Repository navigation
Backfort v1.2.0 — Docker, Kubernetes & Safer Recovery
Backfort now runs as a containerized backup job or a Kubernetes workload, while keeping the same recovery-first approach: explicit sources, verified bundles, independent copies, and staged restores.
This release adds Docker distribution, Helm deployment for PVC-file backups, expanded deployment documentation, and an important fix for symbolic-link recovery.
🐳 Docker distribution
- Added a Debian-based, multi-stage Docker image with GNU tar and the tools needed for compression, encryption, signing, cloud storage, and Docker Compose integration.
- Added a hardened Compose deployment example with read-only configuration and source mounts, persistent state and working storage, a read-only root filesystem, and privilege-escalation protection.
- The default command is
doctor. Backfort remains a one-shot CLI—not a daemon or an in-container scheduler. - Root-capable execution supports ownership and metadata recovery. A narrower non-root files-only deployment is documented.
The release workflow now builds and smoke-tests linux/amd64 and linux/arm64 images before publishing to GHCR. It includes OCI metadata, build provenance, SBOM generation, immutable exact-version tags, and moving major/minor/latest aliases.
Optional Docker Hub publication is enabled through the DOCKERHUB_USERNAME and DOCKERHUB_TOKEN repository secrets.
☸️ Kubernetes deployment
Added a Helm 3 chart for Kubernetes 1.31+:
- Explicit, read-only source PVC mounts.
- Persistent state and a shared Backfort lock.
- Local backup PVCs or offsite destinations through rclone.
- ConfigMap configuration and references to existing Secrets.
- Backup and prune CronJobs, suspended by default.
- Manual Jobs for diagnostics, full verification, and staged recovery.
- Single-Pod execution, bounded deadlines, termination grace periods, and no automatic retries.
- Guardrails against source, state, backup, and recovery claim overlap.
- Manual restores restricted to an explicit recovery PVC and a safe target beneath
/restore.
The default deployment grants no Kubernetes API token, RBAC permissions, Docker socket, hostPath mounts, or privileged-container access. An optional non-root profile is included.
Validate the configuration, create a backup, and complete a recovery drill before enabling schedules.
🔧 Symbolic-link recovery fix
Fixed file-source archive transforms incorrectly adding the internal data/ prefix to symbolic-link targets. This could produce broken links after an otherwise successful restore.
New backups preserve relative, absolute, and dangling symbolic-link targets when follow_symlinks: false. Archive member names and hard-link references retain the required internal prefix, and explicit dereferencing remains supported.
Existing backup bundles are not rewritten automatically. Create a fresh recovery point and inspect symbolic-link targets when restoring older backups.
🧪 Testing and automation
- Added Docker-image smoke tests covering diagnostics, backup, full verification, staged restore, and invalid configuration.
- Added Helm rendering and negative configuration tests.
- Added a dedicated Kubernetes workflow with real-image integration in a disposable kind cluster.
- Kubernetes integration covers metadata recovery—including ownership, ACLs, xattrs, and SGID—read-only sources, cross-Job locking, nonempty-target refusal, invalid configuration, pruning, and non-root operation.
- Added symbolic-link and hard-link regression tests, including explicit dereferencing.
- Extended Dependabot configuration with Docker base-image updates.
📚 Documentation
Expanded README and Wiki guidance for Docker and Kubernetes deployment, persistent storage, Secrets, scheduling, recovery, and troubleshooting.
Added ready-to-adapt Kubernetes values examples for local PVC storage, rclone destinations, non-root execution, and isolated restore Jobs, plus architecture decision records and updated project operating instructions.
Upgrade notes and scope
The native CLI, Backfort YAML schema, and recovery-bundle format remain unchanged.
Kubernetes support covers files on explicitly mounted PVCs, not whole-cluster backup. It does not provide Kubernetes resource discovery, CSI snapshot orchestration, or native database dumps from Pods.
Reading a live database PVC is not an application-consistent backup. Prepare a consistent export or clone through an application-controlled procedure.
Review storage-driver permissions, locking semantics, RWO/RWOP access modes, and working-space capacity before deployment. CronJob concurrency policies do not coordinate separate CronJobs or manual Jobs; the persistent Backfort lock remains essential.
Docker Compose database jobs continue to require a deliberately granted host Docker socket and matching project paths. They are not Kubernetes-native database adapters.