pgdrive-backup
A Go streaming pipeline for PostgreSQL backups, gzip compression, AES-256 encryption, and Google Drive storage.
Read as MarkdownArchitecture
pg_dump → gzip → AES-256-CTR → Google Drive; encrypted archive → Decrypt / decompress → pg_restore
Pipeline design
The utility connects pg_dump output to compression, encryption, and upload using Go io.Pipe stages. It avoids writing a complete intermediate backup to local disk. That makes streaming and failure propagation central to the design, rather than treating upload as a separate step after a full file is created.
Compression and storage
The documented pipeline uses gzip at maximum compression and a resumable Google Drive upload. Retention management purges backups older than the configured retention period. Compression saves transfer and storage space at a CPU cost; that tradeoff should be measured on representative databases.
Encryption boundary
AES-256-CTR encrypts the stream with a random IV per backup. CTR encryption does not authenticate the ciphertext, so encryption alone should not be described as tamper detection. Key storage and backup integrity need separate consideration.
Restore workflow
The decrypt utility reverses encryption and compression. The README specifies that the resulting archive uses PostgreSQL custom format and should be restored with pg_restore. A backup that uploaded successfully still needs a restore drill to establish recoverability.
Operational tools
The repository includes a command-line backup browser, a web restore interface, Docker packaging, and configuration for automated runs. A useful operational check covers interrupted streams, failed uploads, retention behavior, and restoration into a separate test database.
Evidence and limitations
This note follows the public README. It describes the streaming architecture without claiming a measured constant-memory result, recovery-time objective, or tested database-size ceiling.
Source: public project repository →