Skip to main content

python-bareos

python-bareos is a Python module to access a https://www.bareos.com backup system.

Packages for python-bareos are included in the Bareos core distribution and available via https://pypi.org/.

Documentation is available at https://docs.bareos.org/DeveloperGuide/PythonBareos.html

Preparations

Create some named consoles for testing:

root@host:~# bconsole
*configure add console name=user1 password=secret profile=operator TlsEnable=no
*configure add console name=user-tls password=secret profile=operator

This creates a console user with name user1 and the profile operator. The operator profile is a default profile that comes with the Bareos Director. It does allow most commands, but deny some dangerous commands (see show profile=operator), so it is well suited for this purpose. Futhermore, TLS enforcement is disabled for this console user.

For testing with TLS-PSK, we also create the user user-tls.

Examples

Calling bareos-director console commands

>>> import bareos.bsock
>>> directorconsole=bareos.bsock.DirectorConsole(address='localhost', port=9101, name='user1', password='secret')
>>> print(directorconsole.call('help').decode("utf-8"))

This creates a console connection to a Bareos Director. This connection can be used to call commands. These are the same commands as available via bconsole.

To connect to the default console instead, omit the name parameter:

>>> directorconsole = bareos.bsock.DirectorConsole(address='localhost', port=9101, password='defaultconsolepassword')

The result of the call method is a bytes object. In most cases, it has to be decoded to UTF-8.

Simple version of the bconsole in Python

>>> import bareos.bsock
>>> directorconsole = bareos.bsock.DirectorConsole(address='localhost', port=9101, password='secret')
>>> directorconsole.interactive()

Or use the bconsole.py script:

bconsole.py --debug --name=user1 --password=secret localhost

Use JSON objects of the API mode 2

Requires: Bareos >= 15.2

The class DirectorConsoleJson is inherited from DirectorConsole and uses the Director Console API mode 2 (JSON).

For general information about API mode 2 and what data structures to expect, see https://docs.bareos.org/DeveloperGuide/api.html#api-mode-2-json

Example:

>>> import bareos.bsock
>>> directorconsole = bareos.bsock.DirectorConsoleJson(address='localhost', port=9101, password='secret')
>>> pools = directorconsole.call('list pools')
>>> for pool in pools["pools"]:
...   print(pool["name"])
...
Scratch
Incremental
Full
Differential

The results the the call method is a dict object.

In case of an error, an exception, derived from bareos.exceptions.Error is raised.

Example:

>>> directorconsole.call("test it")
Traceback (most recent call last):
...
bareos.exceptions.JsonRpcErrorReceivedException: failed: test it: is an invalid command.

Transport Encryption (TLS-PSK)

Since Bareos >= 18.2.4, Bareos supports TLS-PSK (Transport-Layer-Security Pre-Shared-Key) to secure its network connections and uses this by default.

Unfortunately the Python core module ssl does support TLS-PSK only with Python >= 3.13. For some older versions of Python, the extra modules sslpsk3 (Python >= 3.7, see https://github.com/kuba2k2/sslpsk3) or sslpsk (Python <= 3.9, see https://github.com/drbild/sslpsk) offers limited support.

Fallback To Unencrypted Connections

Normally DirectorConsole tries to connect using the latest known protocol version. In order to allow connections in more environments, the DirectorConsole can fall back to older protocol versions. Specify protocolversion = None (or 0 as command line argument) to enable automatic fall back. If connecting via TLS-PSK fails, it falls back to the old, unencrypted protocol version. Depending on your bareos-director configuration, unencrypted connections will be accepted:

>>> import bareos.bsock
/.../bareos/bsock/lowlevel.py:39: UserWarning: Connection encryption via TLS-PSK is not available (TLS-PSK is not available in the ssl module and the extra module sslpsk is not installed).
>>> directorconsole=bareos.bsock.DirectorConsole(address='localhost', port=9101, name='user-tls', password='secret', protocolversion=None)
socket error: Conversation terminated (-4)
Failed to connect using protocol version 2. Trying protocol version 1.
>>> print(directorconsole.call('help').decode("utf-8"))

To enforce a encrypted connection, use the tls_psk_require=True parameter:

>>> import bareos.bsock
/.../bareos/bsock/lowlevel.py:39: UserWarning: Connection encryption via TLS-PSK is not available, as the module sslpsk is not installed.
>>> directorconsole=bareos.bsock.DirectorConsole(address='localhost', port=9101, name='user-tls', password='secret', tls_psk_require=True)
Traceback (most recent call last):
...
bareos.exceptions.ConnectionError: TLS-PSK is required, but not available.

In this case, an exception is raised, if the connection can not be established via TLS-PSK.

sslpsk3

The extra module sslpsk3 (see https://github.com/kuba2k2/sslpsk3) is an extended fork of sslpsk and extends the core module ssl by TLS-PSK.

It is installable via pip, see https://pypi.org/project/sslpsk3.

sslpsk

The extra module sslpsk (see https://github.com/drbild/sslpsk) extends the core module ssl by TLS-PSK.

At the time of writing, the lasted version installable via pip is 1.0.0 (https://pypi.org/project/sslpsk/), which is not working with Python >= 3.

For using python-bareos with TLS-PSK with Python >= 3 and Python <= 3.9 the latest version must by installed manually. At the time of writing, even the latest version (https://github.com/drbild/sslpsk/commit/d88123a75786953f82f5e25d6c43d9d9259acb62) does not support Python >= 3.10. However, Python >= 3.13 has direct support for TLS-PSK in the core ssl module.

Installing the sslpsk module manually:

git clone https://github.com/drbild/sslpsk.git
cd sslpsk
python setup.py build
python setup.py install

python-bareos will detect, that sslpsk is available and will use it automatically. This can be verified by following command:

>>> import bareos.bsock
>>> bareos.bsock.DirectorConsole.is_tls_psk_available()
True

Another limitation of the current sslpsk version is, that it is not able to autodetect the TLS protocol version to use.

In order to use it, specify tls_version with an appropriate protocol version. In most cases this should be tls_version=ssl.PROTOCOL_TLSv1_2, like in the following example:

>>> import ssl
>>> import bareos.bsock
>>> directorconsole = bareos.bsock.DirectorConsoleJson(address='localhost', user='user-tls', password='secret', tls_version=ssl.PROTOCOL_TLSv1_2)
>>> print(directorconsole.call('help').decode("utf-8"))

Release files for python-bareos 25.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for python-bareos 25.1.1
File Size Uploaded
python_bareos-25.1.1.tar.gz 37.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for python-bareos 25.1.1
File Interpreter ABI Platform
python_bareos-25.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 94.1 kB

Release files / python_bareos-25.1.1.tar.gz

Download URL python_bareos-25.1.1.tar.gz
Size 37.6 kB
Tags Source
SHA-256 checksum
How to use checksums
57eb713b3d80682e55512423dae00c8ceab896cea8bebd3d9c54676596cb4310
BLAKE2b-256 checksum
How to use checksums
d4fd2dbe7e4f12b7ba9d977668ed296cdab40241d36f545efbc0f2205564b8ac
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release files / python_bareos-25.1.1-py3-none-any.whl

Download URL python_bareos-25.1.1-py3-none-any.whl
Size 56.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9c333364bb22272f1f7ad9c533577b1eae942fcbd66b5acda519cce559c05be4
BLAKE2b-256 checksum
How to use checksums
7efab60f912b355ca05c51154af7d4d09152f86b3cbbe4753702b2fd4b87d765
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

25.1.1 This release

2 release files

25.0.2

2 release files

24.0.9

2 release files

24.0.7

2 release files

24.0.6

2 release files

24.0.4

2 release files

24.0.3

2 release files

24.0.2

2 release files

24.0.1

2 release files

24.0.0

2 release files

23.1.0

2 release files

23.0.2

2 release files

23.0.1

2 release files

23.0.0

2 release files

22.1.4

2 release files

22.1.3

2 release files

22.1.2

2 release files

22.1.1

2 release files

22.1.0

2 release files

22.0.3

2 release files

22.0.0

2 release files

21.1.9

2 release files

21.1.8

2 release files

21.1.7

2 release files

21.1.6

2 release files

21.1.2

2 release files

21.1.1

2 release files

21.1.0

2 release files

21.0.0

2 release files

20.0.6

2 release files

20.0.5

2 release files

20.0.4

2 release files

20.0.3

2 release files

20.0.2

2 release files

20.0.0

2 release files

19.2.9

2 release files

19.2.7

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page