The Chassis for the Open-Core Edge: Inside duplicati/console-common

How an opinionated .NET library uses built-in Web Application Firewalls and RSA-verified feature gating to turn a self-hosted backup tool into a managed enterprise platform.

8 min read • View on GitHub • More from duplicati

A heavy industrial chassis being lowered onto a pristine engine block, illustrating enterprise guardrails integrating with an open-source core.
Dropping enterprise-grade infrastructure onto a consumer-friendly open-source core.
Key Takeaways

The Open-Core Paradox

Duplicati built its reputation as a beloved, self-hosted backup utility for power users. But the duplicati/console-common repository represents a fundamental architectural pivot. It is not merely a collection of shared utilities. It is the hardened enterprise chassis built to support a new era of centralized, remote backup management.

Excited to announce a major update to the Duplicati Console: Remote Backup Management. The console is now your one stop shop for easily deploying, managing, and monitoring Duplicati's zero trust, open source backup at scale.

Duplicati Inc, Organization · LinkedIn Announcement

The paradox lies in the code itself. This MIT-licensed repository contains strict, proprietary-style licensing logic and opinionated security filters. It is a masterclass in how to professionalize an open-source codebase for a zero-trust environment.

Defense-in-Depth: The Built-In WAF

Most modern web applications outsource edge security to external proxies like Cloudflare. Duplicati assumes a more hostile deployment reality. The ScanningFilterMiddleware.cs file implements a lightweight Web Application Firewall directly within the ASP.NET Core pipeline.

The simple security middleware acts as a request gauntlet, aggressively filtering out common attack vectors before they reach the application layer.

This middleware actively scans incoming requests against a hardcoded blacklist. It blocks PHP requests, local file inclusions, and NoSQL injection attempts at the edge. By wrapping the standard .NET rate limiter into a simplified configuration, it ensures that even directly exposed, self-hosted instances maintain a hardened security posture.

Cryptography for Feature Gating

The business model of open-core relies on enforcing commercial boundaries. In console-common, this is handled by the LicenseChecker. It uses an embedded RSA public key to verify signatures via the JsonSignature library.

A vault door with two keyholes, one receiving a physical brass key and the other a digital keycard, representing air-gapped and cloud-verified licenses.
The licensing engine supports multiple ingestion methods to accommodate both connected and isolated enterprise environments.

The system is remarkably flexible. The licensing logic supports multiple ingestion prefixes, allowing operators to supply keys via remote HTTP verification or through air-gapped files. A unified EnsureFeatures extension method allows the application to cleanly gate specific enterprise features behind these cryptographic checks.

The Developer's Inner Loop

Enterprise software requires enterprise operational maturity. The repository's ConfigSetup and CommonLoggingConfig modules streamline the developer experience and telemetry pipelines. Instead of relying on insecure local environment variables, the system integrates directly with 1Password vaults for secret management.

// Example of dynamic log enrichment using reflection
public static void AddCommonLogging(this IServiceCollection services, LoggingExtras extras)
{
    Log.Logger = new LoggerConfiguration()
        .Enrich.WithProperty("ClientIp", extras.ClientIp)
        .Enrich.WithProperty("CorrelationId", extras.CorrelationId)
        .WriteTo.BetterStack(extras.ApiKey)
        .CreateLogger();
}

Observability is elevated to a first-class citizen. The logging configuration automatically enriches every event with client IPs and correlation IDs, pushing the structured data directly to BetterStack. This cloud-native telemetry is crucial for managing fleets of distributed backup agents.

The Race for the Central Console

The backup ecosystem is crowded with highly efficient command-line tools. However, managing these tools across dozens of nodes requires external orchestration. Duplicati's new architecture directly targets this gap.

FeatureDuplicati (Console)ResticDuplicacy
Target AudienceEnterprise / ManagedPower Users / SysadminsProsumers
Primary InterfaceNative Web UICLI-FirstWeb UI (Paid)
Multi-Node ManagementBuilt-in via ConsoleRequires external toolingRequires separate setup
Telemetry IntegrationNative BetterStackText logs / StdoutBasic logging
A split scene comparing a single hand-tool against a complex command center switchboard.
While CLI tools excel at single-node efficiency, centralized platforms abstract orchestration behind unified dashboards.

By centralizing orchestration, security, and licensing into a shared common library, Duplicati creates a scalable foundation. It trades the raw simplicity of a single binary for the robust, auditable infrastructure required by modern IT teams.