cofferFS

File encryption for Linux

Your vault.
Your filesystem.

One encrypted file. Everything you want to keep private, inside. cofferFS turns it into a regular folder — and grows with your data.

Open source under the MIT license. Mount without root.

~/vaultbash

# Make room for private files

$ coffer create vault.coffer

# Open it like a regular folder

$ coffer mount vault.coffer ~/vault

$ cp -r ~/Documents/privat ~/vault/

# All done? Close your vault.

$ coffer umount ~/vault

vault.cofferAES-256 · SQLCipher
One fileYour encrypted container
No fixed size upfrontGrows as you write
Your toolscp, mv, rsync and your editor

Familiar to use. Encrypted on disk.

A folder when you need it.
A vault when you close it.

vault.cofferEncrypted SQLCipher database
Password + FUSE
~/vault/Documents / Photos / Projects

Adapts to your data

No fixed container size, no manual resizing. The file grows as you write. After large deletions, coffer compact reclaims unused space.

Fits your workflow

FUSE exposes the container as a directory. Copy files, use your file manager or edit documents directly with your usual applications.

Built on proven components

SQLCipher encrypts with AES-256-CBC. HMAC-SHA512 protects page integrity; SQLite journaling helps keep the container consistent if a process stops unexpectedly.

Set up in a few commands

Your files.
Under lock.

Install the package for your Linux distribution and architecture. Then create your first vault.

Download Linux packages

Debian / Ubuntu · Fedora / Enterprise Linux · openSUSE
Packages for x86-64 and ARM64

Create your first vault

With the alias work, you only need to specify the paths once.

coffer create ~/.coffer/work.coffer \
  --save work --mountpoint ~/vault
coffer mount
ls ~/vault
coffer umount

You will be asked for your password when creating and mounting the vault.

See all installation methods

Good to know

Clear scope.
Open source.

For personal documents, photos and projects on Linux. Only one process can mount a container at a time.

Can I back up an open vault?

Yes. coffer backup work DEST creates a consistent copy, even while the container is mounted. Use this command for backups.

Can the vault close automatically?

Yes, optionally. Set --idle-timeout 30m when registering or mounting a vault to unmount it after 30 minutes of inactivity.

What are the limitations?

cofferFS is Linux-only and is not optimized for many multi-gigabyte files. Anyone with the password can access all contents; Unix permissions stored inside the container are not enforced.

Where can I find technical details?

The technical reference on GitHub covers architecture, operation and packaging. Report bugs and suggestions through GitHub Issues.