Re: rsync readonly mode?
RolandK via rsync <[email protected]> Thu, 9 Apr 2026 13:14:08 +0200
| Newsgroups | gmane.network.rsync.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============3504298377539627804==
Content-Type: multipart/alternative;
boundary="------------s0XHZDv3q6ZHIa4J4b7CDPXf"
This is a multi-part message in MIME format.
--------------s0XHZDv3q6ZHIa4J4b7CDPXf
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable
thanks,
i have to admit i have underestimated rrsync.=C2=A0 looks like a powerful=
=20
tool, and testing looks quite promsing.
it seems i need to do only minimal changes to our backup solution.
unfortunately, rrsync is not available on some platforms like macos, not=
=20
even homebrew rsync 3.4.1 does bundle it (yet).
regards
Roland
Am 08.04.26 um 18:22 schrieb Kevin Korb via rsync:
> You can do this by restricting the ssh key to rrsync (comes with rsync=
=20
> in the contrib dir).=C2=A0 It has a read only and a write only mode. If =
the=20
> path you give it is / then it is pretty much transparent unless one of=
=20
> those options is also used.
>
> Otherwise, you can use the rsyncd over ssh setup which is kinda ugly=20
> and would require the same forcing method to not just be optional.
>
> On 4/8/26 12:18, RolandK via rsync wrote:
>> Hello,
>>
>> we are using rsync mostly exclusively for packup purpose in "pull=20
>> mode" , run via script from a central backup server.
>>
>> for that, we typically have allowed remote root login via ssh key.=C2=
=A0=20
>> rsync from the backup server pulls data from all hosts to be backed=20
>> up via ssh/rsync remote pipe.
>> it's running great for years in conjunction with zfs + inplace +=20
>> rotating snapshots.
>>
>> besides the fact that we can use ssh security features to restrict=20
>> what commands can be run from remote - i am curious:
>>
>> wouldn't it be an interesting idea to have some feature/switch in=20
>> rsync, which can globally (on a per host basis) turn rsync=20
>> into=C2=A0=C2=A0"read-only" mode,
>> i.e. which makes rsync binary drop any capability of using=20
>> write/modify/ delete syscalls ?=C2=A0 maybe via some hard-coded=20
>> /etc/rsync.conf , checked on startup ?
>>
>> does this sound reasonable and wold someone find this useful , too ?
>>
>> regards
>> roland
>>
>>
>
>
--------------s0XHZDv3q6ZHIa4J4b7CDPXf
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html>
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF-=
8">
</head>
<body>
<p>thanks,=C2=A0<br>
<br>
i have to admit i have underestimated rrsync.=C2=A0 looks like a
powerful tool, and testing looks quite promsing.=C2=A0<br>
<br>
it seems i need to do only minimal changes to our backup
solution.=C2=A0<br>
<br>
unfortunately, rrsync is not available on some platforms like
macos, not even homebrew rsync 3.4.1 does bundle it (yet).<br>
<br>
regards<br>
Roland<br>
<br>
</p>
<div class=3D"moz-cite-prefix">Am 08.04.26 um 18:22 schrieb Kevin Korb
via rsync:<br>
</div>
<blockquote type=3D"cite"
cite=3D"mid:[email protected]">You
can do this by restricting the ssh key to rrsync (comes with rsync
in the contrib dir).=C2=A0 It has a read only and a write only mode.=
=C2=A0
If the path you give it is / then it is pretty much transparent
unless one of those options is also used.
<br>
<br>
Otherwise, you can use the rsyncd over ssh setup which is kinda
ugly and would require the same forcing method to not just be
optional.
<br>
<br>
On 4/8/26 12:18, RolandK via rsync wrote:
<br>
<blockquote type=3D"cite">Hello,
<br>
<br>
we are using rsync mostly exclusively for packup purpose in
"pull mode" , run via script from a central backup server.
<br>
<br>
for that, we typically have allowed remote root login via ssh
key.=C2=A0 rsync from the backup server pulls data from all hosts =
to
be backed up via ssh/rsync remote pipe.
<br>
it's running great for years in conjunction with zfs + inplace +
rotating snapshots.
<br>
<br>
besides the fact that we can use ssh security features to
restrict what commands can be run from remote - i am curious:
<br>
<br>
wouldn't it be an interesting idea to have some feature/switch
in rsync, which can globally (on a per host basis) turn rsync
into=C2=A0=C2=A0"read-only" mode,
<br>
i.e. which makes rsync binary drop any capability of using
write/modify/ delete syscalls ?=C2=A0 maybe via some hard-coded
/etc/rsync.conf , checked on startup ?
<br>
<br>
does this sound reasonable and wold someone find this useful ,
too ?
<br>
<br>
regards
<br>
roland
<br>
<br>
<br>
</blockquote>
<br>
<br>
</blockquote>
</body>
</html>
--------------s0XHZDv3q6ZHIa4J4b7CDPXf--
--===============3504298377539627804==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--
Please use reply-all for most replies to avoid omitting the mailing list.
To unsubscribe or change options: https://lists.samba.org/mailman/listinfo/rsync
Before posting, read: http://www.catb.org/~esr/faqs/smart-questions.html
--===============3504298377539627804==--