OpenShift环境下,如何在Shell脚本中为restic传递仓库密码
问题描述
我通过以下命令登录OpenShift的Pod:
oc exec example-nxcpj -- bash oc exec example-nxcpj --it -- bash
手动执行restic命令列出仓库锁时,需要输入仓库密码:
restic list locks -r s3:https://s3.****amazonaws.com***/zen46 enter password for repository:
我写了如下Shell脚本,想动态传递密码:
oc exec example-nxcpj -- bash -c 'for i in /var/lib/; do export AWS_ACCESS_KEY_ID=*********; export AWS_SECRET_ACCESS_KEY=********; restic list locks -r s3:https://*****amazonaws.com****zen46; done'
但执行时报错:
Fatal: an empty password is not a password reading repository password from stdin command terminated with exit code 1
请问如何修改脚本实现动态传递密码?
解决方案
Restic支持多种方式传递仓库密码,以下是几种适配你场景的修改方案:
1. 使用环境变量RESTIC_PASSWORD
直接在脚本里导出仓库密码的环境变量,restic会自动读取这个变量的值作为密码:
oc exec example-nxcpj -- bash -c 'for i in /var/lib/; do export AWS_ACCESS_KEY_ID=*********; export AWS_SECRET_ACCESS_KEY=********; export RESTIC_PASSWORD="你的仓库密码"; restic list locks -r s3:https://*****amazonaws.com****zen46; done'
2. 通过管道传递密码
如果不想用环境变量,可以用echo管道把密码传给restic的标准输入:
oc exec example-nxcpj -- bash -c 'for i in /var/lib/; do export AWS_ACCESS_KEY_ID=*********; export AWS_SECRET_ACCESS_KEY=********; echo "你的仓库密码" | restic list locks -r s3:https://*****amazonaws.com****zen46; done'
3. 使用--password-file参数(推荐用于安全场景)
如果Pod内可以存放密码文件,或者能通过其他方式挂载密码文件,可使用该参数:
先在Pod内创建密码文件(比如/tmp/restic-pass),然后修改脚本:
oc exec example-nxcpj -- bash -c 'for i in /var/lib/; do export AWS_ACCESS_KEY_ID=*********; export AWS_SECRET_ACCESS_KEY=********; restic list locks -r s3:https://*****amazonaws.com****zen46 --password-file /tmp/restic-pass; done'
如果需要在脚本中动态生成密码文件,也可以临时写入后删除:
oc exec example-nxcpj -- bash -c 'for i in /var/lib/; do export AWS_ACCESS_KEY_ID=*********; export AWS_SECRET_ACCESS_KEY=********; echo "你的仓库密码" > /tmp/restic-pass-tmp; restic list locks -r s3:https://*****amazonaws.com****zen46 --password-file /tmp/restic-pass-tmp; rm /tmp/restic-pass-tmp; done'
内容的提问来源于stack exchange,提问作者Navaratnam
相关产品推荐
相关产品推荐

