Encrypted file sync between servers. Distribute binaries, configs, and other files over an authenticated, encrypted channel.
# Build
go build -o filesync .
# Generate a shared key (copy to all machines)
filesync keys generate --output /etc/filesync/key
# Start coordinator (source of truth)
filesync /srv/deploy --port 8400 --key /etc/filesync/key
# Connect peers (target servers)
filesync /srv/deploy --peer http://coordinator:8400 --key /etc/filesync/keyPeers poll every 5 seconds and sync bidirectionally. Newer files (by mtime) win.
- Files are encrypted with XChaCha20-Poly1305 in transit
- Every request is authenticated with HMAC-SHA256 (shared key)
- Peers and coordinator verify each other's key via mutual handshake
- Deletions propagate via tombstones (retained 30 days)
- File writes are atomic (temp file + rename)
- Go 1.25+
- Linux (uses inotify for filesystem watching)
- Same key file on all machines