This repository has been archived on 2026-08-17. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
beatzaplenty a6a419bad7
Secret Scan / Scan for secrets and sensitive config (push) Failing after 4s
updated structure
2026-07-24 06:22:31 +10:00

52 lines
2.1 KiB
Bash
Executable File

#!/usr/bin/env bash
# Pull Pi-hole configuration from a running instance to a local directory.
# Sensitive fields (password hashes, TOTP secrets) are redacted automatically.
#
# Usage: pull-config.sh <source-host> <dest-dir>
# source-host SSH-reachable hostname or IP of the source Pi-hole
# dest-dir Local directory to write config into (created if absent)
#
# Example:
# ./pull-config.sh root@pihole ./config
# ./pull-config.sh root@192.168.2.253 /backup/pihole-$(date +%Y%m%d)
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
usage() {
echo "Usage: $(basename "$0") <source-host> <dest-dir>" >&2
echo " source-host SSH target for the source Pi-hole (e.g. root@pihole)" >&2
echo " dest-dir Local directory to write config files into" >&2
exit 1
}
[[ $# -eq 2 ]] || usage
SOURCE="$1"
DEST="$2"
echo "Pulling Pi-hole config from ${SOURCE}${DEST}"
mkdir -p "${DEST}/dnsmasq.d"
# ── pihole.toml ────────────────────────────────────────────────────────────────
echo " pihole.toml"
ssh "${SOURCE}" "cat /etc/pihole/pihole.toml" > "${DEST}/pihole.toml"
"${SCRIPT_DIR}/sanitize-config.sh" "${DEST}/pihole.toml"
# ── custom dnsmasq drop-ins ────────────────────────────────────────────────────
# Pi-hole manages its own generated config; we only capture user-added files.
echo " dnsmasq.d/ (custom drop-ins)"
ssh "${SOURCE}" "ls /etc/dnsmasq.d/*.conf 2>/dev/null || true" | while read -r f; do
name="$(basename "$f")"
echo " ${name}"
ssh "${SOURCE}" "cat '${f}'" > "${DEST}/dnsmasq.d/${name}"
done
# ── DHCP static leases ─────────────────────────────────────────────────────────
echo " dhcp.leases"
ssh "${SOURCE}" "cat /etc/pihole/dhcp.leases 2>/dev/null || true" > "${DEST}/dhcp.leases"
echo "Done. Config written to ${DEST}/"