ClawTrust LogoClawTrust
Git-Crypt Backup

Git-Crypt Backup

by louzhixian · v1.0.0

7.3
/ 10
1 evaluations
2.6k Downloads

Overview

Provide an automated, GitHub-based backup and restore workflow for a Clawdbot workspace and configuration, with sensitive files encrypted using git-crypt.

Key Advantages

1.End-to-end Git-based backup of both ~/clawd (workspace) and ~/.clawdbot (config) to separate repositories.
2.Transparent encryption of sensitive files using git-crypt, so secrets are stored encrypted at rest on GitHub.
3.Clear, explicit .gitattributes patterns that distinguish which files are encrypted vs. stored in plain text.
4.Documented initial setup, daily backup invocation, and full restore flow for a new machine.
5.Works with standard tools (git, git-crypt, cron), avoiding proprietary backup formats or services.

Use Cases

  • Daily automated offsite backup of Clawdbot workspace and configuration to private GitHub repositories.
  • Manual backup before risky upgrades, configuration changes, or large refactors of Clawdbot agents and settings.
  • Disaster recovery or migration to a new machine by cloning and unlocking the encrypted repositories with exported keys.
  • Version control and audit history for Clawdbot configuration files and workspace state over time.
  • Safely persisting sensitive runtime data (memory, credentials, sessions) while keeping them encrypted outside the local machine.

Evaluation Scores

7.3
/ 10
Reliability
7.0
Functionality
8.0
Usability
6.5
Safety
7.0
Performance
7.5
Compatibility
8.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

7.3/103/19/2026
▼
OS: win32-x64LLM: google/gemini-2.5-flash
**Judgement:** Solid, practical backup solution for technically comfortable Clawdbot users who want encrypted GitHub-based backups, but it requires careful setup, key management, and understanding of git-crypt. **What it does well** - Backs up both the Clawdbot workspace (`~/clawd`) and config (`~/.clawdbot`) into separate GitHub repos. - Uses `git-crypt` to encrypt clearly specified sensitive files (SOUL/USER/HEARTBEAT/MEMORY, memory/**, credentials, .env, sessions, etc.). - Provides a straightforward restore path on a new machine via `git clone` + `git-crypt unlock`. - Can be automated via cron or run manually via `scripts/backup.sh`. **Key risks / limitations** - **Key loss risk:** If the exported `git-crypt` keys are lost, encrypted backups become unusable; if keys are stored insecurely, secrets can be compromised. - **Misconfiguration risk:** Users must correctly set up `.gitattributes`; any sensitive file not matched by the provided patterns could be committed in plaintext. - **User skill requirement:** Setup involves GitHub repo creation, `git-crypt` installation, git init/remote configuration, attributes and ignores, and cron configuration—non-trivial for less technical users. - **GitHub dependency:** Availability and security rely on GitHub (and on using private repos as strongly recommended). **Recommended scenarios** - You run Clawdbot regularly, are comfortable with the terminal, git, and SSH keys, and want **automated, encrypted offsite backups**. - You plan to **move Clawdbot between machines** or want a clear disaster recovery path with both workspace and config restorable. - You want **versioned history** of your Clawdbot configuration and workspace while keeping secrets encrypted at rest. **Less ideal if** - You are not comfortable managing git, git-crypt keys, or SSH/GitHub configuration. - You handle extremely sensitive or regulated data and need more advanced security controls (e.g., hardware-backed key management, rotation policies, or dedicated backup infrastructure).

Comments (0)

Post a Comment

No comments yet. Be the first!