Showing posts with label secure. Show all posts
Showing posts with label secure. Show all posts

Tuesday, December 3, 2013

Copying key pairs to your bastion host

When using a bastion host to protect your Oracle database from anyone on the internet getting into your database instance, you will need to copy the 1024-bit SSH-2 RSA key to your bastion EC2 instance.  This is can be done using Linux secure copy (SCP):
scp -i /Users/tom/EC2KeyPairs/AWSThreeDayIAM.pem DBSysOPS.pem ec2-user@54.22.37.178:~/.

Where:
1. -i /Users/tom/EC2KeyPairs/AWSThreeDayIAM.pem : Is the key to the bastion host.
2. DBSysOPS.pem is the key file for your Oracle database server.
3. ec2-user@54.22.37.178:~/. is your EC2 instance and file location where the key file will be copied.

Thursday, March 7, 2013

AWS EC2 Oracle Database backup

The two most common approaches for backing up Oracle databases hosted on EC2/EBS:  
1. The Oracle Secure Backup Cloud Module allows Oracle's Recovery Manager (RMAN) to backup/restore directly to/from S3.  https://aws.amazon.com/backup-storage/gsg-oracle-rman/ 
2. DBAs can put their tablespaces in hot backup mode, issue EBS snapshots using the EC2 CLI (http://docs.aws.amazon.com/AWSEC2/latest/CommandLineReference/OperationList-cmd.html), and then take the Oracle database out of hot backup mode as soon as the EC2 EBS snapshot API call returns.  While in hot backup mode, Oracle logs the full block images to the online and archived redo logs. There is a write up here on how this works:

Tuesday, February 12, 2013

Oracle Secure Backup restore

A benchmark test using OSB, a DBA, was able to restore 3.8 terabytes in 2.5 hours over gigabit Ethernet. This amounts to 25 gigabytes per minute, or 422MB per second. This 2.5 hours using OSB and S3 compares to, conservatively, 10-15 hours that would be required to restore from tape.