Supported Storage Backends
jokowipe.id uses a Bring Your Own Storage (BYOS) model. Your backup files go directly from the agent to your storage bucket. jokowipe.id only stores metadata (path, size, checksum).
Storage Matrix
| Provider | Type | Auth Methods | Server-Side Encryption | Status |
|---|---|---|---|---|
| AWS S3 | Object Storage | Access Key, IAM Role, IRSA | SSE-S3, SSE-KMS, SSE-C | GA |
| Cloudflare R2 | Object Storage | Access Key | AES-256 (auto) | GA |
| Google Cloud Storage | Object Storage | Service Account, Workload Identity | Google-managed, CMEK | GA |
| Azure Blob Storage | Object Storage | Account Key, SAS Token, Managed Identity | AES-256 (auto) | GA |
| MinIO | Object Storage (S3-compatible) | Access Key | SSE-S3 | GA |
| Wasabi | Object Storage (S3-compatible) | Access Key | AES-256 (auto) | GA |
| Backblaze B2 | Object Storage | Application Key | AES-256 (auto) | GA |
| Local Filesystem | Block Storage | N/A | N/A | GA |
| SFTP | Remote Filesystem | Password, SSH Key | N/A | Beta |
AWS S3
storage:
type: s3
s3:
bucket: "my-backups"
region: "us-east-1"
prefix: "jokowipe/" # Optional path prefix
access_key_id: "${AWS_ACCESS_KEY_ID}"
secret_access_key: "${AWS_SECRET_ACCESS_KEY}"
# For IAM Role (EC2/ECS/EKS) — omit access keys:
# use_instance_profile: true
storage_class: STANDARD_IA # STANDARD, STANDARD_IA, GLACIER
server_side_encryption: AES256
IAM Policy
Grant the agent user/role these minimum permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::my-backups",
"arn:aws:s3:::my-backups/jokowipe/*"
]
}
]
}
Cloudflare R2
R2 is S3-compatible. Use the S3 storage type with the R2 endpoint:
storage:
type: s3
s3:
bucket: "my-backups"
endpoint: "https://<ACCOUNT_ID>.r2.cloudflarestorage.com"
region: "auto"
access_key_id: "${R2_ACCESS_KEY_ID}"
secret_access_key: "${R2_SECRET_ACCESS_KEY}"
path_style: true
R2 Egress Pricing
Cloudflare R2 has zero egress fees, making it cost-effective for frequent restore operations.
Google Cloud Storage (GCS)
storage:
type: gcs
gcs:
bucket: "my-backups"
prefix: "jokowipe/"
credentials_file: "/etc/jokowipe/gcs-key.json"
# For Workload Identity — omit credentials_file
storage_class: NEARLINE # STANDARD, NEARLINE, COLDLINE, ARCHIVE
Service Account Permissions
The service account needs these GCS roles:
roles/storage.objectCreatorroles/storage.objectViewerroles/storage.legacyBucketReader
Azure Blob Storage
storage:
type: azure
azure:
container: "my-backups"
account_name: "${AZURE_STORAGE_ACCOUNT}"
account_key: "${AZURE_STORAGE_KEY}"
# Or use SAS token:
# sas_token: "${AZURE_SAS_TOKEN}"
prefix: "jokowipe/"
tier: Cool # Hot, Cool, Cold, Archive
MinIO (Self-Hosted S3-Compatible)
storage:
type: s3
s3:
bucket: "backups"
endpoint: "https://minio.internal:9000"
region: "us-east-1" # Required but can be any value for MinIO
access_key_id: "minioadmin"
secret_access_key: "${MINIO_SECRET_KEY}"
path_style: true # Required for MinIO
skip_tls_verify: false
Local Filesystem
Not Recommended for Production
Local filesystem storage is only suitable for development or testing. There is no redundancy, and backups are lost if the disk fails.
storage:
type: local
local:
path: "/var/backups/jokowipe"
retention_days: 7
Configuring Storage Targets in the Dashboard
- Go to Dashboard → Storage Targets → Add New
- Select your provider
- Enter credentials (they are encrypted at rest using Vault)
- Click Test Connection to verify
- Click Save
See Storage Targets → for detailed instructions.