Repository navigation
π Nimbus Backup v0.4.1
π Signed by RDEM SYSTEMS.
NimbusBackup.exe, its service andNimbusBackup.msiare Authenticode-signed (Azure Artifact Signing): Properties β Digital Signatures shows RDEM SYSTEMS. SmartScreen may still warn on a new release until its reputation is established: check that the publisher is RDEM SYSTEMS, then More info β Run anyway. The command-line tools are not signed yet. Antivirus false positive? See why this happens and how to verify the download Β· π«π· FR.
π What's in this release
Second re-merge with upstream (tizbac/proxmoxbackupclient_go, October
2026): the fork is rebuilt on upstream's current code plus the fork patch
series (see patches/README.md). Upstream's own client-side encryption
replaces the fork's unreleased one.
Added (from upstream)
- Client-side encryption, compatible with
proxmox-backup-client: AES-256-GCM
chunks and blobs, keyed chunk digests. Compatibility is verified in CI on every
build against a real PBS: a folder encrypted by Nimbus Backup with a key created
byproxmox-backup-clientis restored by the official client with the same
key (and refused without it), and an encrypted disk backup made by the official
client is read back by Nimbus Backup. The GUI points each PBS server at an
unprotected key file (create one or pick an existing one, fingerprint shown);
the CLIs also take passphrase-protected key files (-keyfileand
-keyfile-passphrase, or prompt). Restore, search, browse and the NBD server
decrypt; the patched Clonezilla ISO restores encrypted disk backups. - Linux packages (Debian, Fedora, Arch) with a systemd service, a Running jobs
tab (progress, ETA, cancel), a PBS server choice per job, disks pinned by
identity (drive letters shown), host/VM choice for machine backups, NTFS and
POSIX ACL restore, several directories per CLI run, launch-time elevation,
and a real-PBS end-to-end test suite in CI.
Added
- Several folders backed up in parallel (issue #6): GUI setting "Folders backed up in parallel" (one-shot and scheduled backups) and
-parallel N/"parallel"inproxmoxbackup-directory. No maximum; CPUs / 4 is recommended. Each folder stays its own backup group. - One VSS snapshot for a whole multi-folder backup, one after the other or in parallel: the snapshot is taken once for every folder before the first upload, with one shadow copy per volume, so all the folders of a volume are frozen at the same instant (each folder used to get its own snapshot at its own turn). Same on Linux, one snapshot per block device.
- Exclusions in
proxmoxbackup-directory(issue #4):-exclude PATTERN(repeatable),-exclude-from FILE(one pattern per line,#comments) and"exclude"/"exclude-from"in the JSON config, with the GUI's pattern syntax. - Paper key: print an encryption key as a page with its QR code, in the
format ofproxmox-backup-client key paperkey(the QR code holds the key
file), optionally protected by a passphrase; the key and its QR code can also
be shown in the GUI. Import a key from text or a QR code rebuilds a key
file from a scanned QR code, a paper key or a pasted key file. A protected
key is unlocked with its passphrase and saved without one (the GUI only
uses unprotected key files): the import says so, keep that file as safe as
the key itself. - Disk backups restore in Proxmox VE as a VM that matches the machine. The
VM config stored with "vm" snapshots is generated from the real machine:
logical CPU count, RAM, firmware (UEFI or GPT boot disk βbios: ovmf), guest
OS type (Windows version/edition βwin11/win10/win8/win7β¦, Linux β
l26), one NIC per physical adapter keeping its MAC (e1000eon Windows,
virtioon Linux), the SMBIOS identity (UUID, manufacturer, product,
serialβ¦) and the boot disk. The VM description lists what to add before the
first boot (EFI disk, with pre-enrolled keys when Secure Boot was on; TPM
state; "Unique" MACs if the source is still online). Every machine backup
also stores these facts inmachine-info.json.blob.
Fixed
- A busy VSS no longer wipes every shadow copy on the host. When VSS reported that another shadow copy was being created, the client ran
vssadmin delete shadows /alland restarted the VSS service, destroying restore points and other tools' snapshots. It now waits and retries (30 s, 60 s, 120 s), then fails with an explicit message. And the startup cleanup no longer deletes a shadow copy another Nimbus process is still reading (e.g. a CLI backup running while the GUI starts): each run holds an in-use marker for its shadows. - Disk backups never reached PBS, and scheduled ones could still show "Backup terminΓ©" (issue #9). Every machine backup failed at its last step (
execute VM config template: ... can't evaluate field VMID), so no snapshot was committed; the VM config is now generated by upstream's code, covered by tests. And in 0.4.0 a GUI started before the service ran its own scheduler, which recorded a scheduled job as successful as soon as the service had accepted it, without waiting for the result. Only the service runs scheduled jobs now, and it records the real outcome (a failure shows as failed). - A backup run by the service stayed on "Starting backup..." in the GUI (issue #2): the service now reports its progress and completion to the GUI (upstream's progress dispatch), and the status bar no longer hides itself mid-run.
- The service ignored the PBS server selected for a directory backup: the
/backuproute swapped it with the compression level, and the service always used the default PBS. Split backups now pass the selected server too. - Maximising the window filled the screen only up to 1680Γ1008 (issue #1): the window maximum size is gone, so "maximise" fills the screen; on small screens the startup window is shrunk to fit instead.
- Encrypted backups made by
proxmox-backup-clientnow restore. The official
client compresses then encrypts chunks by default (ENCR_COMPRblobs), which
could not be decoded. Our encrypted chunks and blobs are now compressed the
same way when it helps, instead of being uploaded uncompressed (less storage
and bandwidth for encrypted backups). - Error messages now show the reason returned by PBS instead of "authentication
failed" for every refusal, e.g.PBS refused the backup (HTTP 400): backup owner check failed (β¦). 401 and 403 keep their own wording, and the raw
response headers no longer appear in the message. - "VM" machine backups need a numeric VM ID, but reused the Backup ID field,
pre-filled with the hostname. In "VM" mode the form now has its own Proxmox
VM ID field (100β999999999, remembered per machine, the Backup ID stays
intact), validated before the backup or scheduled job starts; editing a
scheduled machine job restores its VM ID and disks. - A machine backup with several disks is no longer split into one snapshot per
disk. - Standalone GUI upgraded from Nimbus Backup <= 0.3.0: its settings are now
also picked up from the legacyProgramData\NimbusBackupfolder. - Scheduled jobs declared in
config.json(unattended deployment) are
validated like jobs saved from the GUI; an invalid one is logged and skipped.
π SHA-256 checksums
Verify with Get-FileHash <file> -Algorithm SHA256 (PowerShell) or sha256sum -c SHA256SUMS.txt.
b9de99cc04d5c129f7ad4650dcc1562fb0cce43a7f7219a674c4ed9be0d3b985 NimbusBackup-v0.4.1-windows.zip
01d0b028e0105b89a1a2772a668cd994387a9b8ab1757bcda0b1013284d681b6 NimbusBackup-v0.4.1.exe
7e415b3bc169d08045afb832800365b7183a8046726062c07dab48420a149915 NimbusBackup-v0.4.1.msi
01d0b028e0105b89a1a2772a668cd994387a9b8ab1757bcda0b1013284d681b6 NimbusBackup.exe
7e415b3bc169d08045afb832800365b7183a8046726062c07dab48420a149915 NimbusBackup.msi
acb56555efb4efef4fcd034d115a4136b2015a51df1baee2c8213bdca7b7925c nimbus-backup-cli-v0.4.1-linux.tar.gz
d9a5e3e8d99d9d7036eda344db5a273fb7d955cdce4cad70a2a50742ef4a4674 nimbus-backup-cli-v0.4.1-macos.tar.gz
5d42b6b3aa2503d985c87206e1f75fef6806b1dd55c29d9fd64cfb8409ff3620 nimbus-backup-cli-v0.4.1-windows.zip
π‘οΈ VirusTotal reports β 0 detections
NimbusBackup-v0.4.1.exeβ cleanNimbusBackup-v0.4.1.msiβ clean
Proxmox Backup Client β Status & notes
Per-version changes are listed in the βChanges sinceβ¦β section of each release (above) and in CHANGELOG.md. This page describes the stable state of the product.
π¦ Available builds
NimbusBackup.msi (installer β recommended for production)
- β Windows service: starts automatically at system boot
- β Persistent admin privileges: the service runs as LocalSystem (VSS guaranteed)
- β Scheduled backups: run automatically, even after a reboot
- β Clean uninstall: full cleanup via Control Panel
NimbusBackup.exe (standalone)
- β Manual and scheduled backups: work as long as the app is running
- β No persistence across reboots: no service β prefer the MSI in production
- π‘ Use case: one-off backups or testing
β Features
Backup & restore
- One-shot (immediate) and scheduled (configurable time) backups
- Split a first backup of a large volume into smaller, resumable backups (opt-in)
- VSS (Volume Shadow Copy) for consistent backups: one snapshot for a whole multi-folder backup, one shadow copy per volume
- Several folders in parallel (no maximum; recommended: CPUs / 4)
- Client-side encryption compatible with
proxmox-backup-client(developed upstream by Tiziano Bacocco), paper key with QR code - File/folder exclusions + automatic exclusion of Windows system folders (System Volume Information, $RECYCLE.BIN, pagefile.sysβ¦)
- Snapshot restore and browsing (fast catalog reads)
- Robust long-running backups (30 s keep-alive, validated on 11 h+ backups)
- Multi-server PBS support
Interface & configuration
- Wails GUI (Go + React), in English, French, Italian, German and Polish
- Backup history and re-run of failed jobs
- Progress bar with statistics, minimize to tray
- PBS configuration with connection test, certificate fingerprint pinning (TOFU) and namespaces
π Known issues
- βΉοΈ Signed since 0.4.1: the GUI, its service and the MSI are signed by RDEM SYSTEMS; SmartScreen may still warn until the reputation of a new release is established. The command-line tools are not signed yet.
- βΉοΈ Upgrading from <= 0.3.0: the configuration folder is merged from
ProgramData\NimbusBackupintoProgramData\ProxmoxBackupClienton first start (copied once, nothing overwritten, old folder kept). β οΈ The standalone .exe does not persist across reboots β use the MSI in production.β οΈ The exclusion format is not validated on input.
Tested with NimbusBackup
This release has been tested against NimbusBackup managed PBS β π¬π§ EN Β· π«π· FR.
RDEM Systems β π¬π§ EN Β· π«π· FR
Nimbus Backup β Fully managed Proxmox Backup Server datastores β π¬π§ EN Β· π«π· FR