# Zerobyte: a web interface for self-hosted Restic backups

> Zerobyte wraps Restic in a Docker-hosted web UI for scheduling and monitoring backups from NFS, SMB, WebDAV, SFTP and local directories. It is a 0.x project with a clear fit and a clear set of sharp edges.

**nicotsx/zerobyte** — Backup automation for self-hosters. Built on top of restic

- Repository: https://github.com/nicotsx/zerobyte
- Website: https://zerobyte.app
- Stars: 6,990 · Forks: 174
- Language: TypeScript
- License: AGPL-3.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/nicotsx-zerobyte

## What Zerobyte actually removes from the Restic workflow

Restic is a command line program. Running it well means writing a shell script, wiring a scheduler, storing the repository password somewhere the script can read, and remembering to check that last night's run exited zero. Zerobyte is aimed at the self-hoster who wants those four things without owning the script. The README describes it as a tool that helps you save data across multiple storage backends and provides a web interface to schedule, manage, and monitor encrypted backups of remote storage. The scope is deliberately narrow: it is a control plane over Restic, not a new backup format. Encryption, compression and retention policies are described as powered by Restic, so the repository layout and the restore path stay compatible with the underlying tool. The intended user runs a home server or a small office box, already has Docker and Docker Compose installed, and wants a browser page instead of a cron tab. It is not aimed at fleets of machines or at teams that need central policy across hundreds of hosts.

## Restic, rclone and FUSE inside one container

The Dockerfile shows the architecture plainly. The image is built on oven/bun:1.4.2-alpine and installs fuse3, sshfs, cifs-utils, davfs2, openssh-client-default, tini and tzdata. Three external binaries are downloaded at build time and pinned by ARG: RESTIC_VERSION 0.19.1, RCLONE_VERSION 1.75.1 and SHOUTRRR_VERSION 0.20.0. That tells you where the work happens. Restic performs the snapshot, rclone supplies the remote backends, and shoutrrr carries notifications. FUSE is what lets a container mount a remote filesystem so that Restic sees it as a directory. The application itself is a TypeScript monorepo with Bun workspaces over apps/* and packages/*, and the state lives in /var/lib/zerobyte, which holds configuration, encryption keys and the database according to the TrueNAS note. The README lists multi-protocol support for NFS, SMB, WebDAV, SFTP and local directories, which matches the packages installed in the image. The practical consequence is that the container needs kernel-level privileges, not just a port.

## Installing Zerobyte with Docker Compose

The README says you need Docker and Docker Compose on your server, then gives a compose file. The image tag in the README is ghcr.io/nicotsx/zerobyte:v0.42, matching the current release line. Two environment variables are marked required: BASE_URL and APP_SECRET. Generate the secret with openssl rand -hex 32, as the README instructs. Note the two capability lines and the FUSE device, which are not optional for remote mounts.

```yaml
services:
  zerobyte:
    image: ghcr.io/nicotsx/zerobyte:v0.42
    container_name: zerobyte
    restart: unless-stopped
    cap_add:
      - SYS_ADMIN
    ports:
      - "4096:4096"
    devices:
      - /dev/fuse:/dev/fuse
    environment:
      - TZ=Europe/Zurich
      - BASE_URL=http://localhost:4096
      - APP_SECRET=<openssl rand -hex 32>
    volumes:
      - /etc/localtime:/etc/localtime:ro
      - /var/lib/zerobyte:/var/lib/zerobyte
```

Start it with the command the README gives, then open the interface on port 4096.

```bash
docker compose up -d
```

The README states that once the container is running you can access the web interface at http://<your-server-ip>:4096. From there the first real task is defining a repository and a volume, then a scheduled job. If you run TrueNAS, the README warns that /var/lib is ephemeral and will be reset during system upgrades, and tells you to mount a dedicated ZFS dataset such as /mnt/tank/docker/zerobyte to /var/lib/zerobyte instead, so that configuration, encryption keys and database survive upgrades. That single substitution is the difference between a working install and losing your repository password on the next update.

## The APP_SECRET and the network exposure trap

Two README warnings deserve more weight than their placement suggests. The first concerns exposure: it is highly discouraged to run Zerobyte on a server accessible from the internet, whether a VPS or a home server with port forwarding. If you do, the README says to change the port mapping to 127.0.0.1:4096:4096 and put a secure tunnel in front, naming SSH tunnels and Cloudflare Tunnel. This is not a theoretical caution. APP_SECRET encrypts sensitive data in the database and BASE_URL is used for authentication, so a publicly reachable instance with a weak or reused secret is the failure mode to avoid. The second warning is about storage: do not point /var/lib/zerobyte at a network share, because you will hit permission issues and strong performance degradation. That rules out the obvious shortcut of putting the application state on the same NAS you are backing up. A related variable, TRUST_PROXY, defaults to false and should stay false unless a reverse proxy is actually setting X-Forwarded-For. Setting it true behind no proxy means client addresses are taken from a header anyone can forge.

## Where Zerobyte is the wrong tool

The README carries its own warning: Zerobyte is still in version 0.x.x and is subject to major changes from version to version, with the author developing core features and collecting feedback. Treat that literally. A configuration that works on v0.40.0 may need attention on v0.42.0, and there is no long-term support line to hold you in place. Beyond version churn, the privilege model is a real constraint. cap_add: SYS_ADMIN plus /dev/fuse is a broad grant, and on a hardened host or a managed Kubernetes cluster it may be refused outright. If you cannot mount FUSE inside a container, the multi-protocol features lose their point. Zerobyte is also the wrong choice if your backup targets are already covered by a first-class agent on the client side, or if you need a documented, stable API contract for automation: the repository exposes an openapi-ts.config.ts and a gen:api-client script, so an API exists, but the README does not present it as a compatibility guarantee. Finally, if you want a tool that manages backup clients on many machines rather than repositories on one host, this is not that.

## How it differs from Backrest

Backrest is the comparison people search for, and the difference is in where the abstraction sits. Backrest is a web UI over Restic repositories on the machine that runs it. Zerobyte adds a layer below that: rclone and FUSE are baked into the image, so remote protocols such as SMB, WebDAV, SFTP and NFS can be presented to Restic as local paths. That is why the container ships cifs-utils, davfs2 and sshfs, and why it needs SYS_ADMIN. If your data is already mounted on the host by the operating system, that extra layer is cost without benefit, and a lighter wrapper will do. If your sources live on a NAS or a remote server that you would otherwise mount by hand, Zerobyte folds the mount step into the same interface as the schedule. The trade-off is that you inherit the container's privileges and the FUSE mount lifecycle as part of your backup reliability.

## Licence, upgrades and what each release costs you

Zerobyte is licensed AGPL-3.0, and the repository carries LICENSES/ and NOTICES.md alongside the LICENSE file, which is consistent with bundling Restic, rclone and shoutrrr. The AGPL matters if you modify the code and offer it to others over a network; the source obligations attach to network use, not only distribution. That is a question for your own legal review, not something to settle from a README. On upgrades, the release cadence visible in the repository is roughly monthly: v0.40.0 on 2026-06-22, v0.41.0 on 2026-07-13, v0.42.0 on 2026-08-23, and the last push to main was on 2026-08-23. Frequent releases are good for fixes and bad for stability, and the README's own warning about major changes between versions means you should read the release notes before moving the image tag. Pin the tag rather than tracking latest, and back up the contents of /var/lib/zerobyte before upgrading, because that directory holds the encryption keys and database. The README does not document a rollback procedure, so a downgrade path is something you would have to establish yourself.

## Conclusion

Adopt Zerobyte if you already run Docker on a private host, you want Restic snapshots on a schedule, and you accept that a 0.x project can change between releases. Do not adopt it if you need a stable configuration contract, if you cannot grant SYS_ADMIN and /dev/fuse to a container, or if the machine is reachable from the internet without a tunnel. Before trusting it with real data, verify that your /var/lib/zerobyte volume is a local path and not a network share, and run one restore from the web interface end to end.

## FAQ

### What is Zerobyte?

Zerobyte is a backup automation tool built on top of Restic, with a web interface for scheduling, managing and monitoring encrypted backups of remote storage. It supports NFS, SMB, WebDAV, SFTP and local directories, and runs as a Docker container.

### What are some good open source backup tools?

Zerobyte itself is open source under AGPL-3.0 and wraps Restic, rclone and shoutrrr, all of which are separate open source projects. If you want a web interface over Restic without the remote-mount layer, Backrest is the closer comparison.

### What is a zerobyte alternative?

Backrest is the alternative the search results point to. The difference is that Zerobyte bundles rclone and FUSE so remote protocols can be presented to Restic as local paths, which is why its container needs SYS_ADMIN and /dev/fuse.

### What is zero byte?

In this context the name refers to Zerobyte, the backup automation tool built on Restic with a web interface. The README does not explain the origin of the name.

### What does zerobytes mean?

The term appears in search data without a definition. The project it points to here is Zerobyte, which schedules and monitors Restic backups from a Docker container.

## Sources

- [Official documentation](https://zerobyte.app)
- [Official README](https://github.com/nicotsx/zerobyte#readme)
- [Project repository](https://github.com/nicotsx/zerobyte)
- [Release notes](https://github.com/nicotsx/zerobyte/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/nicotsx-zerobyte
