Encryption and decryption
PeppyKeep uses .ppk for plaintext archives and .ppke for encrypted ones. New flow: ppk encrypt / ppk decrypt; backup encrypt-artifact and restore decrypt remain for legacy automation.
ppk encrypt --input backup.ppk --output backup.ppke --apply
ppk decrypt --input backup.ppke --output backup.ppk --apply
Encryption needs the public key; decryption needs the private key. Pass passphrases via env vars or the terminal—never shell history, scripts, or tickets. Dry-run without --apply first to confirm inputs, outputs, and key paths.
See ppk encrypt and ppk decrypt for parameters.