The Chassis for the Open-Core Edge: Inside duplicati/console-common
How an opinionated .NET library uses built-in Web Application Firewalls and RSA-verified feature gating to turn a self-hosted backup tool into a managed enterprise platform.
- The console-common library embeds a Web Application Firewall directly into its middleware to protect zero-trust edge deployments without relying on external proxies.
- A hybrid RSA-SHA256 licensing engine allows both cloud-verified and air-gapped feature gating within an MIT-licensed codebase.
- Duplicati's shift toward remote management prioritizes a centralized Web UI and integrated BetterStack telemetry over the single-node CLI approach of its competitors.
The Open-Core Paradox
Duplicati built its reputation as a beloved, self-hosted backup utility for power users. But the duplicati/console-common repository represents a fundamental architectural pivot. It is not merely a collection of shared utilities. It is the hardened enterprise chassis built to support a new era of centralized, remote backup management.
Excited to announce a major update to the Duplicati Console: Remote Backup Management. The console is now your one stop shop for easily deploying, managing, and monitoring Duplicati's zero trust, open source backup at scale.
The paradox lies in the code itself. This MIT-licensed repository contains strict, proprietary-style licensing logic and opinionated security filters. It is a masterclass in how to professionalize an open-source codebase for a zero-trust environment.
Defense-in-Depth: The Built-In WAF
Most modern web applications outsource edge security to external proxies like Cloudflare. Duplicati assumes a more hostile deployment reality. The ScanningFilterMiddleware.cs file implements a lightweight Web Application Firewall directly within the ASP.NET Core pipeline.
This middleware actively scans incoming requests against a hardcoded blacklist. It blocks PHP requests, local file inclusions, and NoSQL injection attempts at the edge. By wrapping the standard .NET rate limiter into a simplified configuration, it ensures that even directly exposed, self-hosted instances maintain a hardened security posture.
Cryptography for Feature Gating
The business model of open-core relies on enforcing commercial boundaries. In console-common, this is handled by the LicenseChecker. It uses an embedded RSA public key to verify signatures via the JsonSignature library.
The system is remarkably flexible. The licensing logic supports multiple ingestion prefixes, allowing operators to supply keys via remote HTTP verification or through air-gapped files. A unified EnsureFeatures extension method allows the application to cleanly gate specific enterprise features behind these cryptographic checks.
The Developer's Inner Loop
Enterprise software requires enterprise operational maturity. The repository's ConfigSetup and CommonLoggingConfig modules streamline the developer experience and telemetry pipelines. Instead of relying on insecure local environment variables, the system integrates directly with 1Password vaults for secret management.
// Example of dynamic log enrichment using reflection
public static void AddCommonLogging(this IServiceCollection services, LoggingExtras extras)
{
Log.Logger = new LoggerConfiguration()
.Enrich.WithProperty("ClientIp", extras.ClientIp)
.Enrich.WithProperty("CorrelationId", extras.CorrelationId)
.WriteTo.BetterStack(extras.ApiKey)
.CreateLogger();
}
Observability is elevated to a first-class citizen. The logging configuration automatically enriches every event with client IPs and correlation IDs, pushing the structured data directly to BetterStack. This cloud-native telemetry is crucial for managing fleets of distributed backup agents.
The Race for the Central Console
The backup ecosystem is crowded with highly efficient command-line tools. However, managing these tools across dozens of nodes requires external orchestration. Duplicati's new architecture directly targets this gap.
| Feature | Duplicati (Console) | Restic | Duplicacy |
|---|---|---|---|
| Target Audience | Enterprise / Managed | Power Users / Sysadmins | Prosumers |
| Primary Interface | Native Web UI | CLI-First | Web UI (Paid) |
| Multi-Node Management | Built-in via Console | Requires external tooling | Requires separate setup |
| Telemetry Integration | Native BetterStack | Text logs / Stdout | Basic logging |
By centralizing orchestration, security, and licensing into a shared common library, Duplicati creates a scalable foundation. It trades the raw simplicity of a single binary for the robust, auditable infrastructure required by modern IT teams.