Configure off-box, encrypted backups for the Cloudron server. Today, nightly box backups run (verified: 2026-09-30, 09-29, 09-14) but provider: None — they are stored on the same VPS disk (96 GB, 41% used) as everything they back up. A disk failure, a provider issue, or a botched migration would destroy: the members DB, LiteLLM Postgres (spend history, budgets, credits ledger), chat histories, git repos, email, and all app data — with no recovery path.
This becomes more acute with the planned hosting migration (issue #2): moving to a new provider with no off-site backup is the riskiest possible moment to have none.
Why does it matter?
Single point of failure currently protects the entire co-op's state
Members' chat histories and API usage records would be unrecoverable
The credits ledger (financial audit trail) lives only on this box
Choose an S3-compatible backup target independent of the app server:
Infomaniak Object Storage (Swiss, hydro-powered, employee-owned — matches the co-op's values story and would pair well with the Infomaniak hosting migration)
Alternatives: Hetzner Storage Box (cheap, EU), Wasabi, any S3-compatible
Configure in Cloudron: Settings → Backups → S3-compatible provider, set a schedule (daily) and retention (e.g. 14–30 days)
Enable backup encryption (Cloudron supports encrypted backups; the members DB and LiteLLM keys make this important)
Verify by restoring at least one app to a scratch instance once
Estimated cost: ~CHF/€ 1–5/month for object storage at our data volume (~40 GB, deduplicated likely much less).
Acceptance
Nightly backups land on external storage (verified in Cloudron UI)
Backup encryption enabled
One successful test restore of a critical app (portal or gateway)
Retention configured
Documented in co-op/docs (runbook: how to restore)
Filed from the 2026-10-01 security review. This was the top-priority finding.
## What's the idea?
Configure **off-box, encrypted backups** for the Cloudron server. Today, nightly box backups run (verified: 2026-09-30, 09-29, 09-14) but `provider: None` — they are stored **on the same VPS disk** (96 GB, 41% used) as everything they back up. A disk failure, a provider issue, or a botched migration would destroy: the members DB, LiteLLM Postgres (spend history, budgets, credits ledger), chat histories, git repos, email, and all app data — with no recovery path.
This becomes more acute with the planned hosting migration (issue #2): moving to a new provider with no off-site backup is the riskiest possible moment to have none.
## Why does it matter?
- Single point of failure currently protects the entire co-op's state
- Members' chat histories and API usage records would be unrecoverable
- The credits ledger (financial audit trail) lives only on this box
- Migration risk (issue #2) compounds it
## How might it work?
1. Choose an S3-compatible backup target independent of the app server:
- **Infomaniak Object Storage** (Swiss, hydro-powered, employee-owned — matches the co-op's values story and would pair well with the Infomaniak hosting migration)
- Alternatives: Hetzner Storage Box (cheap, EU), Wasabi, any S3-compatible
2. Configure in Cloudron: Settings → Backups → S3-compatible provider, set a schedule (daily) and retention (e.g. 14–30 days)
3. Enable backup encryption (Cloudron supports encrypted backups; the members DB and LiteLLM keys make this important)
4. Verify by restoring at least one app to a scratch instance once
Estimated cost: ~CHF/€ 1–5/month for object storage at our data volume (~40 GB, deduplicated likely much less).
## Acceptance
- [ ] Nightly backups land on external storage (verified in Cloudron UI)
- [ ] Backup encryption enabled
- [ ] One successful test restore of a critical app (portal or gateway)
- [ ] Retention configured
- [ ] Documented in co-op/docs (runbook: how to restore)
*Filed from the 2026-10-01 security review. This was the top-priority finding.*
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What's the idea?
Configure off-box, encrypted backups for the Cloudron server. Today, nightly box backups run (verified: 2026-09-30, 09-29, 09-14) but
provider: None— they are stored on the same VPS disk (96 GB, 41% used) as everything they back up. A disk failure, a provider issue, or a botched migration would destroy: the members DB, LiteLLM Postgres (spend history, budgets, credits ledger), chat histories, git repos, email, and all app data — with no recovery path.This becomes more acute with the planned hosting migration (issue #2): moving to a new provider with no off-site backup is the riskiest possible moment to have none.
Why does it matter?
How might it work?
Estimated cost: ~CHF/€ 1–5/month for object storage at our data volume (~40 GB, deduplicated likely much less).
Acceptance
Filed from the 2026-10-01 security review. This was the top-priority finding.