1.4 KiB
1.4 KiB
Backup and Disaster Recovery Guide
Architecture
nx9-wg uses SQLite VACUUM INTO for atomic, consistent online snapshots of the database while the service is live.
1. Creating a Backup
Via CLI
nx9-wg backup create --description "Routine weekly backup"
Via REST API
curl -X POST http://127.0.0.1:8080/api/v1/backups/create \
-H "Authorization: Bearer nx9_<TOKEN>" \
-H "Content-Type: application/json" \
-d '{"description": "Pre-maintenance backup"}'
2. Verifying a Backup
The verification process:
- Validates minimum file size.
- Checks the SQLite 3 magic header bytes (
b"SQLite format 3\0"). - Validates the SHA-256 cryptographic checksum against the manifest.
nx9-wg backup verify /var/lib/nx9-wg/backups/nx9-backup-20260816-120000.db
3. Restoring from a Backup
The restore workflow is designed with fail-safety:
- Verifies the backup archive before performing any modifications.
- Creates an automatic pre-restore safety snapshot (
pre-restore-safety-TIMESTAMP.bak). - Closes open connection pools and replaces the database file.
- Cleans stale WAL and SHM journal files.
- Reopens the database and runs the Reconciliation Engine to bring kernel WireGuard and firewall state in sync with the restored database.
nx9-wg backup restore /var/lib/nx9-wg/backups/nx9-backup-20260816-120000.db