Skip to content

Repository files navigation

FrostKeep — Encrypted cold backups for Proxmox.

FrostKeep · Proxmox backups to AWS Glacier

Encrypted cold storage. A clear path to recovery.

Checks Stable release License: MIT

Get started →   ·   Recovery guide   ·   What's new


FrostKeep is an open-source backup and recovery CLI for Proxmox VE, QEMU virtual machines and LXC containers. It creates independent vzdump archives, encrypts them with rclone crypt, and uploads them to Amazon S3 Glacier Deep Archive.

Keep long-term off-site copies alongside your local backups. Guest archives use Deep Archive; encrypted host configuration and recovery metadata stay in S3 Standard, accessible without an archive retrieval wait.

Important

Validate a complete backup and a real restore on your installation before relying on FrostKeep. Keep your local backups and an independent copy of your encryption keys.

Built for the day you need your backup

Your backup should… How FrostKeep helps
Stay private Encrypts file contents, filenames and directory names before upload.
Show what's complete Checks guest coverage, upload sizes and storage classes before publishing completion; records SHA-256 checksums for recovery.
Recover one guest Retrieves an individual VM or container archive, verifies the download and restores to an unused guest ID, kept stopped.
Handle interruptions Reuses verified uploads when resuming; previews local cleanup before applying it.
Tell you when something is wrong Optional Discord, Slack or HTTPS notifications for failures and overdue backups.

Full archives, with no incremental backups or deduplication. Guest recovery requires AWS retrieval time. See storage costs and the restore workflow before choosing your schedule.

From your host to cold storage

flowchart LR
    P["Proxmox VE<br/>Guests + host settings"] --> C["rclone crypt<br/>Encrypt contents + names"]
    C --> A["Glacier Deep Archive<br/>Guest archives"]
    C --> M["S3 Standard<br/>Recovery metadata"]
    classDef source fill:#06282D,stroke:#65BCBB,color:#DDF8F5
    classDef crypt fill:#17474C,stroke:#8CE3DB,color:#DDF8F5
    classDef storage fill:#12383E,stroke:#65BCBB,color:#DDF8F5
    class P source
    class C crypt
    class A,M storage
Loading

Quick start

1. Prepare your storage. Configure private S3 and rclone crypt using the setup guide. Save your recovery keys independently.

Check the requirements
  • A supported Proxmox VE installation with root access.
  • Python 3.10+, rclone, GNU tar, zstd and setfacl from the acl package.
  • Snapshot support for included container volumes.
  • Staging space for your largest compressed dump, retained failed files and the configured reserve.

No Python packages to install.

2. Install and check. From the reviewed release directory:

sudo bash scripts/install.sh
sudoedit /etc/frostkeep/config.json
sudo chmod 600 /etc/frostkeep/config.json /root/.config/rclone/rclone.conf
sudo frostkeep backup --check

Preflight creates no backups or uploads. Existing installations: follow the migration steps.

3. Back up one guest. Replace 101 with an included guest ID:

sudo frostkeep backup 101
sudo frostkeep status
sudo frostkeep restore list

Rehearse recovery, then enable scheduling and alerts. Installation does not activate a scheduler.

Everyday commands
Task Command
Back up all included guests frostkeep backup
Review recent local runs frostkeep history
Check backup freshness frostkeep health --notify
Inspect a completed backup frostkeep restore inspect RUN_ID
Review an interrupted run frostkeep resume RUN_ID
Review local cleanup frostkeep cleanup RUN_ID

Add --execute to apply resume or cleanup plans. Subset runs do not reset freshness. FrostKeep never deletes cloud objects or starts restored guests.


About

Encrypted Proxmox VE backups to AWS S3 Glacier Deep Archive. Independent VM and LXC archives, rclone crypt, verified recovery, and optional alerts. MIT licensed.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages