nself backup
nself backup — ɳSelf documentation.
Backup operations: create, list, restore, verify, prune, config, status, init-key.
Synopsis
nself backup <subcommand> [flags] [args]
Description
nself backup covers the full life cycle of project backups: full Postgres dumps, write-ahead-log (WAL) checkpoints, MinIO object snapshots, configuration metadata, and combined backups. Backups can be encrypted with age (one keypair per project) and pruned by retention policy.
Subcommands include create (one-shot full or incremental), list (filter by remote, environment, age), restore (from any backup ID or latest, with point-in-time recovery and partial restore options), verify (checksum or full restore-test in a disposable container), and prune (apply daily/weekly/monthly retention).
backup config --install-cron installs systemd timers for full backups, WAL checkpoints, prune cycles, and weekly verify drills so an operator can hand off to automation.
Subcommands
| Name |
Description |
create |
Create a new backup |
list |
List available backups |
restore <backup-id|latest> |
Restore from a backup |
restore-remote |
Stream and restore a backup directly from a remote URL (no disk write) |
verify <backup-id|latest> |
Verify backup integrity |
drill |
Run a DR drill: restore latest backup into scratch DB and measure RTO |
resume <backup-id> |
Resume an interrupted streaming backup |
stream |
Stream an encrypted backup directly to a remote destination (S3/R2/B2/GCS/Azure) |
schedule |
Schedule recurring streaming backups via systemd timers |
prune |
Remove old backups by retention policy |
config |
View or install backup configuration (systemd timers) |
status |
Show backup subsystem status |
init-key |
Generate age encryption keypair for backups |
Flags
backup create
| Flag |
Default |
Description |
--type |
full |
Backup type: full, wal, metadata, minio, all |
--remote |
"" |
Remote name override |
--encrypt |
false |
Force encryption on |
--no-encrypt |
false |
Force encryption off |
--tag |
"" |
Human label for this backup |
--dry-run |
false |
Preview only |
backup list
| Flag |
Default |
Description |
--remote |
"" |
Filter by remote name |
--env |
"" |
Filter by environment |
--since |
"" |
Show backups newer than duration (e.g. 24h, 7d) |
--format |
table |
Output format: table or json |
backup restore <backup-id\|latest>
| Flag |
Default |
Description |
--to |
"" |
Restore to alternate directory |
--only |
"" |
Restore subset: pg, minio, metadata (comma-separated) |
--point-in-time |
"" |
ISO8601 timestamp for PITR |
--decrypt-key |
"" |
Path to age identity file |
--yes |
false |
Skip confirmation |
backup verify <backup-id\|latest>
| Flag |
Default |
Description |
--restore-test |
false |
Spin up test container and restore |
--cleanup |
true |
Remove test container after verify |
--keep |
false |
Keep test container for inspection |
backup prune
| Flag |
Default |
Description |
--dry-run |
false |
Preview only |
--keep-daily |
7 |
Keep last N daily backups |
--keep-weekly |
4 |
Keep last N weekly backups |
--keep-monthly |
12 |
Keep last N monthly backups |
--format |
"" |
Output format: json |
backup config
| Flag |
Default |
Description |
--format |
"" |
Output format: json |
--install-cron |
false |
Install systemd timers for backup, WAL, prune, verify |
--full-at |
03:00 |
Full backup time UTC (HH:MM) when --install-cron |
--wal-every |
15m |
WAL checkpoint interval when --install-cron |
--prune-at |
04:00 |
Prune time UTC (HH:MM) when --install-cron |
--verify-on |
Sun |
Weekly restore-test day when --install-cron |
--verify-at |
05:00 |
Weekly restore-test time UTC when --install-cron |
--remote |
"" |
Override configured remote when --install-cron |
--unit-dir |
/etc/systemd/system |
Systemd unit directory when --install-cron |
--dry-run |
false |
Print unit files without writing when --install-cron |
backup status
| Flag |
Default |
Description |
--format |
"" |
Output format: json |
backup drill
| Flag |
Default |
Description |
--file |
most recent |
Backup file to drill against |
--rto-hours |
4 |
RTO target in hours; 0 disables the gate |
--dry-run |
false |
Validate inputs and exit without restoring |
--json |
false |
Emit DrillResult as JSON to stdout |
backup stream
| Flag |
Default |
Description |
--to |
"" |
Destination URL (rclone remote path) |
--recipient |
none |
Encryption recipient: age key, SSH key, or github:<username> (repeatable) |
--dry-run |
false |
Preview without running |
backup restore-remote
| Flag |
Default |
Description |
--from |
"" |
Source URL (rclone remote path) |
--key |
"" |
Path to age identity file for decryption |
--yes |
false |
Skip confirmation on production |
backup schedule
| Flag |
Default |
Description |
--cron |
"" |
Cron expression (e.g. 0 2 * * *) |
--to |
"" |
Destination URL (rclone remote path) |
--recipient |
"" |
Default encryption recipient |
--unit-dir |
/etc/systemd/system |
Systemd unit directory |
--dry-run |
false |
Print unit files without writing |
Examples
# Generate the age keypair before first encrypted backup
nself backup init-key
# Create a full encrypted backup tagged for traceability
nself backup create --type full --encrypt --tag pre-deploy
# List backups newer than a week, JSON for piping
nself backup list --since 7d --format json
# Restore latest backup, restoring only Postgres data
nself backup restore latest --only pg --yes
# Verify the latest backup with a real restore-test container
nself backup verify latest --restore-test
# Install systemd timers so backups run automatically
sudo nself backup config --install-cron --full-at 02:30
See Also