Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #178680 > unrolled thread
| Started by | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| First post | 2017-03-11 16:20 +0100 |
| Last post | 2017-03-19 11:40 +0100 |
| Articles | 20 on this page of 45 — 18 participants |
Back to article view | Back to linux.debian.user
Guide(s?) to backup philosophies Richard Owlett <rowlett@cloud85.net> - 2017-03-11 16:20 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-11 22:10 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-13 14:00 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-14 05:00 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-17 11:50 +0100
Re: Guide(s?) to backup philosophies Glenn English <ghe2001@gmail.com> - 2017-03-17 19:50 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-18 06:20 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-22 11:50 +0100
Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-22 11:50 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-22 13:20 +0100
Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-22 13:30 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 10:30 +0100
Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-23 11:10 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 13:10 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-23 04:00 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 10:40 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-23 20:10 +0100
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 14:10 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 23:20 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Nathan Dorfman <ndorf@rtfm.net> - 2017-04-01 11:00 +0200
should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) cbannister@slingshot.co.nz - 2017-03-31 14:10 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) <tomas@tuxteam.de> - 2017-03-31 14:20 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Brian <ad44@cityscape.co.uk> - 2017-03-31 15:20 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) <tomas@tuxteam.de> - 2017-03-31 15:30 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 15:30 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 15:50 +0200
Re: Guide(s?) to backup philosophies Glenn English <ghe2001@gmail.com> - 2017-03-14 19:00 +0100
Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-14 19:20 +0100
Re: Guide(s?) to backup philosophies Miles Fidelman <mfidelman@meetinghouse.net> - 2017-03-14 20:20 +0100
Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-14 21:40 +0100
Re: Guide(s?) to backup philosophies Stefan Monnier <monnier@iro.umontreal.ca> - 2017-03-15 13:30 +0100
Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-15 14:10 +0100
Re: Guide(s?) to backup philosophies "Martin McCormick" <martin.m@suddenlink.net> - 2017-03-15 14:30 +0100
Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 16:40 +0100
Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 16:40 +0100
Re: Guide(s?) to backup philosophies Stefan Monnier <monnier@iro.umontreal.ca> - 2017-03-15 21:50 +0100
Re: Guide(s?) to backup philosophies songbird <songbird@anthive.com> - 2017-03-16 23:50 +0100
Re: Guide(s?) to backup philosophies Miles Fidelman <mfidelman@meetinghouse.net> - 2017-03-14 20:10 +0100
Re: Guide(s?) to backup philosophies Joe <joe@jretrading.com> - 2017-03-11 23:30 +0100
Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 13:30 +0100
Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-13 15:20 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-14 05:10 +0100
Re: Guide(s?) to backup philosophies Richard Owlett <rowlett@cloud85.net> - 2017-03-14 15:50 +0100
Re: Guide(s?) to backup philosophies Merlin Büge <toni@bluenox07.de> - 2017-03-14 19:50 +0100
Re: Guide(s?) to backup philosophies DdB <debianlist@potentially-spam.de-bruyn.de> - 2017-03-19 11:40 +0100
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
| From | cbannister@slingshot.co.nz |
|---|---|
| Date | 2017-03-31 14:10 +0200 |
| Subject | should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <tr3xn-4rg-3@gated-at.bofh.it> |
| In reply to | #178810 |
On Mon, Mar 13, 2017 at 08:58:15PM -0700, David Christensen wrote: > On 03/13/2017 05:38 AM, Dan Purgert wrote: > >Currently, the system here is > > > > - every PC has a cronjob backing up $HOME to a central "server" (read - > > repurposed PC with decent WD drives), just an rsync script that runs > > daily. > > Don't forget security: > > 1. With a "push" arrangement (e.g. each workstation backs up itself to the > server) -- if a workstation gets compromised, the backups are at risk. > > 2. With a "pull" arrangement (e.g. the server backs up all the > workstations) -- if a workstation gets compromised, the backups should be > safe (and might have clues about the intrusion). Additionally, the backup > server can be completely firewalled (e.g. no open ports). My understanding is that if there are no services listening on a port then it cannot be accessed. e.g. http://serverfault.com/questions/733633/if-no-service-is-listening-on-a-port-can-a-system-still-be-accessed-using-that-p An I missing something? -- The media's the most powerful entity on earth. They have the power to make the innocent guilty and to make the guilty innocent, and that's power. -- Malcolm X
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-03-31 14:20 +0200 |
| Subject | Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <tr3H4-4uB-15@gated-at.bofh.it> |
| In reply to | #179634 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, Apr 01, 2017 at 01:00:45AM +1300, cbannister@slingshot.co.nz wrote: [...] > My understanding is that if there are no services listening on a port then > it cannot be accessed. > > e.g. > > http://serverfault.com/questions/733633/if-no-service-is-listening-on-a-port-can-a-system-still-be-accessed-using-that-p > > An I missing something? As Dominik said: it's "defense in depth". If your PHP^H^H^H web application has some code injection issue, your adversary might well install a C&C server listening on that port, and work from there on (exfiltrate data, try some privelege escalation, whatever). Now there might be other avenues for that, but security is about closing the avenue your adversary is going to use next ;-) regards - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEUEARECAAYFAljeSPwACgkQBcgs9XrR2kZccACSAtp4XjR4TifCMA1+Ip/j+oM0 wQCfe9snMu/5hvDCXb+5joez/4iPDQ4= =5oco -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-03-31 15:20 +0200 |
| Subject | Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <tr4D8-56f-11@gated-at.bofh.it> |
| In reply to | #179635 |
On Fri 31 Mar 2017 at 14:18:04 +0200, tomas@tuxteam.de wrote: > On Sat, Apr 01, 2017 at 01:00:45AM +1300, cbannister@slingshot.co.nz wrote: > > [...] > > > My understanding is that if there are no services listening on a port then > > it cannot be accessed. > > > > e.g. > > > > http://serverfault.com/questions/733633/if-no-service-is-listening-on-a-port-can-a-system-still-be-accessed-using-that-p > > > > An I missing something? I rather thought cbannister had the correct idea: nothing listening; therefore no access. > As Dominik said: it's "defense in depth". If your PHP^H^H^H web application > has some code injection issue, your adversary might well install a C&C > server listening on that port, and work from there on (exfiltrate data, > try some privelege escalation, whatever). > > Now there might be other avenues for that, but security is about closing > the avenue your adversary is going to use next ;-) If someone unauthorised is on your machine can they not just as well remove firewall rules? -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-03-31 15:30 +0200 |
| Subject | Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <tr4MO-59K-11@gated-at.bofh.it> |
| In reply to | #179637 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, Mar 31, 2017 at 02:17:35PM +0100, Brian wrote: > On Fri 31 Mar 2017 at 14:18:04 +0200, tomas@tuxteam.de wrote: > > > On Sat, Apr 01, 2017 at 01:00:45AM +1300, cbannister@slingshot.co.nz wrote: > > > > [...] > > > > > My understanding is that if there are no services listening on a port then > > > it cannot be accessed. > > > > > > e.g. > > > > > > http://serverfault.com/questions/733633/if-no-service-is-listening-on-a-port-can-a-system-still-be-accessed-using-that-p > > > > > > An I missing something? > > I rather thought cbannister had the correct idea: nothing listening; > therefore no access. > > > As Dominik said: it's "defense in depth". If your PHP^H^H^H web application > > has some code injection issue, your adversary might well install a C&C > > server listening on that port, and work from there on (exfiltrate data, > > try some privelege escalation, whatever). > > > > Now there might be other avenues for that, but security is about closing > > the avenue your adversary is going to use next ;-) > > If someone unauthorised is on your machine can they not just as well > remove firewall rules? If they have done the privilege escalation bit, then yes. If they are "just" running as the web server user (which hopefully ain't root) then "not... yet". Unless you've set up sudo so that www-user can change the firewall rules. But then you'd have to tell us more about that ;-D Regards - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAljeWP0ACgkQBcgs9XrR2kb4OACfSM1gZZ6Ac2OlSHEBaGfEuM+p EmMAn1kpsOY5vTMQQ3ou2hPRwsBAp72b =s6iO -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Dominik George <nik@naturalnet.de> |
|---|---|
| Date | 2017-03-31 15:30 +0200 |
| Subject | Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <tr4MO-59K-25@gated-at.bofh.it> |
| In reply to | #179637 |
>If someone unauthorised is on your machine can they not just as well >remove firewall rules? Well, not without getting root first. And making something listen that spawns a shell usable to gain further access is a big win. Keeping uploading PHP code to some vulnerable webserver will at some point be noticed. Uploading something spawning a shell once probably not. -nik
[toc] | [prev] | [next] | [standalone]
| From | Dominik George <nik@naturalnet.de> |
|---|---|
| Date | 2017-03-31 15:50 +0200 |
| Subject | Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <tr569-5gO-7@gated-at.bofh.it> |
| In reply to | #179639 |
>Well, not without getting root first. > >And making something listen that spawns a shell usable to gain further >access is a big win. Keeping uploading PHP code to some vulnerable >webserver will at some point be noticed. Uploading something spawning a >shell once probably not. > When $someone hacked $somebigamericanwebhoster some years ago, $they first found a CMS that allowed online editing of its PHP code. $they were able to use that to run arbitrary shell commands. However, that thing had an edit history, so keeping passing in new code produced a well-visible log each time (in retrospective, $they could just have patched that away, but well...). Uploading and starting ajaxterm, however, cost $them only two edits, and as it went listening on its own port without a firewall logging, $they had an interactive shell that could be configured to keep no record of anything. (Not of any interest here, but $they then found a misconfigured NFS share that mapped all UIDs to root, keeping suid bits... use your imagination for the rest. But $they would not have found that without an interactive shell.) -nik
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-03-14 19:00 +0100 |
| Message-ID | <tkYTM-3Be-15@gated-at.bofh.it> |
| In reply to | #178755 |
On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote: > David Christensen wrote: >> On 03/11/2017 07:10 AM, Richard Owlett wrote: >>> I've vague ideas of what backup pattern(s) I might follow. >>> I'm looking for reading materials that might trigger "I hadn't thought >>> of that" moments. >>> >>> Suggestions? I didn't see anybody talk about incremental backup (the backup consists of current versions as well as earlier ones -- often earlier work can replace erroneous or lost current work. Or work you don't notice is gone for a few days.). There are 2 I know of, and one (and probably many more) that may do that: Apple's TimeMachine pros: TM backs up forever -- you can recover (many) things from the day it started. It backs up every few minutes without being told to. It's smart about keeping recent files and tossing pretty old ones. It's trivial to get going. cons: It backs up to a single disk. It's GUI is kind of cutesy and a bit hard to use. It's Mac only. Macs change every few minutes. But I've been using it since it came out (one of the Leopards), and it's not changed, AFAIK. Amanda pros: It backs up using tar files so it's possible (but significant trouble) to recover data when the Amanda server fails. It can be configured to use many different pieces of medium. It writes to tape or disk. I don't know if it does cloud. It backs up an entire network. It checks its output, if asked, after backup. Cron can run it at 3:00 in the morning. cons: Configuration is pretty complex and time consuming. There has to be an Amanda client on every host it's to back up. There has to be an 'Amanda buffer disk' (from the tape days). It's old -- no GUI. But it's solid as a rock. Since there's no GUI, it takes a little thought and an instruction book/man page to recover (it does me, anyway). When a file has changed, it writes the entire file, not just the changes (could be considered a pro). Backula I really don't know much about this one except that it writes using a proprietary system. Or it did last time I looked (and rejected it for that reason). I've been using Amanda with tape for over a decade. No probs. Backing up and recovering. I've never had to do a bare metal restore, though. Nor have I ever tried to recover from one of its tarballs. It's written in C, and beware, I've seen at least one goto in the source (I've seen the source because it's Debian free -- I think Backula is too). I've been on Amanda and tape from the beginning, back in the dark ages, but I suspect it'd be happy to write to a handful of large(ish) thumb drives. Another way of getting an incremental backup is to mirror an entire system every day to a different device from a collection of removable media (like thumb drives). That'd be a problem for the likes of Google or Amazon, but might work well for a small system. -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2017-03-14 19:20 +0100 |
| Message-ID | <tkZd8-43W-31@gated-at.bofh.it> |
| In reply to | #178837 |
On Tue, Mar 14, 2017 at 05:54:06PM +0000, Glenn English wrote: > On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote: > > David Christensen wrote: > >> On 03/11/2017 07:10 AM, Richard Owlett wrote: > >>> I've vague ideas of what backup pattern(s) I might follow. > >>> I'm looking for reading materials that might trigger "I hadn't thought > >>> of that" moments. > >>> > >>> Suggestions? > > I didn't see anybody talk about incremental backup (the backup > consists of current versions as well as earlier ones -- often earlier > work can replace erroneous or lost current work. Or work you don't > notice is gone for a few days.). There are 2 I know of, and one (and > probably many more) that may do that: Having been there and done that, I can assure you that having a live snapshot system -- rsnapshot or btrfs/zfs native tools -- is more fun and less work for everyone. As a bonus, they can all send snapshots to remote systems or detachable media. > It backs up to a single disk. > It's GUI is kind of cutesy and a bit hard to use. > It's Mac only. > Macs change every few minutes. But I've been using it since it came > out (one of the Leopards), and it's not changed, AFAIK. On Macs, this is the way to go. But! You don't need to back up to a single disk. You can back up to a Linux system running AppleTalk, and those volumes can sit on RAID or ZFS or whatever you want. Recommended. [Amanda] > It can be configured to use many different pieces of medium. > It writes to tape or disk. I don't know if it does cloud. You can pretend a remote server is a set of disks. I wouldn't. > I've been using Amanda with tape for over a decade. No probs. Backing > up and recovering. I've never had to do a bare metal restore, though. > Nor have I ever tried to recover from one of its tarballs. Not much fun. Especially compared to self-service or nearly self-service from snapshots. > I've been on Amanda and tape from the beginning, back in the dark > ages, but I suspect it'd be happy to write to a handful of large(ish) > thumb drives. Another way of getting an incremental backup is to > mirror an entire system every day to a different device from a > collection of removable media (like thumb drives). That'd be a problem > for the likes of Google or Amazon, but might work well for a small > system. Thumb drives are terribly unreliable, but cheapish. Treat them like tapes and never write over them, and assume that some percentage will just die. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Miles Fidelman <mfidelman@meetinghouse.net> |
|---|---|
| Date | 2017-03-14 20:20 +0100 |
| Message-ID | <tl09c-4Iz-13@gated-at.bofh.it> |
| In reply to | #178838 |
On 3/14/17 11:18 AM, Dan Ritter wrote: > On Tue, Mar 14, 2017 at 05:54:06PM +0000, Glenn English wrote: >> On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote: >>> David Christensen wrote: >>>> On 03/11/2017 07:10 AM, Richard Owlett wrote: >>>>> I've vague ideas of what backup pattern(s) I might follow. >>>>> I'm looking for reading materials that might trigger "I hadn't thought >>>>> of that" moments. >>>>> >>>>> Suggestions? >> I didn't see anybody talk about incremental backup (the backup >> consists of current versions as well as earlier ones -- often earlier >> work can replace erroneous or lost current work. Or work you don't >> notice is gone for a few days.). There are 2 I know of, and one (and >> probably many more) that may do that: > Having been there and done that, I can assure you that having a > live snapshot system -- rsnapshot or btrfs/zfs native tools -- > is more fun and less work for everyone. > Only if they do versioning. Otherwise, live snapshots mirror deletes - not very useful if you want to restore an accidental delete! Miles Fidelman -- In theory, there is no difference between theory and practice. In practice, there is. .... Yogi Berra
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2017-03-14 21:40 +0100 |
| Message-ID | <tl1oB-5wC-9@gated-at.bofh.it> |
| In reply to | #178843 |
On Tue, Mar 14, 2017 at 12:15:15PM -0700, Miles Fidelman wrote: > On 3/14/17 11:18 AM, Dan Ritter wrote: > > > On Tue, Mar 14, 2017 at 05:54:06PM +0000, Glenn English wrote: > > > On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote: > > > > David Christensen wrote: > > > > > On 03/11/2017 07:10 AM, Richard Owlett wrote: > > > > > > I've vague ideas of what backup pattern(s) I might follow. > > > > > > I'm looking for reading materials that might trigger "I hadn't thought > > > > > > of that" moments. > > > > > > > > > > > > Suggestions? > > > I didn't see anybody talk about incremental backup (the backup > > > consists of current versions as well as earlier ones -- often earlier > > > work can replace erroneous or lost current work. Or work you don't > > > notice is gone for a few days.). There are 2 I know of, and one (and > > > probably many more) that may do that: > > Having been there and done that, I can assure you that having a > > live snapshot system -- rsnapshot or btrfs/zfs native tools -- > > is more fun and less work for everyone. > > > Only if they do versioning. Otherwise, live snapshots mirror deletes - not > very useful if you want to restore an accidental delete! All of the systems I mention are versioned (dated) snapshot systems. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2017-03-15 13:30 +0100 |
| Message-ID | <tlgdY-7yR-23@gated-at.bofh.it> |
| In reply to | #178846 |
>> > Having been there and done that, I can assure you that having a
>> > live snapshot system -- rsnapshot or btrfs/zfs native tools --
>> > is more fun and less work for everyone.
I looked at rsnapshot but its behavior is poor when you have lots of
directories with lots of tiny files.
It'd probably be fairly easy to come up with a backup system based on Git
(probably not good for whole-system backups, but likely workable for
homedir backups), but I haven't come across such a thing yet.
Stefan
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2017-03-15 14:10 +0100 |
| Message-ID | <tlgQG-85t-19@gated-at.bofh.it> |
| In reply to | #178863 |
On Wed, Mar 15, 2017 at 08:01:00AM -0400, Stefan Monnier wrote: > >> > Having been there and done that, I can assure you that having a > >> > live snapshot system -- rsnapshot or btrfs/zfs native tools -- > >> > is more fun and less work for everyone. > > I looked at rsnapshot but its behavior is poor when you have lots of > directories with lots of tiny files. Its behavior is correct. The performance is poor, relative to, say, zfs snapshots and sends. rsnapshot needs to do a lot more work. > It'd probably be fairly easy to come up with a backup system based on Git > (probably not good for whole-system backups, but likely workable for > homedir backups), but I haven't come across such a thing yet. You can try etckeeper, which is packaged in Debian. The default config is aimed at /etc, but it can be aimed elsewhere.
[toc] | [prev] | [next] | [standalone]
| From | "Martin McCormick" <martin.m@suddenlink.net> |
|---|---|
| Date | 2017-03-15 14:30 +0100 |
| Message-ID | <tlha2-8dq-21@gated-at.bofh.it> |
| In reply to | #178867 |
Dan Ritter <dsr@randomstring.org> writes regarding rsnapshot: > Its behavior is correct. The performance is poor, relative to, > say, zfs snapshots and sends. rsnapshot needs to do a lot more > work. I like rsnapshot. I retired two years ago, but that's how we backed up all our unix boxes and one didn't have to remember much to recover files in a panic situation. Just go to the last snapshot before whatever terrible event happened and, unless you put your irreplaceable gem in and then blew it up between backups, it's just a case of cp or scp. Martin
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2017-03-15 16:40 +0100 |
| Message-ID | <tljbP-16B-7@gated-at.bofh.it> |
| In reply to | #178867 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Mar 15, 2017 at 09:02:53AM -0400, Dan Ritter wrote: > [rsnapshot]'s behavior is correct. The performance is poor, relative to, > say, zfs snapshots and sends. rsnapshot needs to do a lot more > work. There are user-level tools that handle this situation better (e.g. rdiff-snapshot) -- Jonathan Dowland Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2017-03-15 16:40 +0100 |
| Message-ID | <tljbP-16B-5@gated-at.bofh.it> |
| In reply to | #178863 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Mar 15, 2017 at 08:01:00AM -0400, Stefan Monnier wrote: > >> > Having been there and done that, I can assure you that having a > >> > live snapshot system -- rsnapshot or btrfs/zfs native tools -- > >> > is more fun and less work for everyone. > > I looked at rsnapshot but its behavior is poor when you have lots of > directories with lots of tiny files. rdiff-snapshot works much better IMHO in this situation (I switched from rsnapshot to rdiff-backup for this very reason) > It'd probably be fairly easy to come up with a backup system based on Git > (probably not good for whole-system backups, but likely workable for > homedir backups), but I haven't come across such a thing yet. https://packages.debian.org/sid/bup -- Jonathan Dowland Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2017-03-15 21:50 +0100 |
| Message-ID | <tlo1P-4vc-1@gated-at.bofh.it> |
| In reply to | #178863 |
> It'd probably be fairly easy to come up with a backup system based on Git
> (probably not good for whole-system backups, but likely workable for
> homedir backups), but I haven't come across such a thing yet.
Well, for the reference I've now found `bup` which isn't using Git
directly but uses the storage format of Git.
Stefan
[toc] | [prev] | [next] | [standalone]
| From | songbird <songbird@anthive.com> |
|---|---|
| Date | 2017-03-16 23:50 +0100 |
| Message-ID | <tlMnx-51X-25@gated-at.bofh.it> |
| In reply to | #178886 |
Stefan Monnier wrote: >> It'd probably be fairly easy to come up with a backup system based on Git >> (probably not good for whole-system backups, but likely workable for >> homedir backups), but I haven't come across such a thing yet. > > Well, for the reference I've now found `bup` which isn't using Git > directly but uses the storage format of Git. i've found it useful, but i don't run it every day. i run it before i shut down for the days when i've actually made enough changes that i want to worry about backing up. i also do a backup with tar of selected directories once every few months just in case something happens. when i'm doing a new system from scratch i use a partition copy utility after each major step so i don't have to go back and reinstall from media and/or network if something doesn't quite go as i'd like. songbird
[toc] | [prev] | [next] | [standalone]
| From | Miles Fidelman <mfidelman@meetinghouse.net> |
|---|---|
| Date | 2017-03-14 20:10 +0100 |
| Message-ID | <tkZZv-4D5-11@gated-at.bofh.it> |
| In reply to | #178837 |
On 3/14/17 10:54 AM, Glenn English wrote: > On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote: >> David Christensen wrote: >>> On 03/11/2017 07:10 AM, Richard Owlett wrote: >>>> I've vague ideas of what backup pattern(s) I might follow. >>>> I'm looking for reading materials that might trigger "I hadn't thought >>>> of that" moments. >>>> >>>> Suggestions? > I didn't see anybody talk about incremental backup (the backup > consists of current versions as well as earlier ones -- often earlier > work can replace erroneous or lost current work. Or work you don't > notice is gone for a few days.). There are 2 I know of, and one (and > probably many more) that may do that: > > Adding two: I've been using rdiff-backup for years - essentially it's time machine for linux. There's a little helper routine called "backup ninja" and a gui (works in a text window) called ninjahelper. It will do incremental backups across two machines, and knows how to set up jobs for mysql, postgress, and the entire file system. It takes a little work to set up (server and client), and it's a bit tricky to do recoveries (command line rdiff-backup commands) - but it does the job very well. It's great of recovering accidentally deleted files, and older versions of files. For full snapshots (e.g., crash recovery), I just use RAIDED disks, mirrored via DRBD to a failover machine. If you're on a desktop machine, you might consider a cloud backup service. I recommend CrashPlan - there's a linux client, it will back up to other machines (local and remote) for free, and there's a very reliable, and cheap cloud backup (particularly nice pricing for backing up all machines in a household, with unlimited storage). I use the first approach on our production servers, the second for all the machines at home (mix of Mac, Windows, Linux). My wife and I also run Time Machine on our Macbooks - there's a lot to be said for having backup that doesn't require having an external disk plugged in. Miles Fidelman -- In theory, there is no difference between theory and practice. In practice, there is. .... Yogi Berra
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2017-03-11 23:30 +0100 |
| Message-ID | <tjXGp-Kx-9@gated-at.bofh.it> |
| In reply to | #178680 |
On Sat, 11 Mar 2017 09:10:54 -0600 Richard Owlett <rowlett@cloud85.net> wrote: > I've been good about telling others that backups are a good idea. > Guess who hadn't and then crashed his system and spent hours putting > things back together ;< > > In the past individual projects ended up on individual flash drives > as I was frequently using different machines. I now have some > reliable hardware and a large internal hard drive. > > I have one partition that might be called a "production" environment, > i.e. fairly stable and has the most valuable content. > A second partition hosts my experiments - I've a project to create an > optimal install. The third is the target of those experimental > installs whose content doesn't rate explicit backups. The scripts for > creating those installs being on the second partition. > > I've vague ideas of what backup pattern(s) I might follow. > I'm looking for reading materials that might trigger "I hadn't > thought of that" moments. > > Suggestions? This is a well-known joke (and advert): http://www.taobackup.com/ but does touch briefly on most backup issues. And here's an old page that discusses the issues of snapshot-style backups: http://www.mikerubel.org/computers/rsync_snapshots/ There are more recent implementations of this kind of thing, but this tutorial makes you think about what's going on, and what you might need to go on. Note that using LVM with some spare drive space allows online volume snapshots, along the lines of the Windows Volume Shadow Copy system. But you can enable and disable the LVM snapshot, thereby avoiding the significant overhead on disc writes when you don't need it. It is assumed that Windows users need the facility continuously. One unusual point of view nowadays: given the existence of encryption ransomware, I think there is still a place for optical discs for offline snapshots of actual user data, the OS being far too large now, of course, and USB sticks are still a bit expensive for a frequent write-once-keep-for-years backup scheme. I use truecrypt files on my laptop of around 4GB, so I can dump them to DVD every week or so (yes, I actually have a laptop with an optical drive). -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2017-03-15 13:30 +0100 |
| Message-ID | <tlgdY-7yR-17@gated-at.bofh.it> |
| In reply to | #178695 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, Mar 11, 2017 at 10:28:22PM +0000, Joe wrote: > This is a well-known joke (and advert): > > http://www.taobackup.com/ > > but does touch briefly on most backup issues. Great to see someone else recommending this, I do too :) -- Jonathan Dowland Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web