Add write-only mode
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 28/100
Research direction
Start by tracing how rest-server handles the existing --append-only mode and access to the data subdir. Check how restic backup reads from a repository and how --force changes that behavior. Done means a write-only option prevents read access while still allowing the intended backup requests, with appropriate tests for both permitted and denied access.
Written by the indexing model from the issue text.
Description
Output of rest-server --version
rest-server 0.9.7 compiled with go1.10 on linux/amd64
What should rest-server do differently?
Currently we've --append-only mode that tries to minimize risks of access to repo by attacker from compromised host.
So there is no way to remove data from repo. But there is still a way to 'restore' whatever attacker wants from --append-only repo.
It would be great to also have --write-only like option to completely disable read access to data subdir. I know that restic may need it during backup, but it's actually not strictly required: usually parent snapshot is already cached. And when not cached, it's still possible to perform slower backup with --force option that don't need that snapshot at all. Ideally restic should be aware of such write-only repo and automatically fallback to --force but not necessary.
- Dominant language
- Go
- Stars
- 1.5k
- Forks
- 179
- Avg merge
- 15d 9h
- Merged PRs (30d)
- 2
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from restic/rest-server
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
restic/rest-server#389 ·
-
state: need feedback
Difficulty 3/5 1-2 days Newbie friendliness 55/100
restic/rest-server#391 · 5 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
restic/rest-server#390 · 1 comment · 1 reaction ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
restic/rest-server#384 · 2 comments ·
-
Exit after configurable idle period for servers with limited RAM or are off/suspended when unusedOpen
Difficulty 4/5 3-5 days Newbie friendliness 50/100
restic/rest-server#383 · 2 comments ·
All issues in restic/rest-server
Similar issues
-
automation models
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
txn2/mcp-data-platform#1984 ·
Maintainers usually reply within 1 day
-
agentic-workflows
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
kind/docs prio/P2
Difficulty 1/5 Under an hour Newbie friendliness 95/100
agent-substrate/substrate#1986 ·
Maintainers usually reply within 1 day