Safenix can restore a MySQL or MariaDB database either to a selected point in time or to the time of a full copy, depending on the protection mode configured for the server.
Check the recovery mode and permissions
Run this command on the server:
safenix-agent check-mysqlThe command asks for the database password interactively. It reports:
- Which database protection mode the server uses.
- Whether restoration is possible with the current user.
- Which permissions are missing, if any, and the exact SQL instructions needed to grant them.
Continuous capture requires binary logging to be active on the database server. With continuous capture, you can restore to any selected instant, up to a transaction boundary. The restore includes all transactions completed up to that moment and none of the transactions after it.
With periodic copies, you can restore only to the time of a full copy. The interval between full copies depends on the plan.
Prepare a restore without applying it
Use this command to assemble the full copy and captured changes in a directory without changing any database:
safenix-agent restore-mysql --output-dir DIR --at 2026-08-12T19:00:00ZReplace DIR with the directory where the assembled restore should be placed. The database is not touched by this operation.
Apply the restore
The restore overwrites existing data. It deletes and recreates the tables covered by the restore. Everything written to that server after the selected moment is lost. Do not continue unless this data loss is intended.
To apply the restore, run:
safenix-agent restore-mysql --output-dir DIR --at 2026-08-12T19:00:00Z --executeBefore writing anything, the agent creates a temporary schema to verify that the permissions are sufficient, then deletes it immediately. This causes the restore to fail before it starts rather than partway through if the permissions are inadequate.
The agent then asks for confirmation by requiring you to type the exact address of the server. If the response does not match, nothing is applied.
Use a separate restore account
The permissions required to apply a restore are broader than those required for backups. Grant them to a separate database user. That credential can destroy the databases it can write to, so create it when a restore is needed and remove it immediately afterwards.
Backup operations do not use this credential and do not need its permissions. If permissions are missing, use the exact SQL instructions printed by safenix-agent check-mysql.
What is not restored
MySQL and MariaDB accounts and permissions are never restored. The backup covers database data, not the server's user accounts.