BackupProof

Contributing

BackupProof is open source under the MIT license. Bug reports, fixes, documentation and new import formats are all welcome.

Ways to help

  • Report a bug in GitHub issues with your version, system and the steps to reproduce it.
  • Report a security problem privately, as described on the Security page.
  • Improve the wording. If something in the dashboard or these docs confused you, that’s a bug too.
  • Send a pull request for a fix or feature. For anything large, open an issue first so we can agree on the approach.

Set up

You need Go 1.27 or later. Optionally install restic, kopia, rclone, gpg, openssl and age to run the import tests that use them (tests skip when a tool is missing), Docker to try database restore tests, and golangci-lint v2.

git clone https://github.com/chmuzamil/BackupProof.git
cd BackupProof
go build -o bin/backupproof ./cmd/backupproof
go test ./...
./bin/backupproof server --data ./backupproof-data --listen 127.0.0.1:8420

Open http://127.0.0.1:8420 and create the admin account. The built-in server connects automatically.

Find your way around

FolderWhat’s there
cmd/backupproofThe single program: dashboard, agent and command-line tool.
internal/repo, engine, chunker, crypto, snapshotStorage format, backup, restore and cleanup, chunking, encryption, the Merkle tree.
internal/sourceWhat gets backed up: files, databases, commands.
internal/drillRestore tests and their sandboxes.
internal/proofSigned statements, the ledger, timestamps and bundles.
internal/importerConverting existing backups.
internal/serverDashboard API, scheduler, alerts and proof reports. web/ holds the dashboard (plain JavaScript, no build step).
internal/agent, protocolThe outbound-only agent and how it talks to the dashboard.
internal/e2eEnd-to-end tests of the dashboard and agent together.

Before a pull request

gofmt -l .              # must print nothing
go vet ./...
go test -race ./...     # plain go test on Windows
golangci-lint run ./...
node --check internal/server/web/app.js

CI runs the same checks on Linux and Windows, plus govulncheck.

Guidelines

  • Security first. Changes to restore paths, agent authentication, roles or proofs need a test that tries the attack and shows it fails.
  • Plain language in the dashboard. Use the existing words (“Restore test”, “Backup storage”, “Servers”) and keep technical details behind “Show technical details”.
  • Keep the dashboard CSP-clean. No inline scripts or styles, no third-party assets, and never put server data into innerHTML.
  • Don’t change storage or proof formats without a version bump and a migration note in the changelog.
  • Commit messages in the imperative (“Add Kopia import”), explaining why in the body when it isn’t obvious.