16
submitted 2 years ago* (last edited 2 years ago) by gitamar@feddit.de to c/selfhosted@lemmy.world

I am using restic for backups. I would like to use a non-root user to backup my docker volumes. As the files in the volumes have very different access rights and groups, accessing them is difficult without root rights.

Chowning the files doesn't help sustainably, as new files are created with a different group again.

What recommendation do you have to smoothly backup files from the docker volumes?

Tags #restic #backup #docker

you are viewing a single comment's thread
view the rest of the comments
[-] Illecors@lemmy.cafe 10 points 2 years ago

You could just have a dedicated backup user that is in all the groups of you docker volumes.

[-] BearOfaTime@lemm.ee 9 points 2 years ago

This is a common strategy in enterprise, they're called Service Accounts.

Rather than let all services/apps run under one admin account (windows) or a single account with root (*Nix), an account is created for each service/app, with only the minimum necessary permissions. These accounts are also limited, sometimes they're local accounts on a given server (rather than a domain/directory account), usually with no login capability (so couldn't run in a user context).

This way you prevent a 3rd party service/app from having change access to other services/apps (in Windows services run as system by default, a terrible security hole). It also prevents a rogue admin from using such access to change other things (or if the service account credentials were stolen).

[-] gitamar@feddit.de 1 points 2 years ago

This might be a good idea. It would only work for files that allow read access for the group, but that should be fine

this post was submitted on 26 Nov 2023
16 points (100.0% liked)

Selfhosted

61307 readers
410 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS