Compare commits

..

1 Commits

Author SHA1 Message Date
oysteikt 4ed1668ac5 bicep/{postgres,mysql}: bindmount data storage with noatime
Eval nix flake / evals (push) Successful in 7m28s
Eval nix flake / evals (pull_request) Successful in 8m57s
2026-07-21 21:32:58 +09:00
4 changed files with 48 additions and 52 deletions
+11 -25
View File
@@ -41,38 +41,24 @@ in
path = with pkgs; [
cfg.package
coreutils
diffutils
zstd
];
script = ''
script = let
rotations = 2;
in ''
set -euo pipefail
dump() {
local name="$1" out tmp
out="$STATE_DIRECTORY/$name.sql.zst"
tmp="$out.tmp"
shift
"$@" | zstd -9 --rsyncable -f -o "$tmp"
if cmp -s "$tmp" "$out" 2>/dev/null; then
rm -f "$tmp"
else
mv -f "$tmp" "$out"
fi
}
OUT_FILE="$STATE_DIRECTORY/mysql-dump-$(date --iso-8601).sql.zst"
declare -A keep
while IFS= read -r db; do
[ -n "$db" ] || continue
dump "$db" mysqldump --skip-dump-date --databases "$db"
keep["$db.sql.zst"]=1
done < <(mysql -N -e 'SHOW DATABASES' | grep -vE '^(information_schema|performance_schema)$')
mysqldump --all-databases | zstd --compress -9 --rsyncable -o "$OUT_FILE"
# drop dumps of databases that no longer exist
for f in "$STATE_DIRECTORY"/*.sql.zst; do
[ -e "$f" ] || continue
base="$(basename "$f")"
[ -n "''${keep[$base]:-}" ] || rm -f "$f"
# NOTE: this needs to be a hardlink for rrsync to allow sending it
rm "$STATE_DIRECTORY/mysql-dump-latest.sql.zst" ||:
ln -T "$OUT_FILE" "$STATE_DIRECTORY/mysql-dump-latest.sql.zst"
while [ "$(find "$STATE_DIRECTORY" -type f -printf '.' | wc -c)" -gt '${toString (rotations + 1)}' ]; do
rm "$(find "$STATE_DIRECTORY" -type f -printf '%T+ %p\n' | sort | head -n 1 | cut -d' ' -f2)"
done
'';
+13
View File
@@ -54,6 +54,18 @@ in
mode = "0700";
};
fileSystems.${dataDir} = lib.mkIf cfg.enable {
device = dataDir;
fsType = "none";
options = [
"bind"
"noatime"
"noauto"
"x-systemd.requires=systemd-tmpfiles-setup.service"
"x-systemd.requires=systemd-tmpfiles-resetup.service"
];
};
systemd.services.mysql = lib.mkIf cfg.enable {
after = [
"systemd-tmpfiles-setup.service"
@@ -61,6 +73,7 @@ in
];
serviceConfig = {
RequiresMountsFor = [ dataDir ];
BindPaths = [ "${dataDir}:${cfg.dataDir}" ];
LogsDirectory = "mysql";
+10 -27
View File
@@ -41,42 +41,25 @@ in
path = with pkgs; [
coreutils
diffutils
zstd
cfg.package
];
script = ''
script = let
rotations = 2;
in ''
set -euo pipefail
dump() {
local name="$1" out tmp
out="$STATE_DIRECTORY/$name.sql.zst"
tmp="$out.tmp"
shift
"$@" | zstd -9 --rsyncable -f -o "$tmp"
if cmp -s "$tmp" "$out" 2>/dev/null; then
rm -f "$tmp"
else
mv -f "$tmp" "$out"
fi
}
OUT_FILE="$STATE_DIRECTORY/postgresql-dump-$(date --iso-8601).sql.zst"
declare -A keep
dump globals pg_dumpall -U postgres --globals-only --restrict-key=backup
keep[globals.sql.zst]=1
pg_dumpall -U postgres | zstd --compress -9 --rsyncable -o "$OUT_FILE"
while IFS= read -r db; do
[ -n "$db" ] || continue
dump "$db" pg_dump -U postgres -C -d "$db" --restrict-key=backup
keep["$db.sql.zst"]=1
done < <(psql -U postgres -tAc "SELECT datname FROM pg_database WHERE datallowconn ORDER BY datname")
# NOTE: this needs to be a hardlink for rrsync to allow sending it
rm "$STATE_DIRECTORY/postgresql-dump-latest.sql.zst" ||:
ln -T "$OUT_FILE" "$STATE_DIRECTORY/postgresql-dump-latest.sql.zst"
# drop dumps of databases that no longer exist
for f in "$STATE_DIRECTORY"/*.sql.zst; do
[ -e "$f" ] || continue
base="$(basename "$f")"
[ -n "''${keep[$base]:-}" ] || rm -f "$f"
while [ "$(find "$STATE_DIRECTORY" -type f -printf '.' | wc -c)" -gt '${toString (rotations + 1)}' ]; do
rm "$(find "$STATE_DIRECTORY" -type f -printf '%T+ %p\n' | sort | head -n 1 | cut -d' ' -f2)"
done
'';
@@ -99,6 +99,18 @@ in
mode = "0700";
};
fileSystems."/data/postgresql" = lib.mkIf cfg.enable {
device = "/data/postgresql";
fsType = "none";
options = [
"bind"
"noatime"
"noauto"
"x-systemd.requires=systemd-tmpfiles-setup.service"
"x-systemd.requires=systemd-tmpfiles-resetup.service"
];
};
systemd.services.postgresql-setup = lib.mkIf cfg.enable {
after = [
"systemd-tmpfiles-setup.service"
@@ -110,6 +122,7 @@ in
"key:/etc/certs/postgres.key"
];
RequiresMountsFor = [ "/data/postgresql" ];
BindPaths = [ "/data/postgresql:/var/lib/postgresql" ];
};
};
@@ -125,6 +138,7 @@ in
"key:/etc/certs/postgres.key"
];
RequiresMountsFor = [ "/data/postgresql" ];
BindPaths = [ "/data/postgresql:/var/lib/postgresql" ];
};
};