• v1.0.0 259db0d53e

    kBackup v1.0.0
    Some checks failed
    safe-ci / go-linux (push) Has been cancelled
    safe-ci / go-windows (push) Has been cancelled
    safe-ci / cross-build (push) Has been cancelled
    safe-ci / generated (push) Has been cancelled
    safe-ci / web (push) Has been cancelled
    Stable

    kleb released this 2026-07-27 11:33:43 +02:00 | 56 commits to main since this release

    kBackup v1.0.0

    First production baseline for controlled environments using the kBackup self-managed release trust profile.

    Supported profile

    • Windows 11 Enterprise 25H2 on NTFS, amd64
    • Debian 13 on ext4, amd64
    • New format-v3 repositories on a durable local-filesystem backend
    • One active kBackup host/process per repository
    • File-tree backup and restore through local TUI/IPC or the loopback web UI

    This release is a clean-install baseline. Repositories created by development builds should be preserved with their matching binary, restored, and backed up into a new v3 repository rather than migrated in place.

    The RPM, S3/SFTP backends, raw-device workflows, mounts, rescue media, non-loopback web exposure, other operating systems, and other architectures remain preview or unsupported. See docs/support.md for the complete boundary.

    Trust and verification

    These artifacts use self-managed signing. Windows does not trust the Authenticode signer publicly by default. Independently authenticate the trust manifest digest, then enroll the supplied root and publisher certificate only in controlled systems:

    release-trust.json SHA-256:
    405fbb57e597845d2d0f85855bd8df9f5cfad82ec3e54fbdb11cc010fa9dd020
    

    Package-signing subkey:

    D1ED1F306D446FB0F7A3C0BD2B3AA6B27E33386A
    

    Cosign public-key SHA-256:

    2cb49a5331a5d0fb14347469bf2f4063969069f462d52e3b6ea75451462e5a3d
    

    Follow docs/release-trust.md. The platform bundles contain the native artifacts, SHA256SUMS, SBOMs, provenance, and Cosign bundles with their original filenames. BUNDLES-SHA256SUMS is a transport checksum for the uploaded release assets; authoritative artifact authentication is provided by the native signatures and signed platform metadata inside each bundle.

    Source commit:

    259db0d53e80dadf8d713c5fea57098b6dc0e8cb
    

    The exact signed Windows and Debian artifacts passed clean disposable-VM acceptance before publication.

    Downloads