Automated Disaster-Recovery Validation

Disaster recovery validation
for Proxmox VE & PBS.

CertiStack boots the virtual machines in your PBS backups inside isolated, zero-copy sandboxes. Prove they start and their services answer before disaster strikes, and keep tamper-evident Ed25519-signed evidence of every run.

✓ Zero-Copy COW Sandboxes ✓ Air-Gapped SDN Isolation ✓ Ed25519 Signed Proofs
certistack-cli v1.0.4 • node01.clift.internal
● PROOF SEALED • PASS
Read-only
PBS source snapshots
COW
Disposable test overlays
SDN
Isolated test networks
Ed25519
Signed reports

How CertiStack Validates Recovery

Engineered with fail-closed safety, air-gapped sandboxing, and zero lingering state. Recovery validation drills never impact production workloads.

01. Read-Only PBS Chunk Ingest

CertiStack accesses Proxmox Backup Server datastores using non-privileged, read-only snapshot credentials. Chunk indexes and SHA-256 manifests are validated in memory before any hypervisor resources are allocated.

  • ✓ Strict Read-Only Access: Impossible to overwrite, mutate, or corrupt production snapshots.
  • ✓ Cryptographic Chunk Verification: Verifies PBS deduplicated chunk trees and crypt-hashes against the manifest.
  • ✓ Bandwidth Optimization: Only chunks required for boot and probed services are pulled from the PBS datastore.
MANIFEST SPECIFICATIONFORMAT: JSON
{
  "backup_id": "vm/104/2026-09-30T16:00:00Z",
  "datastore": "pbs01-nvme",
  "chunks_count": 4218,
  "verified_hash": "sha256:7e9b0429f43c8b82...",
  "access_mode": "RO_SNAPSHOT_LOCK",
  "source_node": "proxmox-pve-01"
}

02. Zero-Copy Copy-On-Write Provisioning

Rather than performing lengthy restores that consume terabytes of disk space and hours of I/O, CertiStack maps a thin, ephemeral copy-on-write (COW) scratch disk atop the read-only PBS backing store.

  • ✓ Instant Provisioning: Storage is prepared in under 500 milliseconds regardless of VM disk size.
  • ✓ Zero Disk Waste: Writes made during boot are contained within a temporary memory or NVMe scratch overlay.
  • ✓ Safe Concurrency: Multiple validation drills can run simultaneously on the same PBS cluster.
OVERLAY DRIVERQEMU / BLOCK ENGINE
qemu-img create -f qcow2 \
  -b "nbd://pbs.internal:10809/vm-104-disk-0" \
  -F raw /run/certistack/scratch_vm104.qcow2

# Allocation: 0 bytes copied
# Time elapsed: 0.28s

03. Air-Gapped SDN Sandbox Boot

Test workloads boot within isolated virtual bridges controlled by Proxmox SDN. Strict iptables and nftables policies drop all egress traffic to corporate and production subnets, preventing IP conflicts and accidental production writes.

  • ✓ Complete LAN Isolation: Test VM retains original production IP address safely inside an isolated VLAN/VNet.
  • ✓ Synthetic Default Gateway: Local test runner emulates essential gateway responses to satisfy OS network daemons.
  • ✓ Fail-Closed Firewall: Any attempted outbound connection outside the test sandbox is dropped immediately.
NETWORK TOPOLOGYAIR-GAPPED VIRTUAL SDN
ZONE: sdn_zone_dr_isolated
BRIDGE: vmbr99 (VLAN 999)
GATEWAY STUB: 10.99.0.1 (Synthetic Runner)
TARGET VM IP: 10.99.0.10 (Preserved)
POLICY: DROP ALL TO 10.0.0.0/8 & WAN

04. Synthetic Health & State Probing

A green hypervisor indicator doesn't mean your application is functional. CertiStack executes synthetic multi-layer checks to prove that database engines start, web endpoints respond, and critical systemd units reach target state.

  • ✓ Database Query Readiness: Executes non-mutating test queries against PostgreSQL, MySQL, and Redis.
  • ✓ HTTP/TLS Endpoint Probes: Validates SSL certificates, HTTP response status codes, and response headers.
  • ✓ Guest-Agent Telemetry: Verifies kernel startup, filesystem mounts, and service targets without SSH keys.
PROBE EXECUTIONMULTI-LAYER HARNESS
[PROBE: OS]       systemd: default.target -> ACTIVE (140ms)
[PROBE: DB]       tcp://10.99.0.10:5432   -> SYN/ACK (12ms)
[PROBE: SQL]      SELECT count(*) FROM db -> 2,419,082 (24ms)
[PROBE: HTTP]     GET /healthz            -> 200 OK (8ms)
[RESULT]          ALL 4 PROBES PASSED (0 FAILS)

05. Cryptographic Attestation & Clean Teardown

Upon probe completion, CertiStack seals run telemetry with an Ed25519 digital signature. The temporary VM is immediately halted and the COW scratch disk unlinked, leaving zero lingering state or storage drift.

  • ✓ Ed25519 Proof Bundle: Tamper-evident attestation artifact verifiable with standard open-source tools.
  • ✓ Automated Garbage Collection: Atomic teardown ensures zero orphaned disks, stale taps, or dangling locks.
  • ✓ Audit Compliance: Machine-readable reports ready for ingestion into GRC platforms and insurance binders.
PROOF BUNDLEEd25519 SIGNED ATTESTATION
{
  "status": "VALIDATED",
  "timestamp": "2026-09-30T16:00:05Z",
  "runtime_duration": 4.168,
  "signing_key_id": "node01-clift-infra",
  "signature": "0a174f88e1bc98d47b0e45f917540263f350c388..."
}

PBS Backup Verify vs. CertiStack Execution

Proxmox Backup Server provides exceptional backup verification at rest, but a healthy chunk hash does not prove your guest operating system or production application will boot and recover.

Validation Capability PBS Backup Verify (At Rest) CertiStack Engine (In Sandbox)
Verification Scope Read-only SHA-256 chunk checks at rest Live boot execution in air-gapped sandbox
OS & Kernel Driver Health Untested (treated as opaque disk blocks) Boots the guest and confirms it is running over QMP; optional guest-agent service checks
Filesystem & Database Recovery Undetected broken WALs or dirty states Boots the guest so its own filesystem and database recovery runs, then probes the service
Application Layer Health No service port or API validation Synthetic TCP, HTTP, DNS, and LDAP probes
Restore Speed & Storage Overhead Reads all chunks sequentially across network Disposable zero-copy COW overlays
Network & Routing Isolation N/A (offline backup store check) Ephemeral SDN bridge with zero default gateway
Audit & Compliance Proof PBS daemon syslog text entries Portable Ed25519-signed JSON evidence; HTML/PDF auditor binders in Enterprise Edition
Why Chunk Checksums Are Necessary, but Not Sufficient: A backup can have 100% valid chunk hashes while containing an unbootable kernel upgrade, a corrupted database transaction, or broken static IP configurations. CertiStack complements PBS by providing the missing execution layer: proving that the recovered system boots and serves production traffic.

Inspect the evidence shape

This redacted example shows the fields produced by the CLI. It is not retained lab evidence or a signed production report; generate and verify a report from your own approved run.

{
  "report_schema_version": "1.5",
  "report_id": "example-report-id",
  "timestamp": "2026-01-01T00:00:00Z",
  "plan_id": "example-recovery-plan",
  "plan_name": "Illustrative recovery validation",
  "environment": "example-lab",
  "node_fqdn": "pve-node-01.example.com",
  "validation_mode": "full_integrity",
  "engine_version": "dev",
  "git_commit": "not-published",
  "frameworks": [],
  "retention_days": 0,
  "rto_seconds": 0,
  "vm_records": [
    {
      "vmid": 9001,
      "source_vmid": 101,
      "name": "example-http-01",
      "boot_duration_seconds": 0,
      "source_snapshot": "pbs.example.com:backup/vm/9001/2026-01-01T00:00:00Z",
      "source_disks": [{"slot": "scsi0", "archive": "drive-scsi0.img.fidx"}],
      "network_recovery_address": "192.0.2.11",
      "restored_hardware": {"from_backup_config": true, "cores": 2, "sockets": 1, "memory_mb": 2048, "cpu": "host", "scsihw": "virtio-scsi-single", "ostype": "l26", "nic_model": "virtio"},
      "probe_results": [
        {"type": "http", "target": "http://192.0.2.11:80/healthz", "description": "Example HTTP health probe", "passed": true, "duration": 0}
      ]
    },
    {
      "vmid": 9002,
      "source_vmid": 102,
      "name": "example-service-01",
      "boot_duration_seconds": 0,
      "source_snapshot": "pbs.example.com:backup/vm/9002/2026-01-01T00:00:00Z",
      "source_disks": [
        {"slot": "scsi0", "archive": "drive-scsi0.img.fidx"},
        {"slot": "scsi1", "archive": "drive-scsi1.img.fidx"}
      ],
      "network_recovery_address": "192.0.2.31",
      "probe_results": [
        {"type": "tcp", "target": "192.0.2.31:5432", "description": "Example TCP service probe", "passed": true, "duration": 0}
      ]
    }
  ],
  "teardown_evidence": {
    "vm_stopped_and_destroyed": true,
    "overlay_files_removed": [],
    "loop_devices_unmapped": [],
    "orphan_sweep_clean": true,
    "all_cleaned": true,
    "verified_at": "example-only"
  },
  "all_passed": true
}

Report field summary

Plan: example-recovery-plan • Node: pve-node-01.example.com
ILLUSTRATIVE ONLY
Report ID example-report-id
Execution RTO Recorded per run
Source Mutation Source remains read-only
Hypervisor Node Recorded per run
Storage Overlay COW Loopback
Network Isolation Air-Gapped SDN
Report signing:
Real reports can include an operator-managed Ed25519 public key and signature.
This illustrative example intentionally contains no verification key or signature.
operator@example.com:~$ certistack verify-report report.json --public-key trusted_signer.pub
[example] Read the report and trusted signer keyring...
[example] A real run reports signature validity and retained teardown evidence here.
[example] Verify your own report with the trusted public key and retained run evidence.
[example] STATUS: RUN-SPECIFIC RESULT; NOT A CERTIFICATION

Comprehensive Documentation

A complete, self-hostable documentation suite compiled with Material for MkDocs, covering deployment, architecture, command and configuration references, YAML schemas, report verification, scheduling, and lab runbooks.

Quickstart

Ten commands to a signed report

Install the CLI, create a signing key, copy the minimal plan, run it against one backup, and verify the evidence.

Architecture

Controller Deployment

Deployment patterns for management VMs, temporary node workers, and isolation boundaries.

Operations

Automation & Scheduling

Run validations nightly with systemd or cron, verify each report, and get told when a recovery fails.

Reference

CLI Reference

Every command and flag, the exit statuses scripts rely on, and the checks the node diagnostic runs.

Reference

Configuration Reference

Every environment variable, the protected environment file, precedence, and the files kept on the controller and the node.

Configuration

Test-Plan Schema

Complete YAML reference for VMs, disks, ephemeral networks, timeouts, and synthetic probes.

Examples

Example Plans

Copy-ready plans for a single VM, a three-tier Linux application, and a Windows domain, with a guide to choosing probes.

Evidence

Reports & Verification

What a signed report contains, how keys and keyrings work, and how an auditor verifies one with or without CertiStack.

Deep Dive

System Architecture

Detailed recovery flows, zero-copy COW loopbacks, air-gapped sandboxes, and fail-closed teardown.

Diagnostics

Troubleshooting

Operational diagnostics, SSH and setup errors, QEMU guest agent timeouts, SDN bridge states, and recovery logging.

FAQ

Frequently Asked Questions

Short answers on safety, supported versions, scheduling, reports, licensing, and where to get help.

Governance

Release Readiness

Documented test-plan coverage, required lab evidence, campaign safety controls, and approval criteria.

Self-Hostable Documentation Portal

Browse every guide with instant offline search, code snippets, and deployment references.

Launch Documentation Portal →

Commercial licensing

Community Edition is free and open source. Homelab+, Team, and MSP Fleet are Enterprise Edition subscriptions bought online; the signed license file is emailed on payment. The Enterprise daemon is installed on each Proxmox VE node it validates. Enterprise Scale is a negotiated agreement.

Monthly Billing Annual Billing

Prices are in US dollars. To subscribe or request a license, contact sales directly at sales@certistack.dev. Already subscribed? Manage your subscription.

Open Community

Community

Free and open source under AGPLv3, for any use that complies with the license.

$0 forever
  • GNU Affero General Public License v3.0 (AGPLv3)
  • No node or VM cap — commercial use permitted
  • Full local CLI runner (certistack run)
  • Zero-copy COW loopback on PVE & PBS
  • Synthetic probes (TCP, HTTP/HTTPS, DNS, LDAP, guest agent)
  • Ed25519-signed JSON evidence and pinned-key verification
Browse Source Repository
Professional Team

Team

Commercial licensing and the management plane for internal engineering teams.

$89 /month
  • Up to 25 protected workloads
  • Management daemon, dashboard, and HTTP API
  • Compliance binders and outbound webhooks
  • Need more capacity? Contact sales
Contact Sales →
Datacenter & Sovereign

Enterprise Scale

Multi-datacenter, sovereign air-gapped, and compliance-mandated enterprise infrastructure.

Custom Inquiry
  • Deployment, security, and capacity scope defined in writing
  • Support commitments agreed per contract
  • Security review and procurement handled directly
Contact Enterprise Sales →