Follow each snapshot's archive format.
Automatic per-snapshot detection supports both legacy pxar/catalog and split mpxar/ppxar layouts during mixed-retention transitions.
Sqoia Labs tool · Open source
Give authenticated users a focused path from backup date to recovered file, while keeping PBS credentials, privileged storage access, and restore enforcement outside the browser-facing process.
What it adds to Open OnDemand
The application presents the useful part of a shared backup, dates, directories, files, and restore actions, without moving storage credentials into the portal.
Automatic per-snapshot detection supports both legacy pxar/catalog and split mpxar/ppxar layouts during mixed-retention transitions.
The Passenger process invokes a constrained sudo client, then a pinned forced-command SSH path revalidates the effective identity at the storage broker.
Restores are written beneath a configurable directory such as ~/.pbs-restores, organized by backup date and job identifier.
A validated, non-secret site configuration aligns the portal, client, and broker while credentials remain in a separate root-only broker environment.
How it works
The browser receives sanitized snapshot and file metadata. Each lower layer revalidates identity, path, archive, and destination assumptions before privileged work proceeds.
The authenticated user selects a date, browses entries, and chooses what to restore.
The user-scoped WSGI process validates request shape and never receives PBS credentials.
A constrained client forwards only the bounded JSON request for the effective user.
A pinned forced command revalidates identity and performs PBS catalog or archive operations.
Descriptor-relative traversal creates a new destination beneath the user's home.
OPERATING GUARDRAILS
Rendered interface
These views render the application at source revision 765d919a with synthetic users, dates, directories, and restore results. The isolated fixture contacted no PBS server, portal, SSH broker, sudo client, or filesystem restore target.
The main view exposes available dates, the safe destination, file types, sizes, modification times, and restore actions.
Open full rendering ↗
Breadcrumbs and folder actions let the user inspect a snapshot hierarchy before choosing a file or directory.
Open full rendering ↗
A completed restore reports the new path beneath the user's restore directory instead of replacing the current file.
Open full rendering ↗Deployment fit
This is an installable companion application, not a hosted restore service. Adopters own their credentials, backup production, storage capacity, identity mapping, host hardening, and rollout.
OPEN ONDEMAND
A compatible Open OnDemand deployment, protected application source, the constrained sudo client, and site-managed SSH key and known-hosts material.
STORAGE BROKER
A reviewed Linux broker with direct access to the managed home filesystem, a forced-command key, root-only PBS credentials, and audit logging.
PROXMOX BACKUP SERVER
HTTPS API access and a host backup whose legacy or split archive contains one top-level directory per Unix username.
Run the documented identity, traversal, catalog, file, directory, symlink, non-overwrite, audit, and rollback checks with a non-privileged synthetic user before production rollout.
The application source, deployment guide, security checklist, configuration schema, installers, and backup-writer example are public.