public inbox for pbs-devel@lists.proxmox.com
 help / color / mirror / Atom feed
* [pbs-devel] [PATCH proxmox-backup 1/2] docs: add security implications of prune and change detection mode
@ 2024-10-31 15:45 Christian Ebner
  2024-10-31 15:45 ` [pbs-devel] [PATCH proxmox-backup 2/2] docs: deduplicate background details for garbage collection Christian Ebner
  0 siblings, 1 reply; 2+ messages in thread
From: Christian Ebner @ 2024-10-31 15:45 UTC (permalink / raw)
  To: pbs-devel

Users should be made aware that the data stored in chunks outlives
the backup snapshots on pruning and that backups created using the
change-detection-mode set to metadata might reference chunks
containing files which have vanished since the previous backup, but
might still be accessible when access to the chunks raw data is
possible (client or server side).

Signed-off-by: Christian Ebner <c.ebner@proxmox.com>
---
 docs/maintenance.rst | 23 +++++++++++++++++++++--
 1 file changed, 21 insertions(+), 2 deletions(-)

diff --git a/docs/maintenance.rst b/docs/maintenance.rst
index 4bb135e4e..b6d42ecc2 100644
--- a/docs/maintenance.rst
+++ b/docs/maintenance.rst
@@ -6,8 +6,27 @@ Maintenance Tasks
 Pruning
 -------
 
-Prune lets you specify which backup snapshots you want to keep.
-The following retention options are available:
+Prune lets you specify which backup snapshots you want to keep, removing others.
+For removed backups, only the metadata associating the snapshot with the data
+stored in the data chunks is removed, the actual backup data has to be removed
+by garbage collection.
+
+.. Caution:: Take into consideration that sensitive information stored in data
+   chunks will outlive a pruned snapshot and remain present in the datastore as
+   long as at least one backup snapshot references this data.
+
+   If no longer referenced, the data remains until removed by the garbage
+   collection.
+
+   Further, backups created using the `change-detection-mode` set to `metadata`
+   might reference backup chunks containing files which have vanished since the
+   previous backup, but might still be accessible when reading the chunks raw
+   data is possible (client or server side).
+
+   Creating a backup with `change-detection-mode` set to `data` will break this
+   chain, as files will never reuse chunks partially.
+
+The following retention options are available for pruning:
 
 ``keep-last <N>``
   Keep the last ``<N>`` backup snapshots.
-- 
2.39.5



_______________________________________________
pbs-devel mailing list
pbs-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pbs-devel


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2024-10-31 15:46 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-10-31 15:45 [pbs-devel] [PATCH proxmox-backup 1/2] docs: add security implications of prune and change detection mode Christian Ebner
2024-10-31 15:45 ` [pbs-devel] [PATCH proxmox-backup 2/2] docs: deduplicate background details for garbage collection Christian Ebner

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal