claude-timemachine 49d1cb3280
CI / test (3.10) (push) Successful in 8s
CI / test (3.11) (push) Successful in 8s
CI / test (3.12) (push) Successful in 7s
CI / build-pyz (push) Successful in 4s
CI / release (push) Has been skipped
drop restic repo encryption; rely on TLS + append-only + LUKS
User credentials now serve HTTP basic auth only. Repos init with
--insecure-no-password. Removes:
  - RESTIC_PASSWORD env in client subprocess
  - Per-repo password coordination story
  - Multi-key restic setup (user key + operator-master key)
  - Two-password recovery edge cases

Operator-side prune now runs over the filesystem path (-r /srv/.../<user>/)
which bypasses rest-server's HTTP-layer append-only enforcement. No
password needed at all.

Protection model stays:
  - TLS in transit (reverse proxy)
  - HTTP basic per-user (htpasswd) for read/write authorization
  - --private-repos for per-user URL isolation
  - --append-only for client-side delete protection
  - LUKS / disk-level for at-rest encryption (operator's responsibility)

Verified end-to-end on john: pull → push → restore round-trip works,
DELETE on bogus snapshot still returns 403 (append-only intact),
operator can read repo via filesystem path (prune-mode access works).

33 pytest still green.
2026-06-04 22:23:40 +02:00

cloud-sync

Per-user Minecraft state sync via restic. Single Python zipapp drops into Prism / MMC / ATLauncher pre-launch and post-exit hooks alongside packwiz-installer-bootstrap. Part of the automc platform.

See DESIGN.md for the full architecture (restic backend, two-port cloud-svc control plane, etc.).

Status

Working skeleton + sync logic. 33 tests pass. E2E verified against a local restic-rest-server (pull empty → push initial → delete local → pull restores → modify+push creates second snapshot → client forget --prune correctly blocked by --append-only).

Install / build

Requires Python ≥ 3.10. No runtime deps (stdlib only).

# build single-file zipapp
make build       # → cloud-sync.pyz (~53 KB)

# or pip-install
make install     # pip install -e .

Usage in Prism (or MMC / ATLauncher)

Instance Settings → Custom commands:

Pre-launch:
  python /path/to/cloud-sync.pyz pull --url=https://cloud.tm.center --pack-folder=$INST_MC_DIR

Post-exit:
  python /path/to/cloud-sync.pyz push --url=https://cloud.tm.center --pack-folder=$INST_MC_DIR

Player needs Python 3.10+ on PATH. Token file (<INST_MC_DIR>/.cloud-sync/token) gets the discord_id:password credentials from their /register Discord DM.

CLI

python cloud-sync.pyz {pull,push} \
    --url URL              cloud-svc data plane URL (required)
    --pack-folder PATH     Minecraft instance directory (default: cwd)
    --token-file PATH      override default <pack-folder>/.cloud-sync/token
    --restic-binary PATH   skip auto-discovery
    --no-download          fail if no usable restic; don't fetch from upstream
    -g, --no-gui           headless mode

Programmatic API (for frazclient)

from pathlib import Path
import cloud_sync

cloud_sync.pull(cloud_sync.Args(
    url="https://cloud.tm.center",
    pack_folder=Path("/srv/mc/instance"),
    token_file=Path("/srv/mc/instance/.cloud-sync/token"),
    restic_binary=None,        # auto-discover
    allow_download=True,
    headless=True,
))

frazclient's client.py consumes this directly via import cloud_sync instead of subprocessing the pyz.

On-disk layout

Per-instance state under <pack-folder>/.cloud-sync/:

.cloud-sync/
  token                       # discord_id:password (mode 0600)
  scope.json                  # optional; defaults baked in if missing
  restic-<RESTIC_VERSION>      # auto-downloaded binary
  files-from.txt              # restic --files-from
  exclude-from.txt            # restic --exclude-from

Auto-excluded from sync. Multiple MC instances = multiple .cloud-sync/ dirs with independent credentials.

Why Python (not a JAR)

  1. Antivirus. Unsigned JARs that auto-download binaries + upload files are textbook Windows Defender false-positive triggers. Python invoked by code-signed python.exe mostly sidesteps that.
  2. Future Qt UI. PySide6 opens a path to a real Qt UI (matching Prism's look) if richer surfaces are wanted later. JVM Qt bindings are abandoned.
  3. frazclient already needs Python. Inlining as an import is zero overhead; the same package serves Prism via the pyz.

Cost: players using Prism must have Python 3.10+ installed. Most Linux/Mac systems already do; Windows users install once from the Microsoft Store or python.org.

Where the data lives

Component Role Repo
cloud-sync (this) Player-side. Subprocess restic for pull/push. Timemachine/cloud-sync
cloud-svc Operator-side control plane (provisioning + admin). Timemachine/cloud-svc
restic-rest-server (existing) Data plane. Player's restic hits it directly with their password. upstream
discord-bot Calls cloud-svc on /register to provision a player's cloud account. Timemachine/discord-bot

License

MIT.

S
Description
Single-jar Kotlin client for cloud-svc. Drops into Prism / MMC / ATLauncher pre-launch + post-exit hooks alongside packwiz-installer-bootstrap. Swing + FlatLaf UI for conflict resolution. Part of the automc platform.
Readme MIT 284 KiB
Languages
Python 99%
Makefile 1%