summaryrefslogtreecommitdiff
path: root/scripts/restore-drill.sh
diff options
context:
space:
mode:
authorChia <Chia@93.nz>2026-08-05 22:01:29 +1200
committerChia <Chia@93.nz>2026-08-05 22:07:50 +1200
commiteadb2ffe85c43cf6fc741c9823cd28eedb4a844c (patch)
tree1aba2536d57360da403aa35c9ced58b615c7064e /scripts/restore-drill.sh
parentcd0dd91ab93653631904f2ea0e574ccde6d60339 (diff)
feat: harden prepaid billing and commercial operations
Diffstat (limited to 'scripts/restore-drill.sh')
-rwxr-xr-xscripts/restore-drill.sh14
1 files changed, 14 insertions, 0 deletions
diff --git a/scripts/restore-drill.sh b/scripts/restore-drill.sh
new file mode 100755
index 0000000..53b8cd2
--- /dev/null
+++ b/scripts/restore-drill.sh
@@ -0,0 +1,14 @@
+#!/usr/bin/env bash
+set -euo pipefail
+
+: "${AIGW_RESTORE_DATABASE_URL:?AIGW_RESTORE_DATABASE_URL must point to an isolated drill database}"
+backup="${1:?usage: restore-drill.sh BACKUP.dump}"
+[[ -f "$backup" && -f "$backup.sha256" ]] || { printf 'backup or checksum is missing\n' >&2; exit 2; }
+sha256sum -c "$backup.sha256"
+case "$AIGW_RESTORE_DATABASE_URL" in
+ *localhost*|*127.0.0.1*|*restore*|*drill*) ;;
+ *) printf 'refusing restore: target URL must visibly identify localhost, restore, or drill\n' >&2; exit 2 ;;
+esac
+pg_restore --dbname="$AIGW_RESTORE_DATABASE_URL" --clean --if-exists --no-owner "$backup"
+psql "$AIGW_RESTORE_DATABASE_URL" -v ON_ERROR_STOP=1 -c "SELECT count(*) AS tenants FROM tenants; SELECT count(*) AS usage_events FROM usage_events; SELECT count(*) AS ledger_entries FROM billing_ledger;"
+printf 'restore drill completed for %s\n' "$backup"