So instead I have to use restic, which re-implements many features of ZFS and this also feels wrong.
So instead I have to use restic, which re-implements many features of ZFS and this also feels wrong.
We support encrypted zfs[1][2][3] and raw-send, etc.
The pricing is the same but there is a 1TB minimum because we need to give you your own VM (bhyve) and we have to burn an ipv4 address for you, etc.
[1] https://www.rsync.net/products/zfs.html
[2] https://arstechnica.com/information-technology/2015/12/rsync...
[3] https://www.servethehome.com/automating-proxmox-ve-zfs-offsi...
(you could route the ssh traffic similarly based on login)
Is this still true for these special ZFS enabled accounts?
My solution to the `zfs destroy` risk is to make my backups pull-based, where rsync.net connects inbound to my production server, and rsync.net specifies the necessary commands on the production box to grab the raw encrypted streams. That eliminates the ability of an attacker that is on the production server to run arbitrary commands at rsync.net.
There is still a small risk of data destruction if an attacker gets your rsync.net credentials, but those can be protected via off-line storage and secured workstations, which works pretty well.
I've seen several people report using OpenZFS encryption on FBSD on various mailing lists, so I'm 95% sure it's not secretly broken on there.