Skip to content

Repository files navigation

dezhan

Write-once backups whose immutability is a machine-checked theorem, not a configuration flag.

CI SPARK proof: 325 checks, 0 unproved License: Apache 2.0 Website

dezhanctl demo: store an object under a retention, watch a delete-before-expiry be refused, then open the live dashboard

What it is

When you write an object under a retention, the vault refuses to delete it, shorten it, or expire it early until the clock legitimately passes the deadline. That refusal is not a flag an admin can turn off: it is a SPARK state machine, proved by gnatprove to have no execution path that deletes a retained object. It speaks S3 (point restic, Velero, Veeam, aws-cli or boto3 at it) and runs on-prem and air-gapped with no external runtime dependency.

dezhanctl

The control CLI and live dashboard shown above. It ships in every release and talks to the vault's plain HTTP control plane, so it needs no AWS SDK.

export DEZHAN_ENDPOINT=http://127.0.0.1:8080
dezhanctl dashboard            # live TUI: health, seal state, objects, audit, scrub
dezhanctl put report --file ./q3-close.tar --mode compliance --retain 86400
dezhanctl get report -o ./out  # fetch to a file
dezhanctl del report           # refused while the object is retained
dezhanctl admin scrub --admin-token "$DEZHAN_ADMIN_TOKEN"   # token-gated ops

What it proves

Four things in the trusted core are machine-checked by gnatprove on every commit: 325 verification conditions, 0 unproved.

Verified component Invariant it guarantees
Retention state machine retention may be extended, never shortened; a retained object cannot be deleted before expiry
Clock-integrity guard a rewound clock cannot expire a lock; the vault seals instead of releasing
Append-only audit chain every operation is hash-chained; history cannot be rewritten undetectably
Erasure coding data survives drive loss and reconstructs exactly, or is quarantined, never returned wrong

The cryptography (SHA-256/512, ChaCha20, HMAC, Ed25519) is in-tree. Design notes and limits: docs/NOTES.md.

Using it

Standard S3 is validated against the AWS SDK (buckets, copy, multipart, versioning, presigned URLs, SigV4, Object Lock / WORM):

ALIAS="aws --endpoint-url http://localhost:8080 --region us-east-1"
$ALIAS s3api create-bucket --bucket vault --object-lock-enabled-for-bucket
$ALIAS s3 cp important.bak s3://vault/     # any size, multipart handled
$ALIAS s3 rm  s3://vault/important.bak     # refused until retention expires

Install on-prem or on Kubernetes:

curl --proto '=https' --tlsv1.2 -sSf https://raw.githubusercontent.com/obsernetics/dezhan/main/install.sh | sh
kubectl apply -f https://raw.githubusercontent.com/obsernetics/dezhan/main/deploy/dezhan.yaml

A vault is a single writer over durable storage; do not scale it. dezhan trades write speed for durability, so it is slower than a plain object store on PUT. Numbers and the dezhan-vs-Veeam comparison: bench/results/COMPARISON.md.

Configuration

dezhan_server [port] [data-dir], configured by environment:

Variable Meaning Default
DEZHAN_VAULT_KEY passphrase the data key is wrapped under demo key
DEZHAN_REQUIRE_AUTH reject unsigned requests unset
DEZHAN_ACCESS_KEY / DEZHAN_SECRET the S3 credential dezhanadmin / demo
DEZHAN_ADMIN_TOKEN token gating /admin/* unset
DEZHAN_DELETE_QUORUM / DEZHAN_APPROVERS four-eyes deletes 0 / unset

Operator and CSI samples: operator/config/samples, deploy/csi/. Builds and proofs run in the project KVM guest; see CLAUDE.md. Early software (v1alpha1); docs/NOTES.md records what is deferred. Licensed under the Apache License 2.0.

About

Air-gapped, immutable, S3-compatible backup vault whose write-once retention is machine-checked with SPARK/gnatprove: objects cannot be deleted before they expire.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages