Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #178680 > unrolled thread

Guide(s?) to backup philosophies

Started byRichard Owlett <rowlett@cloud85.net>
First post2017-03-11 16:20 +0100
Last post2017-03-19 11:40 +0100
Articles 20 on this page of 45 — 18 participants

Back to article view | Back to linux.debian.user


Contents

  Guide(s?) to backup philosophies Richard Owlett <rowlett@cloud85.net> - 2017-03-11 16:20 +0100
    Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-11 22:10 +0100
      Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-13 14:00 +0100
        Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-14 05:00 +0100
          Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-17 11:50 +0100
            Re: Guide(s?) to backup philosophies Glenn English <ghe2001@gmail.com> - 2017-03-17 19:50 +0100
            Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-18 06:20 +0100
              Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-22 11:50 +0100
                Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-22 11:50 +0100
                  Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-22 13:20 +0100
                    Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-22 13:30 +0100
                      Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 10:30 +0100
                        Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-23 11:10 +0100
                          Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 13:10 +0100
                Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-23 04:00 +0100
                  Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 10:40 +0100
                    Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-23 20:10 +0100
          Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 14:10 +0200
            Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 23:20 +0200
            Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) Nathan Dorfman <ndorf@rtfm.net> - 2017-04-01 11:00 +0200
          should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) cbannister@slingshot.co.nz - 2017-03-31 14:10 +0200
            Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) <tomas@tuxteam.de> - 2017-03-31 14:20 +0200
              Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) Brian <ad44@cityscape.co.uk> - 2017-03-31 15:20 +0200
                Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) <tomas@tuxteam.de> - 2017-03-31 15:30 +0200
                Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 15:30 +0200
                  Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 15:50 +0200
        Re: Guide(s?) to backup philosophies Glenn English <ghe2001@gmail.com> - 2017-03-14 19:00 +0100
          Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-14 19:20 +0100
            Re: Guide(s?) to backup philosophies Miles Fidelman <mfidelman@meetinghouse.net> - 2017-03-14 20:20 +0100
              Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-14 21:40 +0100
                Re: Guide(s?) to backup philosophies Stefan Monnier <monnier@iro.umontreal.ca> - 2017-03-15 13:30 +0100
                  Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-15 14:10 +0100
                    Re: Guide(s?) to backup philosophies "Martin McCormick" <martin.m@suddenlink.net> - 2017-03-15 14:30 +0100
                    Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 16:40 +0100
                  Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 16:40 +0100
                  Re: Guide(s?) to backup philosophies Stefan Monnier <monnier@iro.umontreal.ca> - 2017-03-15 21:50 +0100
                    Re: Guide(s?) to backup philosophies songbird <songbird@anthive.com> - 2017-03-16 23:50 +0100
          Re: Guide(s?) to backup philosophies Miles Fidelman <mfidelman@meetinghouse.net> - 2017-03-14 20:10 +0100
    Re: Guide(s?) to backup philosophies Joe <joe@jretrading.com> - 2017-03-11 23:30 +0100
      Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 13:30 +0100
    Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-13 15:20 +0100
      Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-14 05:10 +0100
      Re: Guide(s?) to backup philosophies Richard Owlett <rowlett@cloud85.net> - 2017-03-14 15:50 +0100
    Re: Guide(s?) to backup philosophies Merlin Büge <toni@bluenox07.de> - 2017-03-14 19:50 +0100
    Re: Guide(s?) to backup philosophies DdB <debianlist@potentially-spam.de-bruyn.de> - 2017-03-19 11:40 +0100

Page 2 of 3 — ← Prev page 1 [2] 3  Next page →


#179634 — should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

Fromcbannister@slingshot.co.nz
Date2017-03-31 14:10 +0200
Subjectshould I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<tr3xn-4rg-3@gated-at.bofh.it>
In reply to#178810
On Mon, Mar 13, 2017 at 08:58:15PM -0700, David Christensen wrote:
> On 03/13/2017 05:38 AM, Dan Purgert wrote:
> >Currently, the system here is
> >
> > - every PC has a cronjob backing up $HOME to a central "server" (read -
> >   repurposed PC with decent WD drives), just an rsync script that runs
> >   daily.
> 
> Don't forget security:
> 
> 1.  With a "push" arrangement (e.g. each workstation backs up itself to the
> server) -- if a workstation gets compromised, the backups are at risk.
> 
> 2.  With a "pull" arrangement (e.g. the server backs up all the
> workstations) -- if a workstation gets compromised, the backups should be
> safe (and might have clues about the intrusion).  Additionally, the backup
> server can be completely firewalled (e.g. no open ports).

My understanding is that if there are no services listening on a port then
it cannot be accessed.

e.g.

http://serverfault.com/questions/733633/if-no-service-is-listening-on-a-port-can-a-system-still-be-accessed-using-that-p

An I missing something? 

-- 
The media's the most powerful entity on earth. 
They have the power to make the innocent guilty 
and to make the guilty innocent, and that's power.
 -- Malcolm X

[toc] | [prev] | [next] | [standalone]


#179635 — Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

From<tomas@tuxteam.de>
Date2017-03-31 14:20 +0200
SubjectRe: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<tr3H4-4uB-15@gated-at.bofh.it>
In reply to#179634
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sat, Apr 01, 2017 at 01:00:45AM +1300, cbannister@slingshot.co.nz wrote:

[...]

> My understanding is that if there are no services listening on a port then
> it cannot be accessed.
> 
> e.g.
> 
> http://serverfault.com/questions/733633/if-no-service-is-listening-on-a-port-can-a-system-still-be-accessed-using-that-p
> 
> An I missing something? 

As Dominik said: it's "defense in depth". If your PHP^H^H^H web application
has some code injection issue, your adversary might well install a C&C
server listening on that port, and work from there on (exfiltrate data,
try some privelege escalation, whatever).

Now there might be other avenues for that, but security is about closing
the avenue your adversary is going to use next ;-)

regards
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEUEARECAAYFAljeSPwACgkQBcgs9XrR2kZccACSAtp4XjR4TifCMA1+Ip/j+oM0
wQCfe9snMu/5hvDCXb+5joez/4iPDQ4=
=5oco
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#179637 — Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

FromBrian <ad44@cityscape.co.uk>
Date2017-03-31 15:20 +0200
SubjectRe: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<tr4D8-56f-11@gated-at.bofh.it>
In reply to#179635
On Fri 31 Mar 2017 at 14:18:04 +0200, tomas@tuxteam.de wrote:

> On Sat, Apr 01, 2017 at 01:00:45AM +1300, cbannister@slingshot.co.nz wrote:
> 
> [...]
> 
> > My understanding is that if there are no services listening on a port then
> > it cannot be accessed.
> > 
> > e.g.
> > 
> > http://serverfault.com/questions/733633/if-no-service-is-listening-on-a-port-can-a-system-still-be-accessed-using-that-p
> > 
> > An I missing something? 

I rather thought cbannister had the correct idea: nothing listening;
therefore no access.
 
> As Dominik said: it's "defense in depth". If your PHP^H^H^H web application
> has some code injection issue, your adversary might well install a C&C
> server listening on that port, and work from there on (exfiltrate data,
> try some privelege escalation, whatever).
> 
> Now there might be other avenues for that, but security is about closing
> the avenue your adversary is going to use next ;-)

If someone unauthorised is on your machine can they not just as well
remove firewall rules?

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#179638 — Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

From<tomas@tuxteam.de>
Date2017-03-31 15:30 +0200
SubjectRe: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<tr4MO-59K-11@gated-at.bofh.it>
In reply to#179637
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Fri, Mar 31, 2017 at 02:17:35PM +0100, Brian wrote:
> On Fri 31 Mar 2017 at 14:18:04 +0200, tomas@tuxteam.de wrote:
> 
> > On Sat, Apr 01, 2017 at 01:00:45AM +1300, cbannister@slingshot.co.nz wrote:
> > 
> > [...]
> > 
> > > My understanding is that if there are no services listening on a port then
> > > it cannot be accessed.
> > > 
> > > e.g.
> > > 
> > > http://serverfault.com/questions/733633/if-no-service-is-listening-on-a-port-can-a-system-still-be-accessed-using-that-p
> > > 
> > > An I missing something? 
> 
> I rather thought cbannister had the correct idea: nothing listening;
> therefore no access.
>  
> > As Dominik said: it's "defense in depth". If your PHP^H^H^H web application
> > has some code injection issue, your adversary might well install a C&C
> > server listening on that port, and work from there on (exfiltrate data,
> > try some privelege escalation, whatever).
> > 
> > Now there might be other avenues for that, but security is about closing
> > the avenue your adversary is going to use next ;-)
> 
> If someone unauthorised is on your machine can they not just as well
> remove firewall rules?

If they have done the privilege escalation bit, then yes. If they are
"just" running as the web server user (which hopefully ain't root) then
"not... yet". Unless you've set up sudo so that www-user can change
the firewall rules. But then you'd have to tell us more about that ;-D

Regards
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAljeWP0ACgkQBcgs9XrR2kb4OACfSM1gZZ6Ac2OlSHEBaGfEuM+p
EmMAn1kpsOY5vTMQQ3ou2hPRwsBAp72b
=s6iO
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#179639 — Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

FromDominik George <nik@naturalnet.de>
Date2017-03-31 15:30 +0200
SubjectRe: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<tr4MO-59K-25@gated-at.bofh.it>
In reply to#179637
>If someone unauthorised is on your machine can they not just as well
>remove firewall rules?


Well, not without getting root first.

And making something listen that spawns a shell usable to gain further access is a big win. Keeping uploading PHP code to some vulnerable webserver will at some point be noticed. Uploading something spawning a shell once probably not.

-nik

[toc] | [prev] | [next] | [standalone]


#179642 — Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

FromDominik George <nik@naturalnet.de>
Date2017-03-31 15:50 +0200
SubjectRe: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<tr569-5gO-7@gated-at.bofh.it>
In reply to#179639
>Well, not without getting root first.
>
>And making something listen that spawns a shell usable to gain further
>access is a big win. Keeping uploading PHP code to some vulnerable
>webserver will at some point be noticed. Uploading something spawning a
>shell once probably not.
>

When $someone hacked $somebigamericanwebhoster some years ago, $they first found a CMS that allowed online editing of its PHP code. $they were able to use that to run arbitrary shell commands. However, that thing had an edit history, so keeping passing in new code produced a well-visible log each time (in retrospective, $they could just have patched that away, but well...).

Uploading and starting ajaxterm, however, cost $them only two edits, and as it went listening on its own port without a firewall logging, $they had an interactive shell that could be configured to keep no record of anything.

(Not of any interest here, but $they then found a misconfigured NFS share that mapped all UIDs to root, keeping suid bits... use your imagination for the rest. But $they would not have found that without an interactive shell.)

-nik

[toc] | [prev] | [next] | [standalone]


#178837

FromGlenn English <ghe2001@gmail.com>
Date2017-03-14 19:00 +0100
Message-ID<tkYTM-3Be-15@gated-at.bofh.it>
In reply to#178755
On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote:
> David Christensen wrote:
>> On 03/11/2017 07:10 AM, Richard Owlett wrote:
>>> I've vague ideas of what backup pattern(s) I might follow.
>>> I'm looking for reading materials that might trigger "I hadn't thought
>>> of that" moments.
>>>
>>> Suggestions?

I didn't see anybody talk about incremental backup (the backup
consists of current versions as well as earlier ones -- often earlier
work can replace erroneous or lost current work. Or work you don't
notice is gone for a few days.). There are 2 I know of, and one (and
probably many more) that may do that:

Apple's TimeMachine

pros:
TM backs up forever -- you can recover (many) things from the day it started.
It backs up every few minutes without being told to.
It's smart about keeping recent files and tossing pretty old ones.
It's trivial to get going.

cons:
It backs up to a single disk.
It's GUI is kind of cutesy and a bit hard to use.
It's Mac only.
Macs change every few minutes. But I've been using it since it came
out (one of the Leopards), and it's not changed, AFAIK.

Amanda

pros:
It backs up using tar files so it's possible (but significant trouble)
to recover data when the Amanda server fails.
It can be configured to use many different pieces of medium.
It writes to tape or disk. I don't know if it does cloud.
It backs up an entire network.
It checks its output, if asked, after backup.
Cron can run it at 3:00 in the morning.

cons:
Configuration is pretty complex and time consuming.
There has to be an Amanda client on every host it's to back up.
There has to be an 'Amanda buffer disk' (from the tape days).
It's old -- no GUI. But it's solid as a rock.
Since there's no GUI, it takes a little thought and an instruction
book/man page to recover (it does me, anyway).
When a file has changed, it writes the entire file, not just the
changes (could be considered a pro).

Backula

I really don't know much about this one except that it writes using a
proprietary system. Or it did last time I looked (and rejected it for
that reason).


I've been using Amanda with tape for over a decade. No probs. Backing
up and recovering. I've never had to do a bare metal restore, though.
Nor have I ever tried to recover from one of its tarballs.

It's written in C, and beware, I've seen at least one goto in the
source (I've seen the source because it's Debian free -- I think
Backula is too).

I've been on Amanda and tape from the beginning, back in the dark
ages, but I suspect it'd be happy to write to a handful of large(ish)
thumb drives. Another way of getting an incremental backup is to
mirror an entire system every day to a different device from a
collection of removable media (like thumb drives). That'd be a problem
for the likes of Google or Amazon, but might work well for a small
system.

--
Glenn English

[toc] | [prev] | [next] | [standalone]


#178838

FromDan Ritter <dsr@randomstring.org>
Date2017-03-14 19:20 +0100
Message-ID<tkZd8-43W-31@gated-at.bofh.it>
In reply to#178837
On Tue, Mar 14, 2017 at 05:54:06PM +0000, Glenn English wrote:
> On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote:
> > David Christensen wrote:
> >> On 03/11/2017 07:10 AM, Richard Owlett wrote:
> >>> I've vague ideas of what backup pattern(s) I might follow.
> >>> I'm looking for reading materials that might trigger "I hadn't thought
> >>> of that" moments.
> >>>
> >>> Suggestions?
> 
> I didn't see anybody talk about incremental backup (the backup
> consists of current versions as well as earlier ones -- often earlier
> work can replace erroneous or lost current work. Or work you don't
> notice is gone for a few days.). There are 2 I know of, and one (and
> probably many more) that may do that:

Having been there and done that, I can assure you that having a
live snapshot system -- rsnapshot or btrfs/zfs native tools --
is more fun and less work for everyone.

As a bonus, they can all send snapshots to remote systems or
detachable media.


> It backs up to a single disk.
> It's GUI is kind of cutesy and a bit hard to use.
> It's Mac only.
> Macs change every few minutes. But I've been using it since it came
> out (one of the Leopards), and it's not changed, AFAIK.

On Macs, this is the way to go. But! You don't need to back up
to a single disk. You can back up to a Linux system running
AppleTalk, and those volumes can sit on RAID or ZFS or whatever
you want. Recommended.

[Amanda]

> It can be configured to use many different pieces of medium.
> It writes to tape or disk. I don't know if it does cloud.

You can pretend a remote server is a set of disks. I wouldn't.

> I've been using Amanda with tape for over a decade. No probs. Backing
> up and recovering. I've never had to do a bare metal restore, though.
> Nor have I ever tried to recover from one of its tarballs.

Not much fun. Especially compared to self-service or nearly
self-service from snapshots.

> I've been on Amanda and tape from the beginning, back in the dark
> ages, but I suspect it'd be happy to write to a handful of large(ish)
> thumb drives. Another way of getting an incremental backup is to
> mirror an entire system every day to a different device from a
> collection of removable media (like thumb drives). That'd be a problem
> for the likes of Google or Amazon, but might work well for a small
> system.

Thumb drives are terribly unreliable, but cheapish. Treat them
like tapes and never write over them, and assume that some
percentage will just die.

-dsr-

[toc] | [prev] | [next] | [standalone]


#178843

FromMiles Fidelman <mfidelman@meetinghouse.net>
Date2017-03-14 20:20 +0100
Message-ID<tl09c-4Iz-13@gated-at.bofh.it>
In reply to#178838
On 3/14/17 11:18 AM, Dan Ritter wrote:

> On Tue, Mar 14, 2017 at 05:54:06PM +0000, Glenn English wrote:
>> On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote:
>>> David Christensen wrote:
>>>> On 03/11/2017 07:10 AM, Richard Owlett wrote:
>>>>> I've vague ideas of what backup pattern(s) I might follow.
>>>>> I'm looking for reading materials that might trigger "I hadn't thought
>>>>> of that" moments.
>>>>>
>>>>> Suggestions?
>> I didn't see anybody talk about incremental backup (the backup
>> consists of current versions as well as earlier ones -- often earlier
>> work can replace erroneous or lost current work. Or work you don't
>> notice is gone for a few days.). There are 2 I know of, and one (and
>> probably many more) that may do that:
> Having been there and done that, I can assure you that having a
> live snapshot system -- rsnapshot or btrfs/zfs native tools --
> is more fun and less work for everyone.
>
Only if they do versioning.  Otherwise, live snapshots mirror deletes - 
not very useful if you want to restore an accidental delete!

Miles Fidelman



-- 
In theory, there is no difference between theory and practice.
In practice, there is.  .... Yogi Berra

[toc] | [prev] | [next] | [standalone]


#178846

FromDan Ritter <dsr@randomstring.org>
Date2017-03-14 21:40 +0100
Message-ID<tl1oB-5wC-9@gated-at.bofh.it>
In reply to#178843
On Tue, Mar 14, 2017 at 12:15:15PM -0700, Miles Fidelman wrote:
> On 3/14/17 11:18 AM, Dan Ritter wrote:
> 
> > On Tue, Mar 14, 2017 at 05:54:06PM +0000, Glenn English wrote:
> > > On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote:
> > > > David Christensen wrote:
> > > > > On 03/11/2017 07:10 AM, Richard Owlett wrote:
> > > > > > I've vague ideas of what backup pattern(s) I might follow.
> > > > > > I'm looking for reading materials that might trigger "I hadn't thought
> > > > > > of that" moments.
> > > > > > 
> > > > > > Suggestions?
> > > I didn't see anybody talk about incremental backup (the backup
> > > consists of current versions as well as earlier ones -- often earlier
> > > work can replace erroneous or lost current work. Or work you don't
> > > notice is gone for a few days.). There are 2 I know of, and one (and
> > > probably many more) that may do that:
> > Having been there and done that, I can assure you that having a
> > live snapshot system -- rsnapshot or btrfs/zfs native tools --
> > is more fun and less work for everyone.
> > 
> Only if they do versioning.  Otherwise, live snapshots mirror deletes - not
> very useful if you want to restore an accidental delete!

All of the systems I mention are versioned (dated) snapshot
systems.

-dsr-

[toc] | [prev] | [next] | [standalone]


#178863

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2017-03-15 13:30 +0100
Message-ID<tlgdY-7yR-23@gated-at.bofh.it>
In reply to#178846
>> > Having been there and done that, I can assure you that having a
>> > live snapshot system -- rsnapshot or btrfs/zfs native tools --
>> > is more fun and less work for everyone.

I looked at rsnapshot but its behavior is poor when you have lots of
directories with lots of tiny files.

It'd probably be fairly easy to come up with a backup system based on Git
(probably not good for whole-system backups, but likely workable for
homedir backups), but I haven't come across such a thing yet.


        Stefan

[toc] | [prev] | [next] | [standalone]


#178867

FromDan Ritter <dsr@randomstring.org>
Date2017-03-15 14:10 +0100
Message-ID<tlgQG-85t-19@gated-at.bofh.it>
In reply to#178863
On Wed, Mar 15, 2017 at 08:01:00AM -0400, Stefan Monnier wrote:
> >> > Having been there and done that, I can assure you that having a
> >> > live snapshot system -- rsnapshot or btrfs/zfs native tools --
> >> > is more fun and less work for everyone.
> 
> I looked at rsnapshot but its behavior is poor when you have lots of
> directories with lots of tiny files.

Its behavior is correct. The performance is poor, relative to,
say, zfs snapshots and sends. rsnapshot needs to do a lot more
work.

> It'd probably be fairly easy to come up with a backup system based on Git
> (probably not good for whole-system backups, but likely workable for
> homedir backups), but I haven't come across such a thing yet.

You can try etckeeper, which is packaged in Debian. The default
config is aimed at /etc, but it can be aimed elsewhere.

[toc] | [prev] | [next] | [standalone]


#178870

From"Martin McCormick" <martin.m@suddenlink.net>
Date2017-03-15 14:30 +0100
Message-ID<tlha2-8dq-21@gated-at.bofh.it>
In reply to#178867
Dan Ritter <dsr@randomstring.org> writes regarding rsnapshot:
> Its behavior is correct. The performance is poor, relative to,
> say, zfs snapshots and sends. rsnapshot needs to do a lot more
> work.

	I like rsnapshot. I retired two years ago, but that's how
we backed up all our unix boxes and one didn't have to remember
much to recover files in a panic situation. Just go to the
last snapshot before whatever terrible event happened and, unless
you put your irreplaceable gem in and then blew it up between
backups, it's just a case of cp or scp.

Martin

[toc] | [prev] | [next] | [standalone]


#178874

FromJonathan Dowland <jmtd@debian.org>
Date2017-03-15 16:40 +0100
Message-ID<tljbP-16B-7@gated-at.bofh.it>
In reply to#178867

[Multipart message — attachments visible in raw view] — view raw

On Wed, Mar 15, 2017 at 09:02:53AM -0400, Dan Ritter wrote:
> [rsnapshot]'s behavior is correct. The performance is poor, relative to,
> say, zfs snapshots and sends. rsnapshot needs to do a lot more
> work.

There are user-level tools that handle this situation better (e.g.
rdiff-snapshot)

-- 
Jonathan Dowland
Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#178873

FromJonathan Dowland <jmtd@debian.org>
Date2017-03-15 16:40 +0100
Message-ID<tljbP-16B-5@gated-at.bofh.it>
In reply to#178863

[Multipart message — attachments visible in raw view] — view raw

On Wed, Mar 15, 2017 at 08:01:00AM -0400, Stefan Monnier wrote:
> >> > Having been there and done that, I can assure you that having a
> >> > live snapshot system -- rsnapshot or btrfs/zfs native tools --
> >> > is more fun and less work for everyone.
> 
> I looked at rsnapshot but its behavior is poor when you have lots of
> directories with lots of tiny files.

rdiff-snapshot works much better IMHO in this situation (I switched
from rsnapshot to rdiff-backup for this very reason)

> It'd probably be fairly easy to come up with a backup system based on Git
> (probably not good for whole-system backups, but likely workable for
> homedir backups), but I haven't come across such a thing yet.

https://packages.debian.org/sid/bup

-- 
Jonathan Dowland
Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#178886

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2017-03-15 21:50 +0100
Message-ID<tlo1P-4vc-1@gated-at.bofh.it>
In reply to#178863
> It'd probably be fairly easy to come up with a backup system based on Git
> (probably not good for whole-system backups, but likely workable for
> homedir backups), but I haven't come across such a thing yet.

Well, for the reference I've now found `bup` which isn't using Git
directly but uses the storage format of Git.


        Stefan

[toc] | [prev] | [next] | [standalone]


#178939

Fromsongbird <songbird@anthive.com>
Date2017-03-16 23:50 +0100
Message-ID<tlMnx-51X-25@gated-at.bofh.it>
In reply to#178886
Stefan Monnier wrote:
>> It'd probably be fairly easy to come up with a backup system based on Git
>> (probably not good for whole-system backups, but likely workable for
>> homedir backups), but I haven't come across such a thing yet.
>
> Well, for the reference I've now found `bup` which isn't using Git
> directly but uses the storage format of Git.

  i've found it useful, but i don't run it
every day.  i run it before i shut down for
the days when i've actually made enough
changes that i want to worry about backing
up.

  i also do a backup with tar of selected
directories once every few months just in case 
something happens.

  when i'm doing a new system from scratch i use
a partition copy utility after each major step
so i don't have to go back and reinstall from
media and/or network if something doesn't quite 
go as i'd like.


  songbird

[toc] | [prev] | [next] | [standalone]


#178842

FromMiles Fidelman <mfidelman@meetinghouse.net>
Date2017-03-14 20:10 +0100
Message-ID<tkZZv-4D5-11@gated-at.bofh.it>
In reply to#178837
On 3/14/17 10:54 AM, Glenn English wrote:

> On Mon, Mar 13, 2017 at 12:38 PM, Dan Purgert <dan@djph.net> wrote:
>> David Christensen wrote:
>>> On 03/11/2017 07:10 AM, Richard Owlett wrote:
>>>> I've vague ideas of what backup pattern(s) I might follow.
>>>> I'm looking for reading materials that might trigger "I hadn't thought
>>>> of that" moments.
>>>>
>>>> Suggestions?
> I didn't see anybody talk about incremental backup (the backup
> consists of current versions as well as earlier ones -- often earlier
> work can replace erroneous or lost current work. Or work you don't
> notice is gone for a few days.). There are 2 I know of, and one (and
> probably many more) that may do that:
>
>
Adding two:

I've been using rdiff-backup for years - essentially it's time machine 
for linux.  There's a little helper routine called "backup ninja" and a 
gui (works in a text window) called ninjahelper.  It will do incremental 
backups across two machines, and knows how to set up jobs for mysql, 
postgress, and the entire file system.  It takes a little work to set up 
(server and client), and it's a bit tricky to do recoveries (command 
line rdiff-backup commands) - but it does the job very well.  It's great 
of recovering accidentally deleted files, and older versions of files.  
For full snapshots (e.g., crash recovery), I just use RAIDED disks, 
mirrored via DRBD to a failover machine.

If you're on a desktop machine, you might consider a cloud backup 
service.  I recommend CrashPlan - there's a linux client, it will back 
up to other machines (local and remote) for free, and there's a very 
reliable, and cheap cloud backup (particularly nice pricing for backing 
up all machines in a household, with unlimited storage).

I use the first approach on our production servers, the second for all 
the machines at home (mix of Mac, Windows, Linux).  My wife and I also 
run Time Machine on our Macbooks - there's a lot to be said for having 
backup that doesn't require having an external disk plugged in.

Miles Fidelman


-- 
In theory, there is no difference between theory and practice.
In practice, there is.  .... Yogi Berra

[toc] | [prev] | [next] | [standalone]


#178695

FromJoe <joe@jretrading.com>
Date2017-03-11 23:30 +0100
Message-ID<tjXGp-Kx-9@gated-at.bofh.it>
In reply to#178680
On Sat, 11 Mar 2017 09:10:54 -0600
Richard Owlett <rowlett@cloud85.net> wrote:

> I've been good about telling others that backups are a good idea.
> Guess who hadn't and then crashed his system and spent hours putting 
> things back together ;<
> 
> In the past individual projects ended up on individual flash drives
> as I was frequently using different machines. I now have some
> reliable hardware and a large internal hard drive.
> 
> I have one partition that might be called a "production" environment, 
> i.e. fairly stable and has the most valuable content.
> A second partition hosts my experiments - I've a project to create an 
> optimal install. The third is the target of those experimental
> installs whose content doesn't rate explicit backups. The scripts for
> creating those installs being on the second partition.
> 
> I've vague ideas of what backup pattern(s) I might follow.
> I'm looking for reading materials that might trigger "I hadn't
> thought of that" moments.
> 
> Suggestions?

This is a well-known joke (and advert):

http://www.taobackup.com/

but does touch briefly on most backup issues. 

And here's an old page that discusses the issues of snapshot-style
backups:

http://www.mikerubel.org/computers/rsync_snapshots/

There are more recent implementations of this kind of thing, but this
tutorial makes you think about what's going on, and what you might
need to go on. Note that using LVM with some spare drive space allows
online volume snapshots, along the lines of the Windows Volume Shadow
Copy system. But you can enable and disable the LVM snapshot, thereby
avoiding the significant overhead on disc writes when you don't need
it. It is assumed that Windows users need the facility continuously.

One unusual point of view nowadays: given the existence of encryption
ransomware, I think there is still a place for optical discs for
offline snapshots of actual user data, the OS being far too large now,
of course, and USB sticks are still a bit expensive for a frequent
write-once-keep-for-years backup scheme. I use truecrypt files on my
laptop of around 4GB, so I can dump them to DVD every week or so (yes,
I actually have a laptop with an optical drive).

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#178862

FromJonathan Dowland <jmtd@debian.org>
Date2017-03-15 13:30 +0100
Message-ID<tlgdY-7yR-17@gated-at.bofh.it>
In reply to#178695

[Multipart message — attachments visible in raw view] — view raw

On Sat, Mar 11, 2017 at 10:28:22PM +0000, Joe wrote:
> This is a well-known joke (and advert):
> 
> http://www.taobackup.com/
> 
> but does touch briefly on most backup issues. 

Great to see someone else recommending this, I do too :)

-- 
Jonathan Dowland
Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


Page 2 of 3 — ← Prev page 1 [2] 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web