• 2 Posts
  • 407 Comments
Joined 1 year ago
cake
Cake day: June 24th, 2024

help-circle









  • philpo@feddit.orgtoSelfhosted@lemmy.worldBackups of Backups
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    11 days ago

    Basically:

    • Small proxmox node (Zimablade) that basically does only operate a Proxmox Backup Server for local clients and fast backup.

    • Offsite ZFS send to a VPS I operate for that purpose. As well as Proxmox Backup Server for VMs,etc. Basically meant as a fast recovery option. (Layer7)

    • Offsite S3 storage backup to a different provider from above. Meant for a medium term backup. (Hetzner and IONOS)

    • Portable HD: I have two different portable HDs. One is hooked up to the Backup server, the other one is in a lock box in my banks safe. The “connected one” does a weekly backup (and is switched off in between). Once in a while (around 6 to 12 weeks, with 12 weeks being the hard maximum) I take the active one to the bank and both drives switch places. That provides a full backup. (WD My Book and Seagate Expansion - the differrnt manufacturers are intentional)

    • Last line of defence: The real real important things (photos of life events-weddings,etc.- important documents,Password DBs) etc.) get burned on a M-disc Archive blue ray. They are also in the bank safe and at a secure third location. They are more meant for “shit hit the fan and I might not be there anymore,but maybe the kids want these”. Additionally they provide a defence against encryption viruses - write once reas many (WORM) has it’s advantages here.

    This is another thing to consider: Have detailed descriptions for others how to retrieve your data in case something happens. I operate a private wiki (on an external server) that also gets saved into the M-Discs that has step by step instructions, as they might need to be followed by someone not that tech adept. (Like my In-Laws in case both my wife and I perish.), have notes in my password DB (Vaultwarden, which has a digital heritage/emergency access function and is also exported), in the vault, and a note in my will notifying people about this.

    Edit: And: Test your recovery. Almost every data loss I have witnessed in the last years was a recovery problem. Missing encryption keys, data structure issues, etc. I have seen them all. Personally I try to recover a random file (as in: A script tells me which one) twice a year from every method and try a full recovery of each method at least once six month after introduction. Thst being said: It’s nice to have encrypted backups,but that doesn’t help if you can’t find the keys/the software does no longer exist,etc. Currently a LOT of my clients have the same problem: They use Tandberg RDX for backup, including WORM. Now, Tandberg has gone bust and it’s not that unlikely that yhey won’t be able get another RDX drive in 5 or 10 years. Or 20. Which is the legal requirement for some official files here. Well,fuck. They needed to get additional drives asap when the bankruptcy became official.

    Friends have used ancient LTOs and now face the same issues - LTOs are not downwards compatible. (That’s why I use “common” technology. It’s extremely likely that I will be able to find a spare BD drive in 20 years,etc.)



  • Massive massive trade alleviations - the fact that Canada could export to a economic zone of 340 Million people (realistically more as a lot of smaller economies are linked to the Euro, arouns 500 -700 Million depending on how strict your criteria are).

    The direct GdP of that zone is roughly 16.4 Trillion USD, the third largest economic zone after the UD and China but with a much less centralized wealth distribution. (And 17.5 Trillion if you add the closely related economies.

    Why is this important/good? Because then Canadian companies could do trade with long term commitments without having to factor in the risk of currency fluctuations. Additioally the economy would be much less prone to foreign pressure on it’s currency.

    For Canada this would be especially interesting: They import large amounts of natural ressources, import industry goods but are also far enough away that some drawvacks like outsourcing to lower income areas are not as likely.

    And from the EU perspective the additional “stable customer” and “stable supplier” would be golden.


  • You are more than welcome to join, if you ask me(and basically everyone I know).

    After all you are the country with the closest sea border to France* and also have a close maritime border to Denmark*.

    (*: Well, these parts are not part of the EU,yes,but that’s hardly youe fault).

    We would be very happy to have you.

    And beside the whole “free trade” stuff it also has another often overlooked one: The EU is also a defence alliance (the terms are actually stronger than NATO’s but the later takes precedence) especially in times when NATO is,well, unreliable, that might be a big plus as well.






  • Yeah,does not reflect the actual situation.

    Currently especially their SDN capable stuff (Omada) is far better than e.g. the Ubiquiti stuff - we are relatively surprised by the build quality for the bucks you pay,tbh. (And unlike Ubiquiti they can be run stand alone and SDN).

    Not defending their China-issues btw, we absolutely recommend to all our clients that they put a OPNsense in front of it. But it does it job and has it’s place in small businesses. (And tbh,their Wifi gear is good enough that I have seen it in fairly large deployments)

    Sadly there’s not too much alternative for that sector atm.


  • Yeah, especially router wise I tend not to recommend them as well, but we widely use OPNsense as FWs now. Switching wise they are good and tbh, their track record got much better. (And everyone elses got worse, looking at you,Forti)

    We tend to recommend Omada for smaller clients that would otherwise use ubiquiti (their track record is…far worse) and simply put a OPNsense in front of it. These are small healthcare establishments - the alternative is often far worse (cousin John doing the network or some antique Zyxel the local IT shithead service sold them as new) and with the OPN we can do due dilligence IT security wise.