Skip to main content
Edge and Central are separate apps with separate jobs. Edge does all the work that needs your plaintext files. Central only ever receives encrypted archives.
Edge 1 at 192.168.1.21:6556, Edge 2 at 192.168.1.22:6556, and Edge 3 at 192.168.1.23:6556 send backups to Central at 192.168.1.10:6555. An optional external sync sends another copy to cloud storage.

Each Edge uploads independently to the same Central. The cloud copy is handled by an external tool.

The addresses above are examples: each machine has its own IP, so its Edge UI can use the same port, 6556. All three Edges set their Central URL to the same receiver, shown here as http://192.168.1.10:6555. Use your own reachable address, with HTTPS when configured. The numbers count copies of each machine’s data: 1 is its original files, 2 is Central’s snapshots, and 3 is an independent copy made by an external sync tool. Central does not upload to cloud storage itself. See Storage and the 3-2-1 rule for how location and storage choices affect those copies.

The backup flow

1

You mark a folder

Create a .upload_dir file in a folder on the Edge machine, or select the folder in Edge’s UI.
2

Edge finds it during a scan

On each scheduled cycle, Edge walks its scan root looking for markers. Each marked folder is a job.
3

Edge decides whether anything changed

Edge fingerprints the job’s sorted file paths and sizes and compares that with the last backup. See Design decisions.
4

Edge builds and encrypts an archive

If the fingerprint changed, Edge creates a tar.zst archive of the folder and encrypts it with its own key.
5

Edge uploads it to Central

The encrypted archive is uploaded in chunks, with retries and a circuit breaker if Central is unreachable.
6

Central verifies and stores it

Central checks the upload, stores it under edge_id/edge_instance_id/job_name, and prunes older snapshots for that instance.
7

You browse, download, or restore

Download snapshots from Central’s UI (decrypted in your browser) or restore them from Edge.

Identity: edge ID and instance ID

Every Edge has two identifiers:
  • EDGE_ID is a name you choose, such as laptop-alice. Central groups snapshots by it.
  • Instance ID is generated automatically on first run and saved in Edge’s config directory. It keeps each installation separate, even if two machines were given the same EDGE_ID by mistake.
Central stores snapshots under both, so two installations never write into the same place or prune each other’s snapshots.
Still give every Edge its own EDGE_ID. It is the name you’ll see in Central’s UI.

Where encryption happens

Each Edge generates its own encryption.key on first run and encrypts every archive before upload. Central stores the encrypted blobs as-is. When you download a snapshot from Central’s UI, the browser asks for that Edge’s key and decrypts the file locally. The browser compares the key’s fingerprint with the one Edge reported, so it can tell you if you pasted the wrong key before trying to decrypt. The key is never sent to Central’s server. See Encryption key for how to find, back up, and rotate the key.