Sign in Start free trial
← Help centre

Test a Safenix Restore Without Touching Production

Run a complete restore verification in a temporary folder without connecting to databases or changing production data.

Run safenix-agent verify-restore. It performs a real restore into a temporary folder created by the agent, without connecting to any database or writing outside that folder. When the verification ends, the agent always deletes the temporary folder, whether the restore succeeds or fails.

What the verification checks

The command decrypts the complete backup and reapplies the captured changes up to the present moment. It verifies that:

  • The data can be decrypted with the encryption password you provide.
  • The chain of captured changes has no interruptions.
  • The restore completes through the present moment.

If the change chain has an interruption, the command stops and reports the point up to which a restore would be possible.

The verification does not connect to any database and does not apply anything in production. This also applies when you run it on the original server.

Run the verification

You need four values: the server identifier, the encryption password, the Control Plane address, and a restore credential issued by the dashboard. The restore credential starts with sk_restore_.

  1. In the dashboard, open the server's Credential section. The first three lines are ready to copy, with the server identifier and restore credential filled in. The encryption password is not included: Safenix does not possess it and cannot provide it.

  2. Set the four values as environment variables before running the command:

    export SAFENIX_AGENT_ID=<identificativo del server>
    export SAFENIX_CONTROL_PLANE_URL=https://api.safenix.eu
    export SAFENIX_API_TOKEN=<la credenziale sk_restore_...>
    export SAFENIX_ENCRYPTION_PASSWORD='<la password di cifratura>'

    The encryption password can also be provided as RESTIC_PASSWORD.

  3. Run the verification:

    safenix-agent verify-restore

Why the upload token does not work

The token used by the agent to upload backups cannot be used for this command. That token can write data but cannot read it. The same restriction applies on the original server, so use the restore credential from the dashboard instead.

When to run it

Safenix automatically performs a separate verification every month. It checks that the objects required for a restore are present, complete, the correct size, and unaltered. It does not decrypt the data and cannot prove that the backups can be opened. The two checks are complementary.

Safenix does not track when you run verify-restore, and there is no automatic reminder. You decide when to perform this verification.

Still stuck?

If this page did not solve it, write to us and a person answers.

Contact