Adapts to your data
No fixed container size, no manual resizing. The file grows as you write. After large deletions, coffer compact reclaims unused space.
File encryption for Linux
One encrypted file. Everything you want to keep private, inside. cofferFS turns it into a regular folder — and grows with your data.
Open source under the MIT license. Mount without root.
# Make room for private files
$ coffer create vault.coffer
# Open it like a regular folder
$ coffer mount vault.coffer ~/vault
$ cp -r ~/Documents/privat ~/vault/
# All done? Close your vault.
$ coffer umount ~/vault
Familiar to use. Encrypted on disk.
No fixed container size, no manual resizing. The file grows as you write. After large deletions, coffer compact reclaims unused space.
FUSE exposes the container as a directory. Copy files, use your file manager or edit documents directly with your usual applications.
SQLCipher encrypts with AES-256-CBC. HMAC-SHA512 protects page integrity; SQLite journaling helps keep the container consistent if a process stops unexpectedly.
Set up in a few commands
Install the package for your Linux distribution and architecture. Then create your first vault.
Download Linux packagesDebian / Ubuntu · Fedora / Enterprise Linux · openSUSE
Packages for x86-64 and ARM64
With the alias work, you only need to specify the paths once.
coffer create ~/.coffer/work.coffer \
--save work --mountpoint ~/vault
coffer mount
ls ~/vault
coffer umountYou will be asked for your password when creating and mounting the vault.
See all installation methodsGood to know
For personal documents, photos and projects on Linux. Only one process can mount a container at a time.
Yes. coffer backup work DEST creates a consistent copy, even while the container is mounted. Use this command for backups.
Yes, optionally. Set --idle-timeout 30m when registering or mounting a vault to unmount it after 30 minutes of inactivity.
cofferFS is Linux-only and is not optimized for many multi-gigabyte files. Anyone with the password can access all contents; Unix permissions stored inside the container are not enforced.
The technical reference on GitHub covers architecture, operation and packaging. Report bugs and suggestions through GitHub Issues.