4 ms·
1. Register an Amazon AWS S3 account - https://aws-portal.amazon.com/gp/aws/developer/registration/index.html https://aws-portal.amazon.com/gp/aws/developer/reg
by leftnode 17y ago
1. Register an Amazon AWS S3 account - https://aws-portal.amazon.com/gp/aws/developer/registration/index.html https://aws-portal.amazon.com/gp/aws/developer/registration/...
2. Download my S3 backup script (or anyone's S3 Backup script) - http://github.com/leftnode/S3-Backup http://github.com/leftnode/S3-Backup
3. Set up a cron to push hourly/daily/whatever tar's of your vhost's directory to S3.
Spend, like, $10 a month. Thats 30gb of storage, 30gb up and 30gb down. Now, I know that may not be a lot, but I doubt codinghorror.com had that much data.
- PStamatiou 17y agoI do the same thing, with a script using ruby s3sync I wrote a while ago (that I should probably update): http://paulstamatiou.com/how-to-bulletproof-server-backups-with-amazon-s3 http://paulstamatiou.com/how-to-bulletproof-server-backups-w...
- kalid 17y agoJust wanted to say thanks for the article -- I'm using your script for my blog :).
- ryanwaggoner 17y agoI'm using your script (plus zipline and automysqlbackup) on several blogs. Thanks! In case anyone else is interested: http://code.google.com/p/ziplinebackup/ http://code.google.com/p/ziplinebackup/ https://sourceforge.net/projects/automysqlbackup/ https://sourceforge.net/projects/automysqlbackup/
- Legion 17y agos3sync is great. I'm using it for automated backups for a number of work projects. Thank you for writing it and sharing it.
- PStamatiou 17y agoOops I should clarify: "script using ruby s3sync I wrote a while ago" I wrote a bash script that uses s3sync (not written by me). You can thank the s3sync community for that! :-) http://s3sync.net/wiki http://s3sync.net/wiki
- gfodor 17y agoThanks for s3sync!
- agb 17y agoIf you push your backups, make sure the account used does not have permissions to modify or delete the files it is creating offsite.
- duskwuff 17y agoYes, this! Push backups are inherently risky -- if at all possible, backups should either be pulled by the target, or should be mediated by a third system. Otherwise, you risk an attacker deleting all your backups along with your data.
- mechanical_fish 17y agoThere's also tarsnap, run by HN's very own cperciva.
- jrockway 17y agoAnd Duplicity, which cperciva claims is theoretically less secure, but which seems to work pretty well for me. (Who cares if the NSA can decrypt my blog backups? They are already available unencrypted...)
- cperciva 17y agoWho cares if the NSA can decrypt my blog backups Confidentiality is only one aspect of security. Authenticity is also important in some cases: You might care if the NSA edits your backups so that after restoring them it looks like you said something you didn't really say.
- carbon8 17y agoI recently moved some servers over to this for encrypted daily s3 backups: http://github.com/astrails/safe http://github.com/astrails/safe Dead simple to specify what to backup, drop the config in /etc/safe and add a cron job.
- mrduncan 17y agoStep 4, most importantly, should be to verify those backups on a regular basis. All too often, people lose data due to a failure and then a backup which was failing or corrupted.
- bprater 17y agoThanks for the tip. I've been doing the same thing Atwood has been doing. So I just installed your stuff and have it running. A tip for folks using leftnode's setup: I didn't notice $gpgRecipient hidden at the end of the config file and chased around a bit looking for it.
- leftnode 17y agoThanks for using it! I use it to backup all of my databases and entire vhosts directory every hour and night. Let me know if you find any bugs!
- jhancock 17y agogood outline. An alternative, which I use, is tarsnap http://www.tarsnap.com/ http://www.tarsnap.com/.