Files
nx9-wg/docs/BACKUP_RESTORE.md
T

51 lines
1.4 KiB
Markdown

# Backup and Disaster Recovery Guide
## Architecture
`nx9-wg` uses SQLite `VACUUM INTO` for atomic, consistent online snapshots of the database while the service is live.
---
## 1. Creating a Backup
### Via CLI
```bash
nx9-wg backup create --description "Routine weekly backup"
```
### Via REST API
```bash
curl -X POST http://127.0.0.1:8080/api/v1/backups/create \
-H "Authorization: Bearer nx9_<TOKEN>" \
-H "Content-Type: application/json" \
-d '{"description": "Pre-maintenance backup"}'
```
---
## 2. Verifying a Backup
The verification process:
1. Validates minimum file size.
2. Checks the SQLite 3 magic header bytes (`b"SQLite format 3\0"`).
3. Validates the SHA-256 cryptographic checksum against the manifest.
```bash
nx9-wg backup verify /var/lib/nx9-wg/backups/nx9-backup-20260816-120000.db
```
---
## 3. Restoring from a Backup
The restore workflow is designed with fail-safety:
1. Verifies the backup archive before performing any modifications.
2. Creates an automatic pre-restore safety snapshot (`pre-restore-safety-TIMESTAMP.bak`).
3. Closes open connection pools and replaces the database file.
4. Cleans stale WAL and SHM journal files.
5. Reopens the database and runs the Reconciliation Engine to bring kernel WireGuard and firewall state in sync with the restored database.
```bash
nx9-wg backup restore /var/lib/nx9-wg/backups/nx9-backup-20260816-120000.db
```