Make backup pruning fully automatic, no prompt

The safety net (only ever touches disposable *.backup.* files, never
the newest one for any given file) makes this low-stakes enough to
just set up unprompted, the same way tab completion already is —
matches the user's own read on it. Still fully idempotent (skipped if
the timer already exists), so a rerun doesn't re-ask or redo anything.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H4k6J1qXXyYxhGEgnJaMvn
This commit is contained in:
Claude
2026-08-11 04:56:43 +00:00
parent c50704e1b3
commit 3584ad6499
2 changed files with 13 additions and 12 deletions
+7 -4
View File
@@ -322,10 +322,13 @@ docker compose down # stop
Every service in this repo backs up a live config before overwriting it —
`Caddyfile.backup.<timestamp>`, `/etc/fstab.backup.<timestamp>`, and so on —
but nothing cleans those up afterward, so they build up on any box
reconfigured regularly. `base` offers a daily systemd timer
(`prune-old-backups`) that removes anything older than 30 days, always
keeping at least the single newest backup per file regardless of age — a
box left alone for months never ends up with zero backups for something.
reconfigured regularly. `base` sets up a daily systemd timer
(`prune-old-backups`), automatically and without asking (the same way it
sets up [tab completion](#tab-completion) — low-stakes enough not to need
a prompt, and idempotent either way), that removes anything older than 30
days, always keeping at least the single newest backup per file regardless
of age — a box left alone for months never ends up with zero backups for
something.
```bash
sudo bash tools/prune-old-backups.sh [KEEP_DAYS] # run by hand, default 30
+6 -8
View File
@@ -23,7 +23,7 @@ install_base() {
echo "[DRY-RUN] Would offer CrowdSec intrusion prevention install (full repo only)"
echo "[DRY-RUN] Would offer to add SSH Host aliases to ~/.ssh/config"
echo "[DRY-RUN] Would add setup.sh tab completion to ~/.bashrc (if not already there)"
echo "[DRY-RUN] Would offer daily pruning of old *.backup.* config files (systemd timer)"
echo "[DRY-RUN] Would set up daily pruning of old *.backup.* config files (systemd timer, if not already there)"
return 0
fi
@@ -120,9 +120,12 @@ _base_setup_tab_completion() {
# Every service in this repo backs up a live config before overwriting it
# (Caddyfile, /etc/fstab, ...) but none of them ever clean those up
# afterward — see tools/prune-old-backups.sh's own header for the full
# reasoning. Offers a daily systemd timer that prunes anything older than
# reasoning. Sets up a daily systemd timer that prunes anything older than
# 30 days, always keeping at least the single newest backup per file
# regardless of age.
# regardless of age. No prompt — same reasoning as _base_setup_tab_completion
# right above: idempotent, and the safety net (only ever touches disposable
# *.backup.* files, never the newest one for anything) makes this low-stakes
# enough not to ask about, the same way that one doesn't.
_base_setup_backup_pruning() {
command -v systemctl >/dev/null 2>&1 || return 0
systemctl list-unit-files prune-old-backups.timer --no-legend 2>/dev/null | grep -q . && return 0
@@ -130,11 +133,6 @@ _base_setup_backup_pruning() {
local prune_script="$HERE/tools/prune-old-backups.sh"
[ -f "$prune_script" ] || return 0
echo ""
local ENABLE_PRUNE=""
prompt_yn "Automatically prune old config backups (Caddyfile.backup.*, fstab.backup.*, etc — keeps 30 days, always keeps at least the newest one)? (y/n):" "y" ENABLE_PRUNE
[[ "$ENABLE_PRUNE" =~ ^[Yy]$ ]] || return 0
cat > /etc/systemd/system/prune-old-backups.service << UNIT
[Unit]
Description=Prune old *.backup.* config backups (Caddyfile, fstab, etc)