When you write an object under a retention, the vault refuses to delete it,
shorten it, or expire it early until the clock legitimately passes the deadline.
That refusal is not a flag an admin can turn off: it is a SPARK state machine,
proved by gnatprove to have no execution path that deletes a retained object.
It speaks S3 (point restic, Velero, Veeam, aws-cli or boto3 at it) and runs
on-prem and air-gapped with no external runtime dependency.
The control CLI and live dashboard shown above. It ships in every release and talks to the vault's plain HTTP control plane, so it needs no AWS SDK.
export DEZHAN_ENDPOINT=http://127.0.0.1:8080
dezhanctl dashboard # live TUI: health, seal state, objects, audit, scrub
dezhanctl put report --file ./q3-close.tar --mode compliance --retain 86400
dezhanctl get report -o ./out # fetch to a file
dezhanctl del report # refused while the object is retained
dezhanctl admin scrub --admin-token "$DEZHAN_ADMIN_TOKEN" # token-gated opsFour things in the trusted core are machine-checked by gnatprove on every
commit: 325 verification conditions, 0 unproved.
| Verified component | Invariant it guarantees |
|---|---|
| Retention state machine | retention may be extended, never shortened; a retained object cannot be deleted before expiry |
| Clock-integrity guard | a rewound clock cannot expire a lock; the vault seals instead of releasing |
| Append-only audit chain | every operation is hash-chained; history cannot be rewritten undetectably |
| Erasure coding | data survives drive loss and reconstructs exactly, or is quarantined, never returned wrong |
The cryptography (SHA-256/512, ChaCha20, HMAC, Ed25519) is in-tree. Design notes
and limits: docs/NOTES.md.
Standard S3 is validated against the AWS SDK (buckets, copy, multipart, versioning, presigned URLs, SigV4, Object Lock / WORM):
ALIAS="aws --endpoint-url http://localhost:8080 --region us-east-1"
$ALIAS s3api create-bucket --bucket vault --object-lock-enabled-for-bucket
$ALIAS s3 cp important.bak s3://vault/ # any size, multipart handled
$ALIAS s3 rm s3://vault/important.bak # refused until retention expiresInstall on-prem or on Kubernetes:
curl --proto '=https' --tlsv1.2 -sSf https://raw.githubusercontent.com/obsernetics/dezhan/main/install.sh | sh
kubectl apply -f https://raw.githubusercontent.com/obsernetics/dezhan/main/deploy/dezhan.yamlA vault is a single writer over durable storage; do not scale it. dezhan trades
write speed for durability, so it is slower than a plain object store on PUT.
Numbers and the dezhan-vs-Veeam comparison: bench/results/COMPARISON.md.
dezhan_server [port] [data-dir], configured by environment:
| Variable | Meaning | Default |
|---|---|---|
DEZHAN_VAULT_KEY |
passphrase the data key is wrapped under | demo key |
DEZHAN_REQUIRE_AUTH |
reject unsigned requests | unset |
DEZHAN_ACCESS_KEY / DEZHAN_SECRET |
the S3 credential | dezhanadmin / demo |
DEZHAN_ADMIN_TOKEN |
token gating /admin/* |
unset |
DEZHAN_DELETE_QUORUM / DEZHAN_APPROVERS |
four-eyes deletes | 0 / unset |
Operator and CSI samples: operator/config/samples,
deploy/csi/. Builds and proofs run in the project KVM guest; see
CLAUDE.md. Early software (v1alpha1); docs/NOTES.md
records what is deferred. Licensed under the Apache License 2.0.
