Sqoia Labs tool · Open source

PBS File Restore for Open OnDemand

Give authenticated users a focused path from backup date to recovered file, while keeping PBS credentials, privileged storage access, and restore enforcement outside the browser-facing process.

What it adds to Open OnDemand

A recovery path designed around the authenticated user.

The application presents the useful part of a shared backup, dates, directories, files, and restore actions, without moving storage credentials into the portal.

01 / ARCHIVES

Follow each snapshot's archive format.

Automatic per-snapshot detection supports both legacy pxar/catalog and split mpxar/ppxar layouts during mixed-retention transitions.

02 / IDENTITY

Keep requests bound to the Unix user.

The Passenger process invokes a constrained sudo client, then a pinned forced-command SSH path revalidates the effective identity at the storage broker.

03 / DESTINATION

Recover without overwriting current work.

Restores are written beneath a configurable directory such as ~/.pbs-restores, organized by backup date and job identifier.

04 / OPERATIONS

Configure every role from one reviewed model.

A validated, non-secret site configuration aligns the portal, client, and broker while credentials remain in a separate root-only broker environment.

How it works

Privilege narrows as the request moves toward storage.

The browser receives sanitized snapshot and file metadata. Each lower layer revalidates identity, path, archive, and destination assumptions before privileged work proceeds.

  1. 01Browser

    The authenticated user selects a date, browses entries, and chooses what to restore.

  2. 02Passenger app

    The user-scoped WSGI process validates request shape and never receives PBS credentials.

  3. 03Sudo client

    A constrained client forwards only the bounded JSON request for the effective user.

  4. 04SSH broker

    A pinned forced command revalidates identity and performs PBS catalog or archive operations.

  5. 05Restore tree

    Descriptor-relative traversal creates a new destination beneath the user's home.

OPERATING GUARDRAILS

Recovery authority stays explicit.

  • PBS API credentials stay in a root-only broker environment and never reach the portal host or browser response.
  • Returned PBS paths are revalidated before use; browser-visible snapshot data omits internal backup-group and archive identifiers.
  • The implemented backup model expects one host backup group with a first-level directory for each matching Unix username.
  • Restores are synchronous and require site review for capacity, concurrency, credentials, SSH trust, sudo policy, and production canaries.

Rendered interface

See the recovery flow inside Open OnDemand.

These views render the application at source revision 765d919a with synthetic users, dates, directories, and restore results. The isolated fixture contacted no PBS server, portal, SSH broker, sudo client, or filesystem restore target.

Open OnDemand PBS File Restore page showing backup-date controls and a populated home-directory snapshot
Choose a date and browse the backup

The main view exposes available dates, the safe destination, file types, sizes, modification times, and restore actions.

Open full rendering ↗
Open OnDemand PBS File Restore page browsing a synthetic research-data directory
Navigate before restoring

Breadcrumbs and folder actions let the user inspect a snapshot hierarchy before choosing a file or directory.

Open full rendering ↗
Open OnDemand PBS File Restore page showing a completed synthetic restore destination
Return the exact destination

A completed restore reports the new path beneath the user's restore directory instead of replacing the current file.

Open full rendering ↗

Deployment fit

Bring Open OnDemand, PBS, and a reviewed shared backup layout.

This is an installable companion application, not a hosted restore service. Adopters own their credentials, backup production, storage capacity, identity mapping, host hardening, and rollout.

OPEN ONDEMAND

User-facing portal

A compatible Open OnDemand deployment, protected application source, the constrained sudo client, and site-managed SSH key and known-hosts material.

STORAGE BROKER

Privileged boundary

A reviewed Linux broker with direct access to the managed home filesystem, a forced-command key, root-only PBS credentials, and audit logging.

PROXMOX BACKUP SERVER

Supported backup model

HTTPS API access and a host backup whose legacy or split archive contains one top-level directory per Unix username.

CANARY FIRST

Run the documented identity, traversal, catalog, file, directory, symlink, non-overwrite, audit, and rollback checks with a non-privileged synthetic user before production rollout.

Inspect the recovery path.

The application source, deployment guide, security checklist, configuration schema, installers, and backup-writer example are public.