pete1450/GlacierVault

Single app for creating and managing rustic storage in Amazon Glacier

Go

2

52 commits

updated Oct 5, 2026

See the code

See what people are saying

SourceMessageScoreDate

GlacierVault- UI and orchestrator for dirt cheap Glacier tier S3 backups (r/selfhosted)

tl;dr at the top for you: The cheapest AWS storage is a pain to use. GlacierVault puts a few established tools(read: Rustic) and orchestrations together in a UI to make it painless. When backup/restore is cheap you're a lot more likely to use/test it. If you're afraid of AI turn away now because…

0

Oct 5, 2026

README

GlacierVault

logo

A self-hosted backup appliance that makes cheap AWS Glacier Deep Archive as simple as possible: you bring AWS credentials, it handles the rest. One Docker container with a web UI — it deploys the AWS infrastructure with CDK, schedules encrypted Rustic backups into Deep Archive, and walks restores through Glacier retrieval with a private CloudFront distribution for free-egress downloads and Apprise notifications when jobs finish.

Built on

  • Rustic — the backup engine (encrypted, deduplicated repositories)
  • glacier-cold-storage-cdk — the CDK project that provisions the S3/SQS/IAM infrastructure
  • warmup-s3-archives — restores archived S3 objects via Batch Operations before download
  • Apprise — notification dispatch (Discord, Slack, Telegram, email, ntfy, webhooks, …)

Thought process

  • Deep archive is dirt-cheap but retrieval can be a pain
  • Bulk retrieval is cheap($2.50 per TB)
  • 1TB per month egress from AWS through Cloudfront is free
  • PUT/GET request need to be managed intelligently
  • Warmup process takes a while
  • Wouldn't it be nice to have this all in a single app
image image image

Quick start

  1. Create a setup IAM user in the AWS console (it deploys real infrastructure, so it needs broad permissions — use once, then delete it). See docs/setup.md for the exact policy.
  2. Run the container:
# docker-compose.yml
services:
  glaciervault:
    # Prebuilt image from tagged releases (ghcr.io/pete1450/glaciervault).
    # To build locally instead, see "Building the image yourself" in docs/setup.md.
    image: ghcr.io/pete1450/glaciervault:latest
    ports:
      - "8080:8080"
    environment:
      - INITIAL_PASSWORD=changeme   # web UI login
    volumes:
      - glaciervault-config:/config
      - glaciervault-database:/database
      - glaciervault-cache:/cache
      - glaciervault-logs:/logs
      # Mount the folders you want to back up (read-only):
      - /home:/mnt/home:ro

volumes:
  glaciervault-config:
  glaciervault-database:
  glaciervault-cache:
  glaciervault-logs:
docker compose up -d

The compose file pulls the prebuilt image for the latest tagged release. To build the image yourself, see docs/setup.md.

  1. Open http://localhost:8080 and follow the setup wizard: paste your AWS key/secret/region, review the resource estimate, and hit Deploy Infrastructure. CDK bootstrap + deploy takes 5–10 minutes, then the app initializes the backup repositories and provisions the CloudFront free-egress path automatically.
  2. Add a backup source on the Backups page (name, source paths, schedule) and you're done — or press Run now for the first backup.

Docs

Everything else lives in docs/:

  • Setup — IAM user creation, wizard walkthrough, teardown
  • User workflow — backups, snapshots, restores, costs in practice
  • Cost guide — verified AWS pricing with worked examples
  • Design — architecture and theory
  • Goals — what this optimizes for (and what it doesn't)
  • Pages — tour of every UI page

pete1450/GlacierVault

Single app for creating and managing rustic storage in Amazon Glacier

Go

2

52 commits

updated Oct 5, 2026

See the code

See what people are saying

SourceMessageScoreDate

GlacierVault- UI and orchestrator for dirt cheap Glacier tier S3 backups (r/selfhosted)

tl;dr at the top for you: The cheapest AWS storage is a pain to use. GlacierVault puts a few established tools(read: Rustic) and orchestrations together in a UI to make it painless. When backup/restore is cheap you're a lot more likely to use/test it. If you're afraid of AI turn away now because…

0

Oct 5, 2026

README

GlacierVault

logo

A self-hosted backup appliance that makes cheap AWS Glacier Deep Archive as simple as possible: you bring AWS credentials, it handles the rest. One Docker container with a web UI — it deploys the AWS infrastructure with CDK, schedules encrypted Rustic backups into Deep Archive, and walks restores through Glacier retrieval with a private CloudFront distribution for free-egress downloads and Apprise notifications when jobs finish.

Built on

  • Rustic — the backup engine (encrypted, deduplicated repositories)
  • glacier-cold-storage-cdk — the CDK project that provisions the S3/SQS/IAM infrastructure
  • warmup-s3-archives — restores archived S3 objects via Batch Operations before download
  • Apprise — notification dispatch (Discord, Slack, Telegram, email, ntfy, webhooks, …)

Thought process

  • Deep archive is dirt-cheap but retrieval can be a pain
  • Bulk retrieval is cheap($2.50 per TB)
  • 1TB per month egress from AWS through Cloudfront is free
  • PUT/GET request need to be managed intelligently
  • Warmup process takes a while
  • Wouldn't it be nice to have this all in a single app
image image image

Quick start

  1. Create a setup IAM user in the AWS console (it deploys real infrastructure, so it needs broad permissions — use once, then delete it). See docs/setup.md for the exact policy.
  2. Run the container:
# docker-compose.yml
services:
  glaciervault:
    # Prebuilt image from tagged releases (ghcr.io/pete1450/glaciervault).
    # To build locally instead, see "Building the image yourself" in docs/setup.md.
    image: ghcr.io/pete1450/glaciervault:latest
    ports:
      - "8080:8080"
    environment:
      - INITIAL_PASSWORD=changeme   # web UI login
    volumes:
      - glaciervault-config:/config
      - glaciervault-database:/database
      - glaciervault-cache:/cache
      - glaciervault-logs:/logs
      # Mount the folders you want to back up (read-only):
      - /home:/mnt/home:ro

volumes:
  glaciervault-config:
  glaciervault-database:
  glaciervault-cache:
  glaciervault-logs:
docker compose up -d

The compose file pulls the prebuilt image for the latest tagged release. To build the image yourself, see docs/setup.md.

  1. Open http://localhost:8080 and follow the setup wizard: paste your AWS key/secret/region, review the resource estimate, and hit Deploy Infrastructure. CDK bootstrap + deploy takes 5–10 minutes, then the app initializes the backup repositories and provisions the CloudFront free-egress path automatically.
  2. Add a backup source on the Backups page (name, source paths, schedule) and you're done — or press Run now for the first backup.

Docs

Everything else lives in docs/:

  • Setup — IAM user creation, wizard walkthrough, teardown
  • User workflow — backups, snapshots, restores, costs in practice
  • Cost guide — verified AWS pricing with worked examples
  • Design — architecture and theory
  • Goals — what this optimizes for (and what it doesn't)
  • Pages — tour of every UI page