Skip to main content

nself backup

nself backup — ɳSelf documentation.

Backup operations: create, list, restore, verify, prune, config, status, init-key.

Synopsis

nself backup <subcommand> [flags] [args]

Description

nself backup covers the full life cycle of project backups: full Postgres dumps, write-ahead-log (WAL) checkpoints, MinIO object snapshots, configuration metadata, and combined backups. Backups can be encrypted with age (one keypair per project) and pruned by retention policy.

Subcommands include create (one-shot full or incremental), list (filter by remote, environment, age), restore (from any backup ID or latest, with point-in-time recovery and partial restore options), verify (checksum or full restore-test in a disposable container), and prune (apply daily/weekly/monthly retention).

backup config --install-cron installs systemd timers for full backups, WAL checkpoints, prune cycles, and weekly verify drills so an operator can hand off to automation.

Subcommands

Name Description
create Create a new backup
list List available backups
restore <backup-id|latest> Restore from a backup
restore-remote Stream and restore a backup directly from a remote URL (no disk write)
verify <backup-id|latest> Verify backup integrity
drill Run a DR drill: restore latest backup into scratch DB and measure RTO
resume <backup-id> Resume an interrupted streaming backup
stream Stream an encrypted backup directly to a remote destination (S3/R2/B2/GCS/Azure)
schedule Schedule recurring streaming backups via systemd timers
prune Remove old backups by retention policy
config View or install backup configuration (systemd timers)
status Show backup subsystem status
init-key Generate age encryption keypair for backups

Flags

backup create

Flag Default Description
--type full Backup type: full, wal, metadata, minio, all
--remote "" Remote name override
--encrypt false Force encryption on
--no-encrypt false Force encryption off
--tag "" Human label for this backup
--dry-run false Preview only

backup list

Flag Default Description
--remote "" Filter by remote name
--env "" Filter by environment
--since "" Show backups newer than duration (e.g. 24h, 7d)
--format table Output format: table or json

backup restore <backup-id\|latest>

Flag Default Description
--to "" Restore to alternate directory
--only "" Restore subset: pg, minio, metadata (comma-separated)
--point-in-time "" ISO8601 timestamp for PITR
--decrypt-key "" Path to age identity file
--yes false Skip confirmation

backup verify <backup-id\|latest>

Flag Default Description
--restore-test false Spin up test container and restore
--cleanup true Remove test container after verify
--keep false Keep test container for inspection

backup prune

Flag Default Description
--dry-run false Preview only
--keep-daily 7 Keep last N daily backups
--keep-weekly 4 Keep last N weekly backups
--keep-monthly 12 Keep last N monthly backups
--format "" Output format: json

backup config

Flag Default Description
--format "" Output format: json
--install-cron false Install systemd timers for backup, WAL, prune, verify
--full-at 03:00 Full backup time UTC (HH:MM) when --install-cron
--wal-every 15m WAL checkpoint interval when --install-cron
--prune-at 04:00 Prune time UTC (HH:MM) when --install-cron
--verify-on Sun Weekly restore-test day when --install-cron
--verify-at 05:00 Weekly restore-test time UTC when --install-cron
--remote "" Override configured remote when --install-cron
--unit-dir /etc/systemd/system Systemd unit directory when --install-cron
--dry-run false Print unit files without writing when --install-cron

backup status

Flag Default Description
--format "" Output format: json

backup drill

Flag Default Description
--file most recent Backup file to drill against
--rto-hours 4 RTO target in hours; 0 disables the gate
--dry-run false Validate inputs and exit without restoring
--json false Emit DrillResult as JSON to stdout

backup stream

Flag Default Description
--to "" Destination URL (rclone remote path)
--recipient none Encryption recipient: age key, SSH key, or github:<username> (repeatable)
--dry-run false Preview without running

backup restore-remote

Flag Default Description
--from "" Source URL (rclone remote path)
--key "" Path to age identity file for decryption
--yes false Skip confirmation on production

backup schedule

Flag Default Description
--cron "" Cron expression (e.g. 0 2 * * *)
--to "" Destination URL (rclone remote path)
--recipient "" Default encryption recipient
--unit-dir /etc/systemd/system Systemd unit directory
--dry-run false Print unit files without writing

Examples

# Generate the age keypair before first encrypted backup
nself backup init-key

# Create a full encrypted backup tagged for traceability
nself backup create --type full --encrypt --tag pre-deploy

# List backups newer than a week, JSON for piping
nself backup list --since 7d --format json

# Restore latest backup, restoring only Postgres data
nself backup restore latest --only pg --yes

# Verify the latest backup with a real restore-test container
nself backup verify latest --restore-test

# Install systemd timers so backups run automatically
sudo nself backup config --install-cron --full-at 02:30

See Also