Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
d25d0f8b56
|
|||
|
4525de1d10
|
|||
|
9a837d210d
|
|||
|
d3c9fabbc2
|
|||
|
950b163869
|
@@ -1,4 +1,22 @@
|
|||||||
{ ... }:
|
{ config, pkgs, lib, ... }:
|
||||||
|
let
|
||||||
|
cfg = config.services.irqbalance;
|
||||||
|
in
|
||||||
{
|
{
|
||||||
services.irqbalance.enable = true;
|
services.irqbalance.enable = true;
|
||||||
}
|
|
||||||
|
# irqbalance only has meaningful work to do on multi-socket machines, so
|
||||||
|
# skip starting it pointlessly everywhere else.
|
||||||
|
systemd.services.irqbalance.serviceConfig.ExecCondition = let
|
||||||
|
isMultiSocket = pkgs.writeShellApplication {
|
||||||
|
name = "irqbalance-is-multi-socket";
|
||||||
|
runtimeInputs = [ pkgs.coreutils ];
|
||||||
|
text = ''
|
||||||
|
sockets=$(cat /sys/devices/system/cpu/cpu*/topology/physical_package_id | sort -u | wc -l)
|
||||||
|
[ "$sockets" -gt 1 ]
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
in lib.mkIf cfg.enable [
|
||||||
|
(lib.getExe isMultiSocket)
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|||||||
@@ -41,24 +41,38 @@ in
|
|||||||
path = with pkgs; [
|
path = with pkgs; [
|
||||||
cfg.package
|
cfg.package
|
||||||
coreutils
|
coreutils
|
||||||
|
diffutils
|
||||||
zstd
|
zstd
|
||||||
];
|
];
|
||||||
|
|
||||||
script = let
|
script = ''
|
||||||
rotations = 2;
|
|
||||||
in ''
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
OUT_FILE="$STATE_DIRECTORY/mysql-dump-$(date --iso-8601).sql.zst"
|
dump() {
|
||||||
|
local name="$1" out tmp
|
||||||
|
out="$STATE_DIRECTORY/$name.sql.zst"
|
||||||
|
tmp="$out.tmp"
|
||||||
|
shift
|
||||||
|
"$@" | zstd -9 --rsyncable -f -o "$tmp"
|
||||||
|
if cmp -s "$tmp" "$out" 2>/dev/null; then
|
||||||
|
rm -f "$tmp"
|
||||||
|
else
|
||||||
|
mv -f "$tmp" "$out"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
mysqldump --all-databases | zstd --compress -9 --rsyncable -o "$OUT_FILE"
|
declare -A keep
|
||||||
|
while IFS= read -r db; do
|
||||||
|
[ -n "$db" ] || continue
|
||||||
|
dump "$db" mysqldump --skip-dump-date --databases "$db"
|
||||||
|
keep["$db.sql.zst"]=1
|
||||||
|
done < <(mysql -N -e 'SHOW DATABASES' | grep -vE '^(information_schema|performance_schema)$')
|
||||||
|
|
||||||
# NOTE: this needs to be a hardlink for rrsync to allow sending it
|
# drop dumps of databases that no longer exist
|
||||||
rm "$STATE_DIRECTORY/mysql-dump-latest.sql.zst" ||:
|
for f in "$STATE_DIRECTORY"/*.sql.zst; do
|
||||||
ln -T "$OUT_FILE" "$STATE_DIRECTORY/mysql-dump-latest.sql.zst"
|
[ -e "$f" ] || continue
|
||||||
|
base="$(basename "$f")"
|
||||||
while [ "$(find "$STATE_DIRECTORY" -type f -printf '.' | wc -c)" -gt '${toString (rotations + 1)}' ]; do
|
[ -n "''${keep[$base]:-}" ] || rm -f "$f"
|
||||||
rm "$(find "$STATE_DIRECTORY" -type f -printf '%T+ %p\n' | sort | head -n 1 | cut -d' ' -f2)"
|
|
||||||
done
|
done
|
||||||
'';
|
'';
|
||||||
|
|
||||||
|
|||||||
@@ -41,25 +41,42 @@ in
|
|||||||
|
|
||||||
path = with pkgs; [
|
path = with pkgs; [
|
||||||
coreutils
|
coreutils
|
||||||
|
diffutils
|
||||||
zstd
|
zstd
|
||||||
cfg.package
|
cfg.package
|
||||||
];
|
];
|
||||||
|
|
||||||
script = let
|
script = ''
|
||||||
rotations = 2;
|
|
||||||
in ''
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
OUT_FILE="$STATE_DIRECTORY/postgresql-dump-$(date --iso-8601).sql.zst"
|
dump() {
|
||||||
|
local name="$1" out tmp
|
||||||
|
out="$STATE_DIRECTORY/$name.sql.zst"
|
||||||
|
tmp="$out.tmp"
|
||||||
|
shift
|
||||||
|
"$@" | zstd -9 --rsyncable -f -o "$tmp"
|
||||||
|
if cmp -s "$tmp" "$out" 2>/dev/null; then
|
||||||
|
rm -f "$tmp"
|
||||||
|
else
|
||||||
|
mv -f "$tmp" "$out"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
pg_dumpall -U postgres | zstd --compress -9 --rsyncable -o "$OUT_FILE"
|
declare -A keep
|
||||||
|
dump globals pg_dumpall -U postgres --globals-only --restrict-key=backup
|
||||||
|
keep[globals.sql.zst]=1
|
||||||
|
|
||||||
# NOTE: this needs to be a hardlink for rrsync to allow sending it
|
while IFS= read -r db; do
|
||||||
rm "$STATE_DIRECTORY/postgresql-dump-latest.sql.zst" ||:
|
[ -n "$db" ] || continue
|
||||||
ln -T "$OUT_FILE" "$STATE_DIRECTORY/postgresql-dump-latest.sql.zst"
|
dump "$db" pg_dump -U postgres -C -d "$db" --restrict-key=backup
|
||||||
|
keep["$db.sql.zst"]=1
|
||||||
|
done < <(psql -U postgres -tAc "SELECT datname FROM pg_database WHERE datallowconn ORDER BY datname")
|
||||||
|
|
||||||
while [ "$(find "$STATE_DIRECTORY" -type f -printf '.' | wc -c)" -gt '${toString (rotations + 1)}' ]; do
|
# drop dumps of databases that no longer exist
|
||||||
rm "$(find "$STATE_DIRECTORY" -type f -printf '%T+ %p\n' | sort | head -n 1 | cut -d' ' -f2)"
|
for f in "$STATE_DIRECTORY"/*.sql.zst; do
|
||||||
|
[ -e "$f" ] || continue
|
||||||
|
base="$(basename "$f")"
|
||||||
|
[ -n "''${keep[$base]:-}" ] || rm -f "$f"
|
||||||
done
|
done
|
||||||
'';
|
'';
|
||||||
|
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ in
|
|||||||
extensions = ps: with ps; [ pg_repack ];
|
extensions = ps: with ps; [ pg_repack ];
|
||||||
enableTCPIP = true;
|
enableTCPIP = true;
|
||||||
|
|
||||||
|
# NOTE: md5 accepts both md5 and scram-sha-256
|
||||||
authentication = ''
|
authentication = ''
|
||||||
host all all ${values.ipv4-space} md5
|
host all all ${values.ipv4-space} md5
|
||||||
host all all ${values.ipv6-space} md5
|
host all all ${values.ipv6-space} md5
|
||||||
@@ -76,6 +77,15 @@ in
|
|||||||
maintenance_io_concurrency = 100;
|
maintenance_io_concurrency = 100;
|
||||||
wal_recycle = true;
|
wal_recycle = true;
|
||||||
|
|
||||||
|
# -------------------------------- #
|
||||||
|
|
||||||
|
# Authentication
|
||||||
|
password_encryption = "scram-sha-256";
|
||||||
|
|
||||||
|
# Logging
|
||||||
|
log_connections = "authorization";
|
||||||
|
log_disconnections = true;
|
||||||
|
|
||||||
# SSL
|
# SSL
|
||||||
ssl = true;
|
ssl = true;
|
||||||
ssl_cert_file = "/run/credentials/postgresql.service/cert";
|
ssl_cert_file = "/run/credentials/postgresql.service/cert";
|
||||||
|
|||||||
Reference in New Issue
Block a user