Skip to content

docs: protect the borg passphrase with age, fixes #4549 - #10404

Merged
ThomasWaldmann merged 1 commit into
borgbackup:masterfrom
ThomasWaldmann:docs-age
Sep 23, 2026
Merged

ThomasWaldmann merged 1 commit into
borgbackup:masterfrom
ThomasWaldmann:docs-age

Conversation

@ThomasWaldmann

Copy link
Copy Markdown
Member

New deployment guide: protect the borg passphrase with age, and through age's plugin ecosystem, with hardware.

The pattern is simple and needs no borg changes: a strong random passphrase, stored age-encrypted, decrypted on demand via BORG_PASSCOMMAND. The age identity that decrypts it can live in hardware:

holder plugin unattended user presence
any FIDO2 security key (hmac-secret) age-plugin-fido2-hmac no (CTAP spec mandates the touch) always a touch, PIN optional
YubiKey PIV age-plugin-yubikey yes (touch/PIN policy never) configurable
TPM 2.0 age-plugin-tpm yes none (optional PIN)
Apple Secure Enclave age-plugin-se yes configurable (Touch ID)

The guide starts with a no-hardware example to introduce the pattern, then covers the interactive touch-gated FIDO2 setup, unattended setups (YubiKey PIV with never policies, TPM, Secure Enclave), multi-recipient redundancy (several YubiKeys plus the TPM unlocking the same passphrase), the offline paper copy as the always-working recovery path, real revocation (borg key change-passphrase, since re-encrypting the file is not enough), and an honest threat-model section: all of this protects data at rest; presence-gated options additionally prevent silent unlocking by code on the machine, device-bound ones do not; the repo stays only as secure as its weakest borg key.

Context: this follows the decision to support hardware-backed key protection through age instead of borg-native hardware integrations — one documented pattern covers all current and future holders (each new one is an age plugin, not a borg PR), including both the presence-gated interactive case and the touchless unattended case that backup jobs actually need. Supersedes the native approaches explored in #8995 and #10399.

All plugin invocations in the guide were checked against the current upstream documentation of the four plugins. sphinx-build -W clean.

🤖 Generated with Claude Code

@ThomasWaldmann ThomasWaldmann changed the title docs: protect the borg passphrase with age (hardware keys, TPM, Secure Enclave) docs: protect the borg passphrase with age, fixes #4549 Sep 22, 2026
…keys)

New deployment chapter showing how to combine BORG_PASSCOMMAND with
age: a strong random borg passphrase stored age-encrypted, decrypted on
demand - and, via the age plugin ecosystem, bound to hardware: any
FIDO2 security key (age-plugin-fido2-hmac, touch-gated by CTAP spec,
interactive use), YubiKey PIV (age-plugin-yubikey, policies allow
silent unattended use), TPM 2.0 (age-plugin-tpm) and Apple Secure
Enclave (age-plugin-se) for machine-bound unattended backups.

The guide starts with a plain no-hardware example to introduce the
pattern, gives an at-a-glance table of what works unattended vs. what
requires user presence, covers multi-recipient redundancy (several
YubiKeys / TPM unlocking the same passphrase), the offline paper copy
as the recovery path, revocation (change-passphrase, not just
re-encrypting) and an honest threat-model note (at-rest protection;
presence-gated options prevent silent unlocking, device-bound ones do
not).

This is the supported way to use hardware-backed key protection with
borg, instead of borg-native hardware integrations. See the discussion
in borgbackup#8995 / borgbackup#10399.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ThomasWaldmann
ThomasWaldmann merged commit 285aefb into borgbackup:master Sep 23, 2026
1 check passed
@ThomasWaldmann
ThomasWaldmann deleted the docs-age branch September 23, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant