME})..."
CLEAN_SCHEMA_SQL="
DO \$\$ DECLARE r RECORD; BEGIN FOR r IN (SELECT oid FROM pg_largeobject_metadata) LOOP PERFORM lo_unlink(r.oid); END LOOP; EXCEPTION WHEN OTHERS THEN NULL; END \$\$;
DROP SCHEMA IF EXISTS public CASCADE;
CREATE SCHEMA public;
GRANT ALL ON SCHEMA public TO ${UAT_DB_USER};
GRANT ALL ON SCHEMA public TO public;
"
ANONYMIZE_SQL="
UPDATE adherent SET
nom = 'Nom_Adherent_' || id,
prenom = 'Prenom_Adherent_' || id,
email = 'adherent' || id || '@test.local',
telephone = '06' || LPAD((id)::text, 8, '0'),
lieu_naissance_ville = 'Ville_' || id,
representant_legal = CASE
WHEN representant_legal IS NOT NULL AND TRIM(representant_legal) <> ''
THEN 'Representant_' || id
ELSE representant_legal
END;
UPDATE pre_inscription SET
nom = 'Nom_PreInscr_' || id,
prenom = 'Prenom_PreInscr_' || id,
email = 'preinscr' || id || '@test.local',
telephone = '06' || LPAD((id)::text, 8, '0'),
lieu_naissance_ville = 'Ville_' || id,
representant_legal = CASE
WHEN representant_legal IS NOT NULL AND TRIM(representant_legal) <> ''
THEN 'Representant_PreInscr_' || id
ELSE representant_legal
END;
UPDATE educateur SET
nom = 'Nom_Educ_' || id,
prenom = 'Prenom_Educ_' || id,
email = 'educ' || id || '@test.local',
telephone = '06' || LPAD((id)::text, 8, '0');
"
RESTORE_SUCCESS=false
if command -v psql >/dev/null 2>&1; then
log "Réinitialisation du schéma public sur UAT..."
PGPASSWORD="${UAT_DB_PASSWORD}" psql -h "${UAT_DB_HOST}" -p "${UAT_DB_PORT}" -U "${UAT_DB_USER}" -d "${UAT_DB_NAME}" -c "$CLEAN_SCHEMA_SQL" >> "$LOG_FILE" 2>&1
log "Restauration du dump Prod vers UAT..."
if gunzip -c "$DUMP_PATH" | PGPASSWORD="${UAT_DB_PASSWORD}" psql -h "${UAT_DB_HOST}" -p "${UAT_DB_PORT}" -U "${UAT_DB_USER}" -d "${UAT_DB_NAME}" >> "$LOG_FILE" 2>&1; then
log "Exécution des requêtes d'anonymisation sur UAT..."
if PGPASSWORD="${UAT_DB_PASSWORD}" psql -h "${UAT_DB_HOST}" -p "${UAT_DB_PORT}" -U "${UAT_DB_USER}" -d "${UAT_DB_NAME}" -c "$ANONYMIZE_SQL" >> "$LOG_FILE" 2>&1; then
RESTORE_SUCCESS=true
fi
fi
elif command -v docker >/dev/null 2>&1; then
log "Réinitialisation du schéma public sur UAT via Docker..."
docker run --rm --net=host -e PGPASSWORD="${UAT_DB_PASSWORD}" postgres:15-alpine psql -h "${UAT_DB_HOST}" -p "${UAT_DB_PORT}" -U "${UAT_DB_USER}" -d "${UAT_DB_NAME}" -c "$CLEAN_SCHEMA_SQL" >> "$LOG_FILE" 2>&1
log "Restauration du dump Prod vers UAT via Docker..."
if gunzip -c "$DUMP_PATH" | docker run --rm -i --net=host -e PGPASSWORD="${UAT_DB_PASSWORD}" postgres:15-alpine psql -h "${UAT_DB_HOST}" -p "${UAT_DB_PORT}" -U "${UAT_DB_USER}" -d "${UAT_DB_NAME}" >> "$LOG_FILE" 2>&1; then
log "Exécution des requêtes d'anonymisation sur UAT via Docker..."
if docker run --rm --net=host -e PGPASSWORD="${UAT_DB_PASSWORD}" postgres:15-alpine psql -h "${UAT_DB_HOST}" -p "${UAT_DB_PORT}" -U "${UAT_DB_USER}" -d "${UAT_DB_NAME}" -c "$ANONYMIZE_SQL" >> "$LOG_FILE" 2>&1; then
RESTORE_SUCCESS=true
fi
fi
fi
if [ "$RESTORE_SUCCESS" = "true" ]; then
log "✅ Restauration et anonymisation UAT réussies avec succès !"
else
log "⚠️ AVERTISSEMENT: Impossible d'effectuer la restauration/anonymisation UAT."
fi
fi
# 3. Transfert sécurisé RSYNC / SCP vers le serveur VPS (Optionnel) # 3. Transfert sécurisé RSYNC / SCP vers le serveur VPS (Optionnel)
if [ "$STATUS" = "SUCCESS" ] && [ "$ENABLE_REMOTE_COPY" = "true" ] && [ -n "$REMOTE_HOST" ]; then if [ "$STATUS" = "SUCCESS" ] && [ "$ENABLE_REMOTE_COPY" = "true" ] && [ -n "$REMOTE_HOST" ]; then
log "Transfert du dump vers le serveur VPS distant (${REMOTE_USER}@${REMOTE_HOST}:${REMOTE_BACKUP_DIR})..." log "Transfert du dump vers le serveur VPS distant (${REMOTE_USER}@${REMOTE_HOST}:${REMOTE_BACKUP_DIR})..."