Get Started

Your folders, in your clouds. Back up your files to every cloud you connected, check every copy, and free the space here once they're safe. Nothing runs in the background, and your files never pass through Local Link's servers.

Needs: macOS or Linux, the bucket plugin (lnk up buckets), and an account with a cloud (AWS, Google Cloud, any S3 storage, or an external drive). Storage and downloads are billed by your cloud. Share links also need a Local Link account (lnk auth login).

Quickstart

lnk up buckets                          # install the bucket plugin
lnk bucket create aws                   # a bucket in your aws account; connects it first if needed
lnk bucket push photos/2019             # ~/Link/Personal/photos/2019 to every cloud, then checked
lnk bucket tree -L 2                    # what's where, per cloud; works offline
lnk bucket clean photos/2019            # delete here, only if every cloud has a checked copy
lnk bucket pull 'photos/2019/**/*.jpg'  # back from the cheapest cloud, checked

Paths are in ~/Link/Personal or an agent's files folder (~/Link/Agents/<name>/Home). A relative path starts from the current folder when you're in one of them, else from ~/Link/Personal. pull, remove and share take globs: quote them, and use ** to span folders.

Connect a cloud

lnk bucket create aws --profile work       # connects that ~/.aws login as the account aws, then makes the bucket
lnk bucket create gcp                      # signs you in with gcloud, in the browser (needs gcloud)
lnk bucket create gcp --cloud ci           # as the account ci, e.g. a service account's
lnk bucket create s3 --endpoint https://<account>.r2.cloudflarestorage.com --key-id <id>
lnk bucket create folder /Volumes/MyDrive  # an external drive
lnk bucket create b2                       # any rclone storage; rclone asks what it needs
lnk bucket clouds                          # what's connected, and what each holds

create makes a private bucket for your files, once per cloud, and tests the keys. If a test fails after the bucket is made, it deletes the bucket again, or says which one it couldn't. Connect as many clouds as you like: push copies to every one.

On AWS and Google Cloud a bucket signs in as a cloud account from lnk cloud connect, the same one your boxes there use. create connects it first when there's none, asking what lnk cloud connect asks. A service account connects there, with its key: lnk cloud connect gcp --name ci --key-file key.json.

  • --name <n>: have two clouds of one kind.
  • --cloud <account>: the cloud account to sign in as (aws, gcp). Default: the one named like the cloud.
  • --region <r>: where new buckets go. aws defaults to the account's region.
  • --profile <p>, --key-id <id>: the login to connect the account with (aws), or an access key (s3). The secret is asked for.
  • --encrypt: encrypt your files and their names before upload. Link makes a password and shows it once; lose it and nobody can read the files.

Back up

lnk bucket push photos/2019
lnk bucket push photos --to aws -- --bwlimit 10M --transfers 8

push sends files to every cloud at once, skips identical ones, and checks every copy it sent. With several clouds, each line of progress starts with its cloud's name. A file with the same size and modification time as when its copy was last checked is skipped without being read. It never deletes anything in a cloud, and never replaces a copy that differs from the file here.

  • --to <name>: only this cloud; repeat for several.
  • --replace: replace cloud copies that differ.
  • --all: send and check every file, unchanged ones too.
  • --archive: use the archive tier, about $1 per TB a month (see Archive old files).
  • -- <flags>: passed to rclone's copy.

Back up each agent's files

lnk bucket push ~/Link/Agents/work/Home
lnk agent stop -a work && lnk bucket clean ~/Link/Agents/work/Home

Each agent's files folder goes to a bucket of its own in every cloud, made on its first push and always encrypted, with one password per agent. The same commands work on it. pull and clean refuse there while the agent runs, or when Link can't tell, so stop it first.

An agent's buckets move with it (agents). On a box, it backs up with a key that reaches only its bucket. If its machine is gone, lnk agent restore finds its bucket in your lnk cloud accounts.

Get files back

lnk bucket pull 'photos/2019/**/*.jpg'
lnk bucket pull photos/2019 --from gcp

pull copies each file from the cheapest cloud that has it and checks it. Downloading from aws or gcp costs about $90 per TB, so it asks before an archive restore or more than 1 GB of charged downloads. It never overwrites a file that differs unless --replace.

See what's where

lnk bucket tree -L 2
lnk bucket tree photos --refresh   # list the clouds again first

Each file gets one mark per cloud: ✓ checked, A checked in an archive tier, ? not checked, ≠ differs, ✗ missing. tree works offline; --refresh finds files pushed from another machine. -d shows folders only, --json prints one entry per file.

Use a bucket from another machine

lnk bucket connect aws --bucket local-link-a1b2c3d4e5f6
lnk bucket connect folder /Volumes/MyDrive --bucket local-link/personal
lnk bucket connect aws --bucket <b> --agent-bucket <b> --agent main  # asks for the agent's password

connect takes the same options as create but makes nothing: it stops if the bucket isn't there. lnk bucket clouds --json on the first machine shows each bucket's name.

Free up space

lnk bucket clean photos/2019 --dry-run   # say what would be deleted
lnk bucket clean photos/2019

clean checks every cloud again, now, and deletes the files here only if every cloud has a copy with the same checksum. Otherwise it says what's missing where. It's the only Link command that deletes your files here.

Archive old files

lnk bucket push old/scans --archive

lnk asks before archiving or restoring; --yes doesn't ask. Archive tiers cost about $1 per TB a month instead of about $20. They exist on aws (S3 Glacier Deep Archive) and gcp (GCS Archive). Reading them back costs money; on aws, pull requests a restore that takes up to 12 hours, so run it again once it's done. Deleting early is charged anyway: 180 days on aws, 365 on gcp, lnk bucket delete included. clean works on archived files without a restore, but for a file over 200 MiB on aws, whose copy it reads back (why).

lnk bucket share 'photos/2019/*.jpg'                   # prints https://<you>.local.link/b/<id>
lnk bucket share notes.pdf --expires 12h --auth friend:secret
lnk bucket shares                                      # your links, from every machine
lnk bucket unshare k3j2h4g5f6d7s8a9q1w2e3r4            # end one now

Anyone with the link can open it in a browser for up to 7 days. The files download straight from your cloud, never through Local Link.

  • --expires <time>: 30m, 12h, 3d, at most 7d (the default).
  • --auth user:password: visitors need the password. Prefer LINK_AUTH, since other users can see command-line flags.
  • --from <name>: link only to copies in this cloud.

It shares only your files (~/Link/Personal) from aws and s3 clouds, outside archive tiers. It uses what the manifest knows, so run tree --refresh first for files pushed from elsewhere. A file keeps its path from where the pattern starts: photos/2019/*.jpg shares beach.jpg, photos/2019 shares 2019/beach.jpg. unshare can't recall URLs already handed out: they work until the link would have expired.

To download a share with Link installed:

lnk bucket pull https://<you>.local.link/b/<id>

It saves the files into the current folder, each checked against its size. --auth gives the password; --replace overwrites files with the same name.

Disconnect or delete

Delete from your clouds

lnk bucket remove old/drafts --from gcp

remove deletes copies from every cloud, or only those given with --from. It refuses to delete a file's last copy anywhere unless --everywhere.

Disconnect or delete a cloud

lnk bucket disconnect gcp   # forget it and its keys; deletes nothing in it
lnk bucket delete aws       # delete its buckets and everything in them, then forget it

disconnect prints the connect command that brings the cloud back. delete removes your files' and your agents' buckets; on a folder cloud, Link's folders in it. delete asks first, and refuses where a file's only copy is, unless --everywhere. disconnect asks only when the cloud holds a file's only copy.

Use rclone directly

lnk bucket rclone lsd aws:
lnk bucket rclone mount aws: ~/mnt

This is rclone itself, the same pinned version, with each connected cloud as a remote named after it, for what lnk bucket doesn't do, such as mount, sync and serve. Link's safety rules don't apply here: sync deletes. Run lnk bucket tree --refresh afterwards to catch up.

Where your settings live

Everything is in ~/.config/lnk/bucket/: which clouds are connected, their keys and encryption passwords, and what went where. On a Mac, the keys and passwords Link writes are in the Keychain instead.

lnk plugin remove bucket and lnk uninstall keep this folder. lnk uninstall --delete buckets deletes it, along with the only copy of encryption passwords Link made: save them first. Neither deletes anything in your clouds.

Troubleshooting

SymptomFix
"is in none of Link's folders"Move the files into ~/Link/Personal or an agent's folder
clean or pull refuses in an agent's folderlnk agent stop -a <name> first
"no cloud here that signs links"lnk bucket push <path> --to <aws or s3 cloud>, not archived
A share's download answers 403Link or signing credentials expired: share again
tree misses files from another machinelnk bucket tree --refresh
"that password doesn't open the files already in ..."Use the bucket's original password

Every flag: lnk bucket <command> --help. What's protected and what isn't: Security. Why it works this way: Decisions.