Introduction¶
The design philosophy of DeepSeek Harness (DSH) is to encapsulate capabilities as plugins. In automated operations scenarios, deploying backup agents on remote Linux servers typically requires handling permission configuration, dependency installation, and long-term maintenance. axelfreeman/backupper solves this pain point: it uses Restic to perform encrypted and deduplicated backups on the Windows side, streams data over SSH, requires no software installation on the server side, and includes comprehensive validation mechanisms.
What Is This¶
This is a DSH skill plugin for managing backups of remote Linux servers. The tool itself runs on a Windows PC; the server only requires tar and sshd. Data is encrypted with AES-256 and deduplicated using Restic, and the key never leaves the PC. The plugin’s source files are licensed under the MIT License.
Core Features¶
- AES-256 client-side encryption: The key remains on the Windows PC, and data is transmitted over SSH.
- Deduplication: Re-running after an interruption is a “catch-up” rather than a full retransmission; after the initial snapshot, daily snapshots have very low cost.
- Zero server-side dependencies: No daemon needs to be installed on the server.
- Validation mechanisms: Threshold checks automatically flag 0-byte or truncated snapshots silently saved by Restic.
- Server-side verifiable: Pull completion can be confirmed through SSH session duration or overlap checks.
Installation and Enablement¶
Use DSH’s install command to add the plugin:
npx skills add axelfreeman/backupper
After installation, place this folder into any AI agent (such as Claude Code, Hermes, Cursor, etc.) and instruct it to “set up backups for my server.” The plugin will handle installation, key setup, repository initialization, .bat wrappers, and scheduling.
Typical Usage¶
The plugin encapsulates Restic’s streaming backup command. Its core workflow is as follows:
ssh root@SERVER "tar -C / -cf - ... /" | restic -r C:\backups\REPO backup --stdin
ssh root@SERVER ...: Runs thetarcommand on the server to package the file system.|: Pipes the packaging stream to the local machine.restic ... backup --stdin: Restic receives the stream and writes it to the local encrypted repository.
The provided scripts/backup-server.bat and scripts/backup-all.bat automatically handle executing these commands, logging, and status checks.
Applicable Scenarios and Notes¶
- Applicable scenarios: You need to pull backups from a Windows PC, the server environment is restricted (unable to install an Agent), and you prefer a free solution with a focus on data encryption.
- Environment requirements: The server only requires
tarandsshd; the backup side runs Restic (BSD-2-Clause). - Permission note: The plugin runs with the current DSH process permissions. Before installation, check the source code and license.
Summary¶
This plugin provides DSH users with a standardized solution for pulling encrypted and deduplicated backups from Windows. Combined with Restic’s features, it implements a lightweight and verifiable backup strategy.