Zero-Knowledge E2EE Cloud Backup
Pluvira Cloud Backup allows you to persist encrypted snapshots of your configuration files (config.yaml and rewrite rules) to the cloud with mathematically guaranteed Zero-Knowledge privacy.
1. Zero-Knowledge Cryptographic Architecture
[User Passphrase] + [16B Random Salt] │ ▼[PBKDF2-HMAC-SHA256 (600,000 iterations)] │ ▼ [256-bit AES Key] │[config.yaml] + [12B Random IV] ──► [AES-256-GCM Encryption] │ ▼ [Opaque Encrypted Binary Blob] │ HTTPS POST /api/v1/backup/upload ▼ [Pluvira Cloud Storage] (Cannot Decrypt Blob)- Client-Side Encryption: Snapshot encryption executes entirely inside your local browser or local daemon before network dispatch.
- Key Derivation (PBKDF2): Derives a 256-bit AES key using PBKDF2-HMAC-SHA256 with 600,000 iterations and a unique 16-byte random salt.
- Opaque Cloud Persistence: Pluvira Cloud stores only opaque binary blobs (
BYTEA) and SHA-256 integrity checksums. Even in the event of a total server breach, stored snapshots cannot be decrypted.
2. Storage Quotas & Retention Policy
| Tier | Type | Max Slots | Max Size | Retention Policy |
|---|---|---|---|---|
| Personal Free (Unregistered) | None | 0 | — | Local file export only |
| Personal Free (Registered) | Manual | 1 Slot | 200 KB | Overwrites previous snapshot |
| Pluvira Pro Tier | Manual + Auto | 5 Slots | 500 KB | Automatic FIFO rotation (oldest pruned) |
| Pluvira Ultra Tier | Manual + Auto | 10 Slots | 1 MB | Automatic FIFO rotation (oldest pruned) |
3. Creating & Restoring Snapshots
Creating a Snapshot
- In the WebUI, navigate to Settings → Cloud Backup.
- Enter a strong personal encryption passphrase.
- Click Create Cloud Snapshot. The local engine verifies SHA-256 integrity and transmits the encrypted blob.
Restoring a Snapshot
- Navigate to Settings → Cloud Backup (or log in to the Customer Portal).
- Select your snapshot from the list and enter your decryption passphrase.
- Click Decrypt & Restore. The configuration is validated and atomically restored.