Repository navigation
BackupProof v0.1.0
First release.
Added
- Install: one-line installers for the dashboard (
install.shfor Linux/macOS,install.ps1for Windows) that verify the download, install a service and print the address and a one-time setup code. Re-running upgrades in place;--uninstallremoves it. Docker imagesghcr.io/chmuzamil/backupproofandghcr.io/chmuzamil/backupproof-agent. - Backups: an encrypted, deduplicating repository format (FastCDC, keyed BLAKE3, XChaCha20-Poly1305, Argon2id) on a local disk, S3-compatible storage with Object Lock, or SFTP. Sources: files, PostgreSQL, MySQL/MariaDB, MongoDB, SQLite and commands, with logins read from Docker containers and WordPress settings.
- Restore tests in isolated sandboxes: Merkle-root comparison of the restored files, database integrity checks, row-count reconciliation, SQL assertions, and loading PostgreSQL dumps found inside backups into a test database.
- Proofs: signed in-toto/DSSE attestations, a hash-chained append-only ledger, RFC 3161 timestamps, offline-verifiable bundles and evidence packs mapped to SOC 2, ISO 27001, NIST CSF, DORA, NIS2 and HIPAA.
- Dashboard: plain-language wizards, a built-in agent ("This server"), one-line installs for other servers, discovery of what to protect, dark mode, keyboard and screen-reader support.
- Import of existing backups: GPG/OpenSSL/age-encrypted files in buckets or folders, restic, Kopia, BorgBackup, and cloud drives via rclone.
- Release pipeline: every
v*tag publishes binaries for Linux, macOS and Windows (amd64/arm64),SHA256SUMS, the installers and Docker images. CI runs tests (Linux with the race detector, and Windows),gofmt,go vet,golangci-lintandgovulncheck.
Security
- A one-time setup code protects creating the first admin account from other machines on the network.
- Restores write through an
os.Rootconfined to the restore folder and create symlinks last, so a crafted snapshot can't write files outside it. - Restore tests only restore the snapshot named in the backup proof the server verified from that item's own server, and check its content root first.
- Anything that could give control of a server is admin-only: commands and hooks, custom restore-test commands, moving items between servers, connecting servers, on-the-fly rclone remotes and the old-backup preview.
- The built-in agent never backs up, imports from or stores into the server's own data folder.
Install
Linux / macOS:
curl -fsSL https://github.com/chmuzamil/BackupProof/releases/latest/download/install.sh | sudo shWindows (PowerShell as Administrator):
irm https://github.com/chmuzamil/BackupProof/releases/latest/download/install.ps1 | iexDocker:
docker run -d --name backupproof -p 8420:8420 -v backupproof-data:/data ghcr.io/chmuzamil/backupproof:latest