Repository navigation
Releases: CruxExperts/BestBackup
Releases · CruxExperts/BestBackup
Release list
v2.0.0-alpha.1
Keep a copy close. Keep a copy elsewhere. This preview introduces the
restic-centered bbackup 2.0 workflow for Linux administrators and small teams.
Backblaze B2 and Amazon S3 are supported repository destinations and restore
sources; provider-specific recovery-protection qualification is still underway.
Added
- Encrypted local restic capture, explicit snapshot replication with independent
passwords, full-data repository checks, and verified restore into new directories. - Transactional SQLite capture, native PostgreSQL and locked MySQL/MariaDB
exports, and PostgreSQL restore into a new database using snapshot-time metadata. - A mouse and keyboard Textual dashboard sharing the same operations service
as the strict version-2 JSON CLI, with generated schemas and agent discovery. - Bounded subprocesses, real process-group cancellation, private operation state,
repository serialization, and explicit reconciliation of interrupted mutations. - Signed, GnuPG-encrypted recovery kits and exact historical S3 object-version
reconstruction that can operate without the original host ledger. - Native Backblaze B2 inspection using the pinned vendor Python SDK, with SDK
backoff inside a bounded cancellable process and no persisted credentials. - A shorter README, a fresh visual identity, a practical documentation hub,
local-to-cloud recipes, and clear recovery and release boundaries.
Fixed
- Legacy uploads now report partial failures truthfully and preserve local
artifacts when all required remote uploads have not succeeded. - Legacy filesystem restore rejects escaping source paths and returns structured
failures for unavailable destinations or failed copies. - Legacy dashboard terminal restoration and operation finalization are more
reliable; unattended backups no longer assume an interactive terminal.
Changed
- S3 inventory and recovery use bounded standard SDK retries with five total
attempts per request. Native B2 inspection delegates protocol retries to b2sdk. - Dependencies are locked; urllib3 is updated to 2.8.0 for the maintainer's fixes.
- The optional Google Drive OAuth client requires oauthlib 4.0.0 or newer,
incorporating the upstream fixes for CVE-2026-49264 and CVE-2026-49265. - Preview features remain under
bbackup production. Existing 1.x commands and
configuration remain available while their replacements are completed.
Release status
This is an alpha prerelease, not the production-qualified 2.0 release.
Local restic and Garage S3 capture → copy → check → restore cycles passed.
Database-client fixtures, independent recovery drills, and headless dashboard
checks passed; live B2/AWS and native database qualification remain outstanding.
Docker recovery, retention enforcement, complete UI flows, and Ubuntu packages
are still under development. See implementation status.
v1.8.6
Added
- Optional secure Google Drive OAuth setup through
bbman auth-gdrive, including dry-run and JSON output, redacted diagnostics, and headless SSH callback guidance. The helper configures My Drive remotes; live Google authorization is not exercised in automated tests. - A repository-wide GitHub Markdown standard, capabilities reference, review checklist, provenance manifest, and CI/pre-push validator now govern public documentation.
Changed
- Pytest uses bounded xdist auto-workers and isolated Docker integration resources to reduce runtime without overcommitting shared hosts.
- CI and release validation install checksum-pinned restic 0.19.1 so native snapshot lifecycle tests cannot silently skip.
Fixed
- Snapshot runs apply configured active-repository and include-path retention through scoped, conjunctive tag selectors.
- Snapshot retirement and purge planning isolate snapshots by host and repository, reconcile removed IDs without losing history, and use exact ledger snapshot IDs.
- Generated schedule services share a user-runtime lock so backup, maintenance, and verification jobs do not overlap.
- Google Drive configuration handles rclone continuation responses, bounds continuation calls, loads optional support lazily, and defaults to My Drive without exposing shared-drive selection.
Security
- Removed the unused GitPython dependency and its
gitdbandsmmaptransitive packages, eliminating the repository's exposure to their known advisories. - Raised the
cryptographydependency floor to 50.0.0, the first release fixing GHSA-g6cj-pr64-35w5 / CVE-2026-69247, and made health/setup checks reject older or prerelease versions.
v1.8.5
Added
- Native restic snapshot profiles with commands for
snapshot init,snapshot run,snapshot check,snapshot restore,snapshot retire,snapshot purge-plan, andsnapshot schedule. - Local restic integration coverage that initializes a temporary repository, snapshots a Git repo, checks the repository, restores content, and verifies the state ledger snapshot ID.
- Profile schedule rendering for daily backup, weekly non-destructive maintenance checks, and monthly verification checks with configurable
verification_read_data_subset. - Generated CLI skills metadata for the native snapshot command surface.
Changed
- Snapshot schedule units now render matching service/timer pairs, use
/usr/bin/env bbackup, and escape systemd percent specifiers. - Snapshot commands now accept required options from
--input-jsonconsistently for agent-driven workflows. - Retired-repo destructive cleanup remains dry-run-first/manual through
snapshot purge-plan. - The pytest
integrationmarker now covers external-tool integration tests such as Docker and restic.
Fixed
- Google Drive rclone snapshot profiles without a dedicated
client_idremain rejected by default, whileallow_default_rclone_drive_client: trueprovides a conservative profile-local opt-in. - Non-dry snapshot operations now enforce profile safety preflight checks before running restic.
- Git repo identity no longer changes on every commit; legacy head-derived repo IDs migrate safely, and unknown active same-path identity conflicts block history merging.
list-backupsand restore dry-run planning no longer initialize Docker for file-only planning paths.- Restore dry-runs now validate filesystem destination and multi-filesystem constraints before returning a success plan.
v1.8.4
Security
- Raised the
cryptographyruntime dependency floor to48.0.1to pick up patched OpenSSL wheels for GHSA-537c-gmf6-5ccf.
Changed
- Release publishing now uploads only the bbackup wheel and source archive artifacts.
v1.8.3
Added
- Backup runs now include a compressed
metadata.tar.*archive of Docker config and network metadata when those metadata directories exist.
Changed
- CI now tests Python 3.12, 3.13, and 3.14 and uses
actions/checkout@v7. - Ruff release checks now include tests and the generated CLI skills script.
- TUI headers now display the package version instead of a hardcoded
1.0.0. - Username-only GitHub public-key lookup now uses standard repositories only; explicit Gist IDs remain supported.
Fixed
restore --all --dry-runnow discovers containers, volumes, networks, and filesystem targets from solid archive backup files.- Non-dry-run filesystem restores now reject missing or ambiguous destinations before any restore mutation runs.
v1.8.2
Changed
- Simplified the GitHub install and redeploy documentation around the single
uv tool install --force git+https://github.com/CruxExperts/best-backup.gitcommand. - Moved the sudo
UV_TOOL_DIR/UV_TOOL_BIN_DIRdeployment form out of the README and Quickstart path, keeping it only as an advanced system-wide install option inINSTALL.md.
v1.8.1
Fixed
- Solid archive backups now remove the expanded staging directory after the archive is created, so local solid mode leaves a single
.tar.*artifact instead of both the archive and the unpacked backup tree. - Rclone uploads of solid archive files now use
rclone copytoto create one remote file, instead ofrclone copycreating a destination folder for the file.
v1.8.0
Added
backup_manifest.jsongeneration for non-cancelled backups, including schema version, source scope, filesystem source paths, volume artifacts, item results, errors, file sizes, and SHA-256 hashes.- Restore-time manifest verification that fails before mutation when files are missing, changed, unlisted, or outside the backup root.
- Temp-to-final promotion for local, SFTP, rclone, and solid-archive writes so partial uploads are not exposed as completed backups.
- GitHub-facing documentation graphics and Mermaid diagrams for the backup pipeline and release/readiness flow.
Changed
- Successful encrypted backups now remove plaintext staging and report encryption based on actual output state.
- Rclone remote listing now uses top-level
lsfoutput so retention targets backup directories and archive files instead of individual nested files. - Existing Docker volume restore uses a staging-volume copy preflight before removing the original volume.
- Direct
--pathsand configured filesystem sets now reject duplicate target names that would overwrite each other. init-encryptionnow rejects unsupported generated-key passwords before creating key directories.- Generated asymmetric keys are RSA-4096 only; ECDSA is no longer advertised as a backup encryption option.
Fixed
- Docker volume backup and restore now propagate failed
docker cpreturn codes. - Failed Docker volume backup attempts remove incomplete local volume artifacts.
- Solid archive failures preserve an existing final archive and remove partial files.
- Partial backup JSON no longer reports encrypted output when encryption was skipped due to item failures.
v1.7.0
Added
- Solid archive mode: optional single compressed tarball (and optional whole-file encryption) before upload so remotes receive one file instead of many. Config
backup.solid_archiveand CLI--solid-archive/--no-solid-archive. Restore accepts a backup path that is a file: it unpacks to a temp dir, restores selected items, then cleans up. Listing and retention treat directories and archive files (e.g.backup_*.tar.gz,backup_*.tar.gz.enc) the same. Staging cleanup runs only after at least one successful upload. Seeconfig.yaml.exampleand docs/architecture.md.
v1.6.0
Added
- Rclone transfer and concurrency options: config-driven
transfersandcheckersfor all rclone operations (upload, list, size, purge). Per-remote optionalrclone_optionsand optional top-levelrclone.default_options; recommended defaults 8/8, cap 32. Seeconfig.yaml.exampleand docs/architecture.md.