3 ms·
as in, the backup host connects to the target machines and pulls them back to itself? Biggest concern I have with that is that to get around file permissions,
by shabble 8y ago
as in, the backup host connects to the target machines and pulls them back to itself?
Biggest concern I have with that is that to get around file permissions, the backup user needs to be effectively root.
It's much more of a problem is the backup server gets compromised and now they also have root level creds to every target machine.
I'm not sure if something like apparmor or selinux could allow for some sort of 'read-only root' type user, and if that would actually be safe in teh circumstances.
- ars 8y agoIt only needs root read not write. There are a number of ways to do this, including a backup client that only sends data but doesn't write, a read only bind remount, or an lvm read only snapshot. The last one is best I think. Make the new lv device readable to the backup user and have it mount it, then copy the data.