Safenix cannot exclude a file or folder from a protected path. There is no exclusion option, exclusions file, or wildcard support. The path list accepts only complete file or folder paths, separated by commas.
Protect selected subfolders instead
To leave out part of a directory, do not add its parent directory and try to exclude the unwanted content. Add each subfolder that you want to protect as a separate path.
For example, to protect /var/www without including /var/www/cache, you cannot add /var/www and exclude /var/www/cache. Instead, list the other subfolders of /var/www one by one. Separate the complete paths with commas.
This approach protects only the paths you explicitly list. It does not provide an exclusion rule inside a protected folder.
The agent state directory is always excluded
Safenix always excludes the directory where the agent stores its own state. This exclusion is decided by Safenix and cannot be changed. By default, this directory is /var/lib/safenix.
This prevents the agent from copying itself. If its state directory were included in the backup path list, each backup cycle would copy the previous backup into the next one, causing the size to double each time.
About the default path list
The path list proposed during registration already excludes /var/lib. This directory normally contains data that a reinstallation recreates, such as system packages and container state.
If the server contains data that you need to protect under /var/lib, add the precise subfolders containing that data. Do not add the parent directory expecting to exclude selected contents later; exclusions are not supported.