Documentation
Introduction
DCTL moves and backs up data across cloud providers the way rclone does, with every byte encrypted client-side and nothing reported stored until it is provably stored.
DCTL is a command-line tool for copying, syncing, backing up and streaming data
across storage providers. If you have used rclone, the vocabulary will be
familiar — copy, sync, cat, mount, REMOTE:PATH addressing, the same
filter rules. That similarity is deliberate.
What is different is the contract underneath.
The one promise#
A run that says a file is stored is telling the truth.
Most transfer tools report success when the last byte leaves the machine. DCTL reports success when the bytes have been read back and checksum-verified at the destination, and the local index has durably committed that fact. A mismatch hard-aborts the run, deletes the staged object, and commits nothing.
There are no half-stored files, and no false copied lines in the log.
What follows from that#
Everything else in the design is downstream of the promise above, plus one assumption: that you are storing things you cannot afford to lose, for longer than any particular tool or provider will exist.
- Encryption is client-side and optional. A remote is either plain or a vault. Through a vault, both file contents and path names are encrypted before anything leaves the machine. The verified-write contract applies identically to both.
- Memory is bounded, whatever the file size. Chunked AEAD and constant-memory multipart keep peak memory flat as a file grows — measured at 139–144 MiB from a 256 MiB file to a 4 GiB one — and seeking into an object uses chunk-aware HTTP range requests. The current CLI copy path still refuses files over 1 GiB; lifting that is the next tracked milestone.
- The backend is authoritative. A fresh machine with only the password can rebuild the entire path map from the provider and restore byte-exact. There is no index backup to lose.
- The format outlives the tool. On-disk identifiers are brand-neutral and design-frozen, and a dependency-free C99 reference decoder proves a vault written today can be read with no Rust, no DCTL and no network.
Where to start#
Build it, create a vault, put and get files, and restore onto a bare machine with nothing but the password.
All commandsEvery verb, grouped by workflow rather than alphabetically.
dctl copyThe transfer verb to learn first — it never removes anything.
dctl syncThe one that deletes. Read it before you run it.
Security & threat modelWhat DCTL protects, and what it does not.
Project statusWhat is finished, what is partial, and what has not started.
A note on maturity#
DCTL is pre-1.0, and this documentation says so wherever it is relevant rather than letting you find out later.
The cryptographic core, the frozen on-disk format, the encrypted index and the
local filesystem backend are complete and exercised. mount and serve are
not usable yet — mount is a stub that validates its flags and then errors. The B2, S3 and R2 backends
are implemented but have not yet been verified end to end against live
providers. The CLI is mid-flight: the happy path is smoke-tested, some verbs
are partial.
Keep independent copies of anything irreplaceable. That is good advice with any tool, and honest advice with this one.
Licence, briefly#
DCTL is source-available under the PolyForm Noncommercial License 1.0.0.
Any noncommercial purpose is permitted, free and permanently:
- Personal use — research, experiment, study, private entertainment, hobby projects, amateur pursuits and religious observance, without any anticipated commercial application.
- Noncommercial organisations — charities, educational institutions, public research, public safety and health, environmental protection and government bodies. This holds regardless of the source of funding, so a publicly funded university is covered outright.
You may modify the source and redistribute your changes.
Any use by or for a business needs a commercial licence, including a proof of concept — the licence grants no trial period. Ask us for an evaluation licence; we would rather you tested properly.
Source-available is not open source
PolyForm licences are not OSI-approved, because they restrict who may use the software. If your organisation only permits OSI-approved licences, DCTL will not satisfy that policy without a commercial agreement. Better to know now.
The full text is at
polyformproject.org,
and in LICENSE.md in the repository. Plain-English detail on the
licence page.
Credit where it is due#
DCTL's architecture, addressing rules and feature set were heavily inspired by the excellent work of the Rclone project. DCTL is an independent implementation written from scratch in Rust, and is not affiliated with or endorsed by Rclone. If you want a mature tool with seventy backends today, use rclone — it is very good.