Amanda-Users

Re: UID under which amanda services should run, if backup server is only client?

2007-07-02 12:39:19
Subject: Re: UID under which amanda services should run, if backup server is only client?
From: Chris Hoogendyk <hoogendyk AT bio.umass DOT edu>
To: Mark Scheufele <mark.scheufele AT diasemi DOT com>
Date: Mon, 02 Jul 2007 12:36:46 -0400

Mark Scheufele wrote:
> Hi,
>
> in our amanda setup there are no other clients than the backup server
> itself. The amanda software was compiled with the
> options--with-user=amanda --with-owner=amanda --with-group=sys so that
> all services do run under a separate amanda user. 
>
> To be able to read all files within the local filesystems I have set the
> parameter dumpuser to "root" in the amanda.conf file. Backups are now
> running fine. But I am running into permission problems with amrecover.
>
> The problem is that all files under etc/<config>/index and all log.*
> files under etc/<config> are all assigned to the root user. The amindexd
> yet runs under the amanda user and therefore isn't able to read those
> files properly.
>
> To fix the problem I was thinking about recompiling amanda to run all
> services completely under the uid root to avoid the permission problems.
>
> But maybe there is a better way to accomplish my goal. It would be great
> if someone could point me into the right direction.

I would not do that. Generally speaking, use root as little as possible.

Just follow the setup instructions and use the amanda user.

You need root to run amrecover, but not to run backups.

When I first set up amanda, I followed the quick_start more or less:
<http://wiki.zmanda.com/index.php/Quick_start>. I had only the server
backing up itself. Once that was working, I expanded from there. But the
basic setup didn't have to change.

If you set things up with root, and then decide to add other clients,
you will be stuck in a situation requiring root processes and root
logins all across your net on a regular basis. It's best not to do that.
As Paul's comments said, get it working as intended rather than trying
to force your way past difficulties using root.


---------------

Chris Hoogendyk

-
   O__  ---- Systems Administrator
  c/ /'_ --- Biology & Geology Departments
 (*) \(*) -- 140 Morrill Science Center
~~~~~~~~~~ - University of Massachusetts, Amherst 

<hoogendyk AT bio.umass DOT edu>

--------------- 

Erdös 4



<Prev in Thread] Current Thread [Next in Thread>