<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Kommentare zu: Secure backups with push and pull strategies via amazon s3</title>
	<atom:link href="http://www.logaholic.de/2009/05/21/secure-backups-with-push-and-pull-strategies-via-amazon-s3/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.logaholic.de/2009/05/21/secure-backups-with-push-and-pull-strategies-via-amazon-s3/</link>
	<description>queer as code!</description>
	<lastBuildDate>Sat, 03 Dec 2011 22:03:07 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Von: Karsten Deubert</title>
		<link>http://www.logaholic.de/2009/05/21/secure-backups-with-push-and-pull-strategies-via-amazon-s3/comment-page-1/#comment-169</link>
		<dc:creator>Karsten Deubert</dc:creator>
		<pubDate>Sat, 29 Aug 2009 19:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.logaholic.de/?p=271#comment-169</guid>
		<description>Hi Lem, thank you for your comment. You are right, i haven&#039;t actually implemented this fully.

At the moment we use amazon s3 just as temporary storage, whilst our nightly pull-script just downloads and deletes the backups from the bucket.
Would it maybe be possible to let the pull-script set the owner of the file to the adminaccount and therefore permit the push-user to delete/modify it?</description>
		<content:encoded><![CDATA[<p>Hi Lem, thank you for your comment. You are right, i haven&#8217;t actually implemented this fully.</p>
<p>At the moment we use amazon s3 just as temporary storage, whilst our nightly pull-script just downloads and deletes the backups from the bucket.<br />
Would it maybe be possible to let the pull-script set the owner of the file to the adminaccount and therefore permit the push-user to delete/modify it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Lem</title>
		<link>http://www.logaholic.de/2009/05/21/secure-backups-with-push-and-pull-strategies-via-amazon-s3/comment-page-1/#comment-167</link>
		<dc:creator>Lem</dc:creator>
		<pubDate>Sat, 22 Aug 2009 21:45:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.logaholic.de/?p=271#comment-167</guid>
		<description>I meant to say &quot;then the user can put, but they can also overwrite and delete&quot;.</description>
		<content:encoded><![CDATA[<p>I meant to say &#8220;then the user can put, but they can also overwrite and delete&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Lem</title>
		<link>http://www.logaholic.de/2009/05/21/secure-backups-with-push-and-pull-strategies-via-amazon-s3/comment-page-1/#comment-166</link>
		<dc:creator>Lem</dc:creator>
		<pubDate>Sat, 22 Aug 2009 21:44:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.logaholic.de/?p=271#comment-166</guid>
		<description>Have you actually implemented this? I am unclear on how &quot;The production environment, with its own (restricted to put and get files) s3 user, will push backups to our s3 bucket. It is not allowed to delete backups there.&quot; is supposed to work.

As far as I can tell, the ACLs in S3 support granting READ or WRITE on buckets and objects. If you grant WRITE on a bucket, then the user can put, but they can also upload and delete. I do not see how you can allow upload but disallow delete.</description>
		<content:encoded><![CDATA[<p>Have you actually implemented this? I am unclear on how &#8220;The production environment, with its own (restricted to put and get files) s3 user, will push backups to our s3 bucket. It is not allowed to delete backups there.&#8221; is supposed to work.</p>
<p>As far as I can tell, the ACLs in S3 support granting READ or WRITE on buckets and objects. If you grant WRITE on a bucket, then the user can put, but they can also upload and delete. I do not see how you can allow upload but disallow delete.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

