Skip to main content

Backing up HivePaaS

Apart from your apps' data, HivePaaS keeps its own: its database, with your projects, apps, settings and users. The system backup backs it up.

Turn it on​

The system backup is off until you set it up. In Settings → Data Backup:

SettingWhat to give
Back UpHivePaaS's database, the spec of the whole installation, or both.
Backup RepositoryA backup repository of the installation, not of a project.
Secrets in the SpecOmit, Plaintext, or Encrypted with a Spec Passphrase.
SchedulingWhen it runs: daily is the default.

Then turn it on. Run Backup Now takes one at once.

Each run takes one snapshot, with:

  • db.pg_dump: HivePaaS's database, a dump in pg_dump's custom format;
  • spec.tar.gz, or spec.tar.gz.age when encrypted: the configuration spec of the whole installation.

Settings → Data Backup lists the snapshots.

Secrets in the spec​

  • Omit: the spec holds no secret; importing it asks for every one again.
  • Plaintext: the spec holds every secret as it is: whoever has the repository's password reads them.
  • Encrypted: the spec is encrypted with a passphrase of its own, besides the repository's password. A lost passphrase is a spec whose secrets cannot be read.

Keep the app secret too​

The database holds your secrets encrypted with the app secret, which is not in the backup: it is in hivepaas.toml, in HivePaaS's data directory. Keep a copy of that file apart from the server: without it, the secrets in a database backup cannot be read.

Moving to a new server​

  1. Install HivePaaS on the new server.
  2. Download the latest spec.tar.gz from a snapshot of the system backup.
  3. Import it in Operations → Export.
  4. Restore your apps' data from their own backups: see Restoring.