Collection of operational skills for VaultMesh infrastructure including: - backup-sovereign: Backup and recovery operations - btc-anchor: Bitcoin anchoring - cloudflare-tunnel-manager: Cloudflare tunnel management - container-registry: Container registry operations - disaster-recovery: Disaster recovery procedures - dns-sovereign: DNS management - eth-anchor: Ethereum anchoring - gitea-bootstrap: Gitea setup and configuration - hetzner-bootstrap: Hetzner server provisioning - merkle-forest: Merkle tree operations - node-hardening: Node security hardening - operator-bootstrap: Operator initialization - proof-verifier: Cryptographic proof verification - rfc3161-anchor: RFC3161 timestamping - secrets-vault: Secrets management 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
55 lines
1.5 KiB
Bash
55 lines
1.5 KiB
Bash
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
log_info(){ echo "[INFO] $(date -Iseconds) $*"; }
|
|
log_warn(){ echo "[WARN] $(date -Iseconds) $*" >&2; }
|
|
log_error(){ echo "[ERROR] $(date -Iseconds) $*" >&2; }
|
|
die(){ log_error "$*"; exit 1; }
|
|
need(){ command -v "$1" >/dev/null 2>&1 || die "Missing required tool: $1"; }
|
|
|
|
confirm_gate() {
|
|
: "${DRY_RUN:=1}"
|
|
: "${REQUIRE_CONFIRM:=1}"
|
|
: "${CONFIRM_PHRASE:=I UNDERSTAND THIS WILL SEND AN ETH TRANSACTION}"
|
|
[[ "$DRY_RUN" == "0" ]] || die "DRY_RUN=$DRY_RUN (set DRY_RUN=0)."
|
|
if [[ "$REQUIRE_CONFIRM" == "1" ]]; then
|
|
echo "Type to confirm:"
|
|
echo " $CONFIRM_PHRASE"
|
|
read -r input
|
|
[[ "$input" == "$CONFIRM_PHRASE" ]] || die "Confirmation phrase mismatch."
|
|
fi
|
|
}
|
|
|
|
json_escape() {
|
|
local s="$1"
|
|
s="${s//\\/\\\\}"; s="${s//\"/\\\"}"; s="${s//$'\n'/\\n}"
|
|
printf "%s" "$s"
|
|
}
|
|
|
|
read_root_hex() {
|
|
# precedence: ROOT_HEX, else parse ROOT_FILE
|
|
: "${ROOT_HEX:=}"
|
|
: "${ROOT_FILE:=}"
|
|
if [[ -n "$ROOT_HEX" ]]; then
|
|
echo "$ROOT_HEX"
|
|
return 0
|
|
fi
|
|
[[ -n "$ROOT_FILE" ]] || die "Set ROOT_HEX or ROOT_FILE."
|
|
[[ -f "$ROOT_FILE" ]] || die "ROOT_FILE not found: $ROOT_FILE"
|
|
local rh
|
|
rh="$(grep '^root_hex=' "$ROOT_FILE" | head -n1 | cut -d= -f2)"
|
|
[[ -n "$rh" ]] || die "Could not parse root_hex from ROOT_FILE."
|
|
echo "$rh"
|
|
}
|
|
|
|
pad_to_32_bytes_hex() {
|
|
# expects hex without 0x
|
|
local h="$1"
|
|
h="${h#0x}"
|
|
# limit to 64, pad right with zeros if shorter (simple deterministic padding)
|
|
if [[ ${#h} -gt 64 ]]; then
|
|
echo "${h:0:64}"
|
|
else
|
|
printf "%-64s" "$h" | tr ' ' '0'
|
|
fi
|
|
}
|