Encrypted, incremental backups to any S3-compatible storage

blueflow is a single, dependency-free binary that deduplicates, compresses and encrypts your files before they leave the machine. Restore one file or a whole server in minutes.

$ brew install blueflow
$ blueflow init s3://backups.example.net/laptop
$ blueflow backup ~/Documents

Apache-2.0Linux · macOS · Windowsv1.8.2

End-to-end encryption

AES-256-GCM with keys derived via Argon2id. The storage provider only ever sees encrypted chunks.

Content-defined deduplication

Files are split into variable-size chunks, so renaming or editing a large file uploads only what changed.

Any S3-compatible backend

Works with AWS S3, Backblaze B2, Wasabi, MinIO, Ceph and any provider that speaks the S3 API, plus local disks and SFTP.

Fast restores

Mount any snapshot as a read-only filesystem and copy what you need, or restore to a different machine.

Retention policies

Keep hourly, daily, weekly and monthly snapshots with a single prune command.

Scriptable

JSON output for every command, meaningful exit codes and a Prometheus metrics endpoint for monitoring.

What a backup looks like

$ blueflow backup /srv --exclude '*.tmp'
scanning      48,213 files, 37.4 GiB
new           312 files, 1.2 GiB
deduplicated  97.1%
uploaded      214 MiB in 00:41 (5.2 MiB/s)
snapshot      7f3c19ab saved

$ blueflow snapshots --last 3
ID        TIME                 HOST   SIZE
7f3c19ab  today 03:00          web01  37.4 GiB
c41e0d72  yesterday 03:00      web01  37.2 GiB
9a6b5521  2 days ago 03:00     web01  37.2 GiB