[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs:\u002Fdocs\u002Foperators\u002Fbackups":3,"docs:nav":347,"docs:surround:\u002Fdocs\u002Foperators\u002Fbackups":559},{"id":4,"title":5,"body":6,"description":337,"extension":338,"launchGate":339,"meta":340,"navigation":341,"path":342,"seo":343,"stem":344,"stub":345,"__hash__":346},"docs_en\u002Fdocs\u002F4.operators\u002F2.backups.md","Backups",{"type":7,"value":8,"toc":325},"minimark",[9,13,24,29,124,127,131,138,158,161,164,168,183,202,208,212,218,269,275,279,285,292,303,307,310,314],[10,11,12],"p",{},"Velrix backs up three things: the platform’s own state, your volumes, and your virtual machines’ disks. Every backup is encrypted with its owner’s own key before it leaves the server, and only what changed since the last one is sent and stored.",[10,14,15,16,19,20,23],{},"Everything here is in the ",[17,18,5],"strong",{}," app. People and organisations back up their own machines and volumes there. Operators back up the platform in ",[17,21,22],{},"Manager › Platform backups",", which also holds the backup targets.",[25,26,28],"h2",{"id":27},"what-is-backed-up-and-how-consistent-it-is","What is backed up, and how consistent it is",[30,31,32,48],"table",{},[33,34,35],"thead",{},[36,37,38,42,45],"tr",{},[39,40,41],"th",{},"What",[39,43,44],{},"How",[39,46,47],{},"Consistency",[49,50,51,65,84,97,111],"tbody",{},[36,52,53,59,62],{},[54,55,56],"td",{},[17,57,58],{},"The platform’s state",[54,60,61],{},"Every module’s own data, all taken at the same moment from each module’s history.",[54,63,64],{},"One consistent state of every module.",[36,66,67,73,81],{},[54,68,69,72],{},[17,70,71],{},"A volume"," on a btrfs server",[54,74,75,76,80],{},"A read-only snapshot, sent with ",[77,78,79],"code",{},"btrfs send",".",[54,82,83],{},"As the snapshot’s moment.",[36,85,86,91,94],{},[54,87,88,90],{},[17,89,71],{}," on a server without btrfs",[54,92,93],{},"Its files, read as they are.",[54,95,96],{},"Files still being written may be caught half-way.",[36,98,99,105,108],{},[54,100,101,104],{},[17,102,103],{},"A virtual machine"," with the guest agent",[54,106,107],{},"Its file systems are frozen through the agent (fsfreeze on Linux) for the moment its disk is cloned, well under a second. Windows guests are frozen through VSS the same way, but restoring one has not yet been proven end to end: until it is, treat Windows backups as unverified.",[54,109,110],{},"Application-consistent.",[36,112,113,118,121],{},[54,114,115,117],{},[17,116,103],{}," without the agent",[54,119,120],{},"Its disk is cloned with the machine paused for a moment.",[54,122,123],{},"Crash-consistent: as after a power cut.",[10,125,126],{},"Each restore point says which one it is.",[25,128,130],{"id":129},"backup-targets","Backup targets",[10,132,133,134,137],{},"A target is where the encrypted copies are kept. Add one in ",[17,135,136],{},"Manager › Platform backups › Targets",":",[139,140,141,152],"ul",{},[142,143,144,147,148,151],"li",{},[17,145,146],{},"S3-compatible object storage",": Safespring, Elastx, or your own MinIO or Ceph. Enter the address (",[77,149,150],{},"https:\u002F\u002F…","), the bucket (which must exist), an optional folder in it, and an access key and secret key. The secret key is sealed at once and never shown again. Velrix talks only to the address you enter.",[142,153,154,157],{},[17,155,156],{},"A folder on the server",". Use this only with a separate disk mounted there: a backup on the same disk as the data is not a backup.",[10,159,160],{},"A target is tried before it is saved: a test object is written, read back and removed. If that fails, nothing is saved and you see why.",[10,162,163],{},"The target only ever sees encrypted objects with meaningless names. It learns their sizes and when they were written, nothing about what is in them or whose they are.",[25,165,167],{"id":166},"schedules-and-retention","Schedules and retention",[10,169,170,171,174,175,179,180,80],{},"Open ",[17,172,173],{},"Backups › Schedule",". An organisation’s schedule needs the ",[176,177,178],"em",{},"Manage backups"," permission; the platform’s needs ",[176,181,182],{},"Operate the platform’s backups",[139,184,185,191,196],{},[142,186,187,190],{},[17,188,189],{},"How often",": from every hour to weekly, counted from an hour you choose (in UTC).",[142,192,193,195],{},[17,194,41],{},": every machine, every volume, or both. The platform’s schedule covers every module.",[142,197,198,201],{},[17,199,200],{},"What to keep",": the newest points whatever their age, then the newest point of each of so many days, weeks, months and years. Points the rules no longer keep are deleted, with everything only they used.",[10,203,204,207],{},[17,205,206],{},"Back up now"," runs everything at once, or one machine or volume from its own page.",[25,209,211],{"id":210},"restoring","Restoring",[10,213,170,214,217],{},[17,215,216],{},"Backups › Restore points",", pick what to restore and the moment.",[139,219,220,245],{},[142,221,222,225,226],{},[17,223,224],{},"Restore beside"," (the default) leaves the original alone:\n",[139,227,228,231,242],{},[142,229,230],{},"a volume becomes a new volume, named after the original and the moment;",[142,232,233,234,237,238,241],{},"a machine is restored as a new machine: choose ",[17,235,236],{},"New machine",", the same image as the original, and pick the restore point in its ",[17,239,240],{},"From a backup"," tab;",[142,243,244],{},"a module’s state is saved as a file for you to look at.",[142,246,247,250,251],{},[17,248,249],{},"Restore in place"," replaces the original, after you confirm:\n",[139,252,253,256,259],{},[142,254,255],{},"a volume must be detached from its app first;",[142,257,258],{},"a machine is stopped, its disk replaced, and started again;",[142,260,261,262,265,266,80],{},"a module’s state is replaced. The other modules keep theirs, so what they hold about it may no longer match. To take the whole platform back to one moment, use ",[17,263,264],{},"Restore the platform to this moment"," on a platform run in ",[17,267,268],{},"Activity",[10,270,271,272,274],{},"Machines and volumes also have a ",[17,273,5],{}," tab on their own page.",[25,276,278],{"id":277},"the-recovery-key","The recovery key",[10,280,281,282],{},"Each owner’s backups are encrypted with their own key. The installation keeps it sealed, but if the installation is lost, its keys are lost with it. ",[17,283,284],{},"Without the key, nobody can read the backups, Velrix included.",[10,286,287,288,291],{},"So download the recovery key from ",[17,289,290],{},"Backups › Recovery key"," and keep it somewhere safe, apart from the installation: in a password manager, or printed in a safe. Every download is recorded.",[10,293,294,295,298,299,302],{},"To read backups on a new installation, add the same target, then in ",[17,296,297],{},"Manager › Platform backups › Recovery key"," use ",[17,300,301],{},"Recover"," with the owner and the key file. The restore points appear again and can be restored as usual.",[25,304,306],{"id":305},"when-something-goes-wrong","When something goes wrong",[10,308,309],{},"A backup that fails, a restore that fails, and a schedule with no good backup for two of its periods each become a notice to whoever set the schedule (operators for the platform), also by e-mail where the installation sends mail.",[25,311,313],{"id":312},"space-and-time","Space and time",[139,315,316,319,322],{},[142,317,318],{},"Backups are deduplicated: unchanged data is never sent or stored twice, across runs and across your machines and volumes. A second backup of an unchanged 1.3 GB machine took 7 seconds in our tests and stored about 1 MB.",[142,320,321],{},"While a backup runs, the server needs free space for one copy of the largest machine or volume being backed up.",[142,323,324],{},"In our tests on one server (NVMe, local S3), a machine with a 1.3 GB disk took 33 seconds to back up the first time, with the guest frozen for under 0.1 seconds; restoring it as a new machine took about a minute until it answered.",{"title":326,"searchDepth":327,"depth":328,"links":329},"",2,3,[330,331,332,333,334,335,336],{"id":27,"depth":327,"text":28},{"id":129,"depth":327,"text":130},{"id":166,"depth":327,"text":167},{"id":210,"depth":327,"text":211},{"id":277,"depth":327,"text":278},{"id":305,"depth":327,"text":306},{"id":312,"depth":327,"text":313},"Scheduled, encrypted backups of state, volumes and VM disks: where they are kept and how to restore them.","md",null,{},true,"\u002Fdocs\u002Foperators\u002Fbackups",{"title":5,"description":337},"docs\u002F4.operators\u002F2.backups",false,"MNDJNyCp59Pu29xircjIt-YFINT60bU0Bo6OpJAn29M",[348],{"title":349,"path":350,"stem":351,"children":352,"page":-1},"Docs","\u002Fdocs","docs",[353,357,387,414,448,516,530,552],{"title":354,"path":350,"stem":355,"stub":345,"launchGate":339,"icon":356},"Overview","docs\u002Findex","i-lucide-house",{"title":358,"stub":345,"launchGate":339,"icon":359,"path":360,"stem":361,"children":362,"page":345},"Get started","i-lucide-rocket","\u002Fdocs\u002Fget-started","docs\u002F1.get-started",[363,367,371,375,379,383],{"title":364,"path":365,"stem":366,"stub":345,"launchGate":339},"What Velrix is","\u002Fdocs\u002Fget-started\u002Fwhat-is-velrix","docs\u002F1.get-started\u002F1.what-is-velrix",{"title":368,"path":369,"stem":370,"stub":345,"launchGate":339},"Ways to run Velrix","\u002Fdocs\u002Fget-started\u002Fways-to-run","docs\u002F1.get-started\u002F2.ways-to-run",{"title":372,"path":373,"stem":374,"stub":345,"launchGate":339},"Install from USB","\u002Fdocs\u002Fget-started\u002Finstall","docs\u002F1.get-started\u002F3.install",{"title":376,"path":377,"stem":378,"stub":345,"launchGate":339},"The setup wizard","\u002Fdocs\u002Fget-started\u002Fsetup-wizard","docs\u002F1.get-started\u002F4.setup-wizard",{"title":380,"path":381,"stem":382,"stub":345,"launchGate":339},"Your first app","\u002Fdocs\u002Fget-started\u002Ffirst-app","docs\u002F1.get-started\u002F5.first-app",{"title":384,"path":385,"stem":386,"stub":345,"launchGate":339},"Your first VM","\u002Fdocs\u002Fget-started\u002Ffirst-vm","docs\u002F1.get-started\u002F6.first-vm",{"title":388,"stub":345,"launchGate":339,"icon":389,"path":390,"stem":391,"children":392,"page":345},"Concepts","i-lucide-lightbulb","\u002Fdocs\u002Fconcepts","docs\u002F2.concepts",[393,397,401,405,409],{"title":394,"path":395,"stem":396,"stub":341,"launchGate":339},"Realms","\u002Fdocs\u002Fconcepts\u002Frealms","docs\u002F2.concepts\u002F1.realms",{"title":398,"path":399,"stem":400,"stub":341,"launchGate":339},"Instances and hosts","\u002Fdocs\u002Fconcepts\u002Finstances-and-hosts","docs\u002F2.concepts\u002F2.instances-and-hosts",{"title":402,"path":403,"stem":404,"stub":341,"launchGate":339},"Modules and the mesh","\u002Fdocs\u002Fconcepts\u002Fmodules-and-the-mesh","docs\u002F2.concepts\u002F3.modules-and-the-mesh",{"title":406,"path":407,"stem":408,"stub":341,"launchGate":339},"Organisations, projects and permissions","\u002Fdocs\u002Fconcepts\u002Forgs-projects-permissions","docs\u002F2.concepts\u002F4.orgs-projects-permissions",{"title":410,"path":411,"stem":412,"stub":341,"launchGate":413},"Host pools","\u002Fdocs\u002Fconcepts\u002Fhost-pools","docs\u002F2.concepts\u002F5.host-pools","A1",{"title":415,"stub":345,"launchGate":339,"icon":416,"path":417,"stem":418,"children":419,"page":345},"Guides for users","i-lucide-book-open","\u002Fdocs\u002Fguides","docs\u002F3.guides",[420,424,428,432,436,440,444],{"title":421,"path":422,"stem":423,"stub":345,"launchGate":339},"Apps","\u002Fdocs\u002Fguides\u002Fapps","docs\u002F3.guides\u002F1.apps",{"title":425,"path":426,"stem":427,"stub":341,"launchGate":339},"Machines","\u002Fdocs\u002Fguides\u002Fmachines","docs\u002F3.guides\u002F2.machines",{"title":429,"path":430,"stem":431,"stub":341,"launchGate":339},"Volumes","\u002Fdocs\u002Fguides\u002Fvolumes","docs\u002F3.guides\u002F3.volumes",{"title":433,"path":434,"stem":435,"stub":345,"launchGate":339},"Stacks","\u002Fdocs\u002Fguides\u002Fstacks","docs\u002F3.guides\u002F4.stacks",{"title":437,"path":438,"stem":439,"stub":341,"launchGate":339},"Terminal and cloud shells","\u002Fdocs\u002Fguides\u002Fterminal","docs\u002F3.guides\u002F5.terminal",{"title":441,"path":442,"stem":443,"stub":345,"launchGate":339},"Registry","\u002Fdocs\u002Fguides\u002Fregistry","docs\u002F3.guides\u002F6.registry",{"title":445,"path":446,"stem":447,"stub":341,"launchGate":339},"Kubernetes","\u002Fdocs\u002Fguides\u002Fkubernetes","docs\u002F3.guides\u002F7.kubernetes",{"title":449,"stub":345,"launchGate":339,"icon":450,"path":451,"stem":452,"children":453,"page":345},"Guides for operators","i-lucide-server-cog","\u002Fdocs\u002Foperators","docs\u002F4.operators",[454,458,462,466,470,474,478,482,486,487,492,496,500,504,508,512],{"title":455,"path":456,"stem":457,"stub":345,"launchGate":339},"Updates and maintenance windows","\u002Fdocs\u002Foperators\u002Fupdates","docs\u002F4.operators\u002F1.updates",{"title":459,"path":460,"stem":461,"stub":345,"launchGate":339},"Migrate: moving VMs from VMware","\u002Fdocs\u002Foperators\u002Fmigrate","docs\u002F4.operators\u002F10.migrate",{"title":463,"path":464,"stem":465,"stub":345,"launchGate":339},"Hardware","\u002Fdocs\u002Foperators\u002Fhardware","docs\u002F4.operators\u002F11.hardware",{"title":467,"path":468,"stem":469,"stub":345,"launchGate":339},"Billing","\u002Fdocs\u002Foperators\u002Fbilling","docs\u002F4.operators\u002F12.billing",{"title":471,"path":472,"stem":473,"stub":345,"launchGate":339},"Policies","\u002Fdocs\u002Foperators\u002Fpolicies","docs\u002F4.operators\u002F13.policies",{"title":475,"path":476,"stem":477,"stub":345,"launchGate":339},"Running the realm","\u002Fdocs\u002Foperators\u002Frealm-ops","docs\u002F4.operators\u002F14.realm-ops",{"title":479,"path":480,"stem":481,"stub":345,"launchGate":339},"Public address and hostnames for apps","\u002Fdocs\u002Foperators\u002Fpublic-address","docs\u002F4.operators\u002F15.public-address",{"title":483,"path":484,"stem":485,"stub":345,"launchGate":339},"Library","\u002Fdocs\u002Foperators\u002Flibrary","docs\u002F4.operators\u002F16.library",{"title":5,"path":342,"stem":344,"stub":345,"launchGate":339},{"title":488,"path":489,"stem":490,"stub":341,"launchGate":491},"Availability and drain","\u002Fdocs\u002Foperators\u002Favailability","docs\u002F4.operators\u002F3.availability","A1, A2, A3",{"title":493,"path":494,"stem":495,"stub":341,"launchGate":339},"Federation","\u002Fdocs\u002Foperators\u002Ffederation","docs\u002F4.operators\u002F4.federation",{"title":497,"path":498,"stem":499,"stub":341,"launchGate":339},"Licensing","\u002Fdocs\u002Foperators\u002Flicensing","docs\u002F4.operators\u002F5.licensing",{"title":501,"path":502,"stem":503,"stub":341,"launchGate":339},"Branding: look and design","\u002Fdocs\u002Foperators\u002Fbranding","docs\u002F4.operators\u002F6.branding",{"title":505,"path":506,"stem":507,"stub":341,"launchGate":339},"Connectivity","\u002Fdocs\u002Foperators\u002Fconnectivity","docs\u002F4.operators\u002F7.connectivity",{"title":509,"path":510,"stem":511,"stub":341,"launchGate":339},"Logs","\u002Fdocs\u002Foperators\u002Flogs","docs\u002F4.operators\u002F8.logs",{"title":513,"path":514,"stem":515,"stub":345,"launchGate":339},"Directory sync: Entra ID and Okta","\u002Fdocs\u002Foperators\u002Fdirectory-sync","docs\u002F4.operators\u002F9.directory-sync",{"title":517,"stub":345,"launchGate":339,"icon":518,"path":519,"stem":520,"children":521,"page":345},"Reference","i-lucide-library","\u002Fdocs\u002Freference","docs\u002F5.reference",[522,526],{"title":523,"path":524,"stem":525,"stub":345,"launchGate":339},"The API reference in your realm","\u002Fdocs\u002Freference\u002Fin-your-realm","docs\u002F5.reference\u002F1.in-your-realm",{"title":527,"path":528,"stem":529,"stub":345,"launchGate":339},"The velrix command","\u002Fdocs\u002Freference\u002Fcli","docs\u002F5.reference\u002F2.cli",{"title":531,"stub":345,"launchGate":339,"icon":532,"path":533,"stem":534,"children":535,"page":345},"Security and compliance","i-lucide-shield-check","\u002Fdocs\u002Fsecurity","docs\u002F6.security",[536,540,544,548],{"title":537,"path":538,"stem":539,"stub":341,"launchGate":339},"Post-quantum","\u002Fdocs\u002Fsecurity\u002Fpost-quantum","docs\u002F6.security\u002F1.post-quantum",{"title":541,"path":542,"stem":543,"stub":341,"launchGate":339},"GDPR","\u002Fdocs\u002Fsecurity\u002Fgdpr","docs\u002F6.security\u002F2.gdpr",{"title":545,"path":546,"stem":547,"stub":341,"launchGate":339},"NIS2 support","\u002Fdocs\u002Fsecurity\u002Fnis2","docs\u002F6.security\u002F3.nis2",{"title":549,"path":550,"stem":551,"stub":341,"launchGate":339},"Data residency","\u002Fdocs\u002Fsecurity\u002Fdata-residency","docs\u002F6.security\u002F4.data-residency",{"title":553,"path":554,"stem":555,"children":556,"stub":345,"launchGate":339,"icon":558},"Release notes","\u002Fdocs\u002Frelease-notes","docs\u002F7.release-notes\u002Findex",[557],{"title":553,"path":554,"stem":555,"stub":345,"launchGate":339},"i-lucide-scroll-text",[560,562],{"title":483,"path":484,"stem":485,"description":561,"children":-1},"The blueprints and script templates people make things from, and how to copy them to another installation.",{"title":488,"path":489,"stem":490,"description":563,"children":-1},"When a server fails: availability policies per app and host pool, draining a server for maintenance, live migration."]