Every backup is one snapshot for each of the site's databases, with its dump, then one snapshot of its files. A site without a database saves its files alone. Right after it is taken, the backup goes through a restore test: until the test ends it is pending, and it counts only once it has passed.
Scheduled backups
A production site starts with backups on: one a day, kept for 30 days. Every 5 minutes the panel checks which sites are due and starts their backup. There is nothing else to do.
- They run only for active sites, and only with a repository and password set.
- Staging copies have no scheduled backups.
- A reverse proxy site is never backed up: it has no content of its own (its application has) and no database. It starts with backups off, and Back up now is refused.
- A scheduled backup that fails is tried again at the site's next slot (in an hour, a day or a week), not at the next check.
To change the schedule, in the site's Backups tab, Schedule card:
- In Frequency pick Off, Every hour, Every day or Every week.
- In Keep choose how long to keep the snapshots: Keep 7 days, 14, 30, 60, 90, 180 or 365 days, or Keep every snapshot. Only an administrator changes this field. A value set another way (with cgctl or the API, 0 to 3650 days) stays among the choices.
- Press Save.
With the API it is PUT /api/sites/<site-id>/backups/policy with enabled, schedule (hourly,
daily, weekly) and retention_days.
Take a backup now
- Open the site and choose the Backups tab.
- Press Back up now. The task Backup started begins.
- The new snapshot appears at the top of the list. The Restore test column goes from pending to passed (or failed) when the test ends.
At the top of the tab are Last backup, Last restore test and Estimated restore time, which is how long the last backup's test took.
cgctl --wait backup run <site-id>
What a backup holds
- Each of the site's databases, if the panel manages it on this server. The dump streams straight into restic and is never written to disk.
- The whole site folder,
/srv/sites/<domain>: releases,shared/(configuration and uploaded files), SFTP keys and the site'slogs/folder. - Only
tmp/, where PHP keeps temporary files and sessions, is left out.
If even one file cannot be read, the backup fails and is not recorded: an incomplete backup does not count.
How long backups stay
Once a day the panel removes the site's snapshots older than the days in Keep from the repository (30 at first; with Keep every snapshot it removes nothing). It never removes the newest backup that passed its restore test, nor one whose test has not run yet. The rule touches only that site's snapshots from this server.
Delete a backup
You need an administrator account.
- In the Backups tab, press the bin on the snapshot's row.
- Confirm. The snapshot is removed from the repository together with its database backup.
The bin is disabled for the newest backup that passed its test, and for one whose test has not run yet. The space in the repository is freed by the daily clean-up.