Configure off-box encrypted backups (single point of failure) #12

Open
opened 2026-10-01 15:22:34 +00:00 by inference-bot · 0 comments
Owner

What's the idea?

Configure off-box, encrypted backups for the Cloudron server. Today, nightly box backups run (verified: 2026-09-30, 09-29, 09-14) but provider: None — they are stored on the same VPS disk (96 GB, 41% used) as everything they back up. A disk failure, a provider issue, or a botched migration would destroy: the members DB, LiteLLM Postgres (spend history, budgets, credits ledger), chat histories, git repos, email, and all app data — with no recovery path.

This becomes more acute with the planned hosting migration (issue #2): moving to a new provider with no off-site backup is the riskiest possible moment to have none.

Why does it matter?

  • Single point of failure currently protects the entire co-op's state
  • Members' chat histories and API usage records would be unrecoverable
  • The credits ledger (financial audit trail) lives only on this box
  • Migration risk (issue #2) compounds it

How might it work?

  1. Choose an S3-compatible backup target independent of the app server:
    • Infomaniak Object Storage (Swiss, hydro-powered, employee-owned — matches the co-op's values story and would pair well with the Infomaniak hosting migration)
    • Alternatives: Hetzner Storage Box (cheap, EU), Wasabi, any S3-compatible
  2. Configure in Cloudron: Settings → Backups → S3-compatible provider, set a schedule (daily) and retention (e.g. 14–30 days)
  3. Enable backup encryption (Cloudron supports encrypted backups; the members DB and LiteLLM keys make this important)
  4. Verify by restoring at least one app to a scratch instance once

Estimated cost: ~CHF/€ 1–5/month for object storage at our data volume (~40 GB, deduplicated likely much less).

Acceptance

  • Nightly backups land on external storage (verified in Cloudron UI)
  • Backup encryption enabled
  • One successful test restore of a critical app (portal or gateway)
  • Retention configured
  • Documented in co-op/docs (runbook: how to restore)

Filed from the 2026-10-01 security review. This was the top-priority finding.

## What's the idea? Configure **off-box, encrypted backups** for the Cloudron server. Today, nightly box backups run (verified: 2026-09-30, 09-29, 09-14) but `provider: None` — they are stored **on the same VPS disk** (96 GB, 41% used) as everything they back up. A disk failure, a provider issue, or a botched migration would destroy: the members DB, LiteLLM Postgres (spend history, budgets, credits ledger), chat histories, git repos, email, and all app data — with no recovery path. This becomes more acute with the planned hosting migration (issue #2): moving to a new provider with no off-site backup is the riskiest possible moment to have none. ## Why does it matter? - Single point of failure currently protects the entire co-op's state - Members' chat histories and API usage records would be unrecoverable - The credits ledger (financial audit trail) lives only on this box - Migration risk (issue #2) compounds it ## How might it work? 1. Choose an S3-compatible backup target independent of the app server: - **Infomaniak Object Storage** (Swiss, hydro-powered, employee-owned — matches the co-op's values story and would pair well with the Infomaniak hosting migration) - Alternatives: Hetzner Storage Box (cheap, EU), Wasabi, any S3-compatible 2. Configure in Cloudron: Settings → Backups → S3-compatible provider, set a schedule (daily) and retention (e.g. 14–30 days) 3. Enable backup encryption (Cloudron supports encrypted backups; the members DB and LiteLLM keys make this important) 4. Verify by restoring at least one app to a scratch instance once Estimated cost: ~CHF/€ 1–5/month for object storage at our data volume (~40 GB, deduplicated likely much less). ## Acceptance - [ ] Nightly backups land on external storage (verified in Cloudron UI) - [ ] Backup encryption enabled - [ ] One successful test restore of a critical app (portal or gateway) - [ ] Retention configured - [ ] Documented in co-op/docs (runbook: how to restore) *Filed from the 2026-10-01 security review. This was the top-priority finding.*
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: co-op/support#12