Skip to main content

Supported Storage Backends

jokowipe.id uses a Bring Your Own Storage (BYOS) model. Your backup files go directly from the agent to your storage bucket. jokowipe.id only stores metadata (path, size, checksum).

Storage Matrix​

ProviderTypeAuth MethodsServer-Side EncryptionStatus
AWS S3Object StorageAccess Key, IAM Role, IRSASSE-S3, SSE-KMS, SSE-CGA
Cloudflare R2Object StorageAccess KeyAES-256 (auto)GA
Google Cloud StorageObject StorageService Account, Workload IdentityGoogle-managed, CMEKGA
Azure Blob StorageObject StorageAccount Key, SAS Token, Managed IdentityAES-256 (auto)GA
MinIOObject Storage (S3-compatible)Access KeySSE-S3GA
WasabiObject Storage (S3-compatible)Access KeyAES-256 (auto)GA
Backblaze B2Object StorageApplication KeyAES-256 (auto)GA
Local FilesystemBlock StorageN/AN/AGA
SFTPRemote FilesystemPassword, SSH KeyN/ABeta

AWS S3​

storage:
type: s3
s3:
bucket: "my-backups"
region: "us-east-1"
prefix: "jokowipe/" # Optional path prefix
access_key_id: "${AWS_ACCESS_KEY_ID}"
secret_access_key: "${AWS_SECRET_ACCESS_KEY}"
# For IAM Role (EC2/ECS/EKS) — omit access keys:
# use_instance_profile: true
storage_class: STANDARD_IA # STANDARD, STANDARD_IA, GLACIER
server_side_encryption: AES256

IAM Policy​

Grant the agent user/role these minimum permissions:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::my-backups",
"arn:aws:s3:::my-backups/jokowipe/*"
]
}
]
}

Cloudflare R2​

R2 is S3-compatible. Use the S3 storage type with the R2 endpoint:

storage:
type: s3
s3:
bucket: "my-backups"
endpoint: "https://<ACCOUNT_ID>.r2.cloudflarestorage.com"
region: "auto"
access_key_id: "${R2_ACCESS_KEY_ID}"
secret_access_key: "${R2_SECRET_ACCESS_KEY}"
path_style: true
R2 Egress Pricing

Cloudflare R2 has zero egress fees, making it cost-effective for frequent restore operations.

Google Cloud Storage (GCS)​

storage:
type: gcs
gcs:
bucket: "my-backups"
prefix: "jokowipe/"
credentials_file: "/etc/jokowipe/gcs-key.json"
# For Workload Identity — omit credentials_file
storage_class: NEARLINE # STANDARD, NEARLINE, COLDLINE, ARCHIVE

Service Account Permissions​

The service account needs these GCS roles:

  • roles/storage.objectCreator
  • roles/storage.objectViewer
  • roles/storage.legacyBucketReader

Azure Blob Storage​

storage:
type: azure
azure:
container: "my-backups"
account_name: "${AZURE_STORAGE_ACCOUNT}"
account_key: "${AZURE_STORAGE_KEY}"
# Or use SAS token:
# sas_token: "${AZURE_SAS_TOKEN}"
prefix: "jokowipe/"
tier: Cool # Hot, Cool, Cold, Archive

MinIO (Self-Hosted S3-Compatible)​

storage:
type: s3
s3:
bucket: "backups"
endpoint: "https://minio.internal:9000"
region: "us-east-1" # Required but can be any value for MinIO
access_key_id: "minioadmin"
secret_access_key: "${MINIO_SECRET_KEY}"
path_style: true # Required for MinIO
skip_tls_verify: false

Local Filesystem​

Not Recommended for Production

Local filesystem storage is only suitable for development or testing. There is no redundancy, and backups are lost if the disk fails.

storage:
type: local
local:
path: "/var/backups/jokowipe"
retention_days: 7

Configuring Storage Targets in the Dashboard​

  1. Go to Dashboard → Storage Targets → Add New
  2. Select your provider
  3. Enter credentials (they are encrypted at rest using Vault)
  4. Click Test Connection to verify
  5. Click Save

See Storage Targets → for detailed instructions.