Repository navigation
Expand file tree
/
Copy pathmigrate.sh
More file actions
executable file
·54 lines (45 loc) · 1.53 KB
/
Copy pathmigrate.sh
File metadata and controls
executable file
·54 lines (45 loc) · 1.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
#!/bin/bash
set -eo pipefail
VAULT="/var/db/sudo-secretspec"
ENV_FILE="$VAULT/.env"
DB_FILE="$VAULT/secrets.db"
if [ "$1" == "--rollback" ]; then
echo "Rolling back migration..."
if [ -f "$DB_FILE.bak" ]; then
mv "$DB_FILE.bak" "$DB_FILE"
chown _sudo_secretspec:_sudo_secretspec "$DB_FILE"
echo "Rollback complete!"
else
echo "No backup found to roll back to!"
fi
exit 0
fi
if [ ! -f "$ENV_FILE" ]; then
echo "Error: $ENV_FILE does not exist. Are you running with sudo?"
exit 1
fi
echo "Starting migration from .env to SQLite secrets.db..."
if [ -f "$DB_FILE" ]; then
echo "Backing up existing secrets.db to secrets.db.bak..."
cp -p "$DB_FILE" "$DB_FILE.bak"
fi
count=0
while IFS='=' read -r key value || [ -n "$key" ]; do
if [[ -z "$key" || "$key" == \#* ]]; then
continue
fi
# Strip quotes if present
value="${value%\"}"
value="${value#\"}"
value="${value%\'}"
value="${value#\'}"
echo "Migrating $key..."
# The CLI takes the value from stdin
if ! echo -n "$value" | sudo-secretspec set "$key" --reason "Migrate from dotenv"; then
echo "Secret $key not found in declarations. Adding it..."
sudo-secretspec add "$key" --description "Migrated from dotenv" --reason "Migrate from dotenv"
echo -n "$value" | sudo-secretspec set "$key" --reason "Migrate from dotenv"
fi
count=$((count+1))
done < "$ENV_FILE"
echo "Migration successful ($count secrets migrated). Run this script with --rollback to undo."