User Tools

Site Tools


hints_tips:untrusted_director_-_nix_solution

This is an old revision of the document!


I ran into a situation where the director and storage systems weren't trusted by the fd client. Ie, some of the data on the client should not be available to the director. Nor should the director have rights to create or delete critical files on the client.

The approach I took was to:

  1. create a chroot environment to run the bacula fd client in. The bacula client does not run as root.
  2. create a cron script to copy the files that need to be backed up into the chroot area. This script uses gpg to encrypt and compress the files before copying.

The result is that bacula is used to backup selected files without trusting the bacula system. File names are still exposed but I wasn't concerned about that.

hints_tips/untrusted_director_-_nix_solution.1236701404.txt.gz · Last modified: 2009/03/10 16:10 by jzeeff