{"repo":"danieltamas/fortified","free":true,"listed":false,"github":"https://github.com/danieltamas/fortified","clone":"git clone https://github.com/danieltamas/fortified.git","description":"fortified is a deterministic backup and disaster-recovery CLI for a self-hosted server fleet — Docker containers and native/systemd-installed databases alike.","language":"Go","stars":10,"topics":["borg","borg-admin","borg-backup","borgbackup","hetzner","hetzner-cloud","hetzner-robot-api"],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"fortified A backup you haven't tried to restore isn't a backup. It's a guess. fortified is a deterministic backup and disaster-recovery CLI for a self-hosted server fleet — Docker containers and native/systemd-installed databases alike. It provisions an isolated, append-only backup destination on a Hetzner Storage Box for each server, dumps databases through their own engine (never raw file copy), archives everything with BorgBackup, and — the part almost every backup tool skips — actually restores the archive and proves it matches before it lets you rely on it. No daemon. No dashboard. No vendor lock-in. One static binary, one YAML file, and a security model built so that even a fully compromised protected server can't touch its own backup history. At a glance - Structurally append-only. The only key a protected server ever holds can push new archives — it cannot delete or overwrite old ones, enforced server-side by a forced SSH command, not client-side promises. - Verify isn't a checkbox. fortified verify restores the latest archive for real and diffs it against a recorded manifest (SHA-256 + per-table row counts). Nothing downstream trusts a backup that hasn't passed this. - Discovers before it assumes. fortified discover inspects a server over SSH — containers, databases, exposure, volume manager — and writes your config for you. It never guesses what's running. - Dual-key discipline. The one credential capable of deleting anything ( prune ) is never stored anywhere, ever","default_branch":null,"files":null,"tree":[],"storefront":"/r/danieltamas","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/danieltamas/fortified/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}