3 ms·
I've occasionally wondered what the best way to secure your backup host from the individual clients, and possibly clients from a compromised backup host would b
by shabble 8y ago
I've occasionally wondered what the best way to secure your backup host from the individual clients, and possibly clients from a compromised backup host would be.
The most promising option I've come across so far is Borg running in append-only mode[1] with a client-push type model.
I imagine it wouldn't help in this case, if the attacker has the creds and access to run `dd' on the backup machine directly.
Anyone had any good/bad experiences with Borg append-only (or have other suggestions?)
[1] https://borgbackup.readthedocs.io/en/stable/usage/notes.html#append-only-mode https://borgbackup.readthedocs.io/en/stable/usage/notes.html...
- megous 8y agoWhat about backup server being a client? That should do it.
- shabble 8y agoas in, the backup host connects to the target machines and pulls them back to itself? Biggest concern I have with that is that to get around file permissions, the backup user needs to be effectively root. It's much more of a problem is the backup server gets compromised and now they also have root level creds to every target machine. I'm not sure if something like apparmor or selinux could allow for some sort of 'read-only root' type user, and if that would actually be safe in teh circumstances.
- ars 8y agoIt only needs root read not write. There are a number of ways to do this, including a backup client that only sends data but doesn't write, a read only bind remount, or an lvm read only snapshot. The last one is best I think. Make the new lv device readable to the backup user and have it mount it, then copy the data.
- _muff1nman_ 8y agoI personally like the model of burp[1]. The clients can be configured to not have delete or even restore access to their backups and the backup server is responsible for rotating backups. [1] https://burp.grke.org/ https://burp.grke.org/
- m3nu 8y agoThis was the main reason why I built BorgBase[1] to host backups: You can set individual SSH keys to append-only. Then this setting can be protected by 2FA. This should give good protection against such cases. Many other providers still allow SFTP access, which makes append-only mode useless. 1: https://www.borgbase.com/ https://www.borgbase.com/