Run safenix-agent verify-restore. It performs a real restore into a temporary folder created by the agent, without connecting to any database or writing outside that folder. When the verification ends, the agent always deletes the temporary folder, whether the restore succeeds or fails.
What the verification checks
The command decrypts the complete backup and reapplies the captured changes up to the present moment. It verifies that:
- The data can be decrypted with the encryption password you provide.
- The chain of captured changes has no interruptions.
- The restore completes through the present moment.
If the change chain has an interruption, the command stops and reports the point up to which a restore would be possible.
The verification does not connect to any database and does not apply anything in production. This also applies when you run it on the original server.
Run the verification
You need four values: the server identifier, the encryption password, the Control Plane address, and a restore credential issued by the dashboard. The restore credential starts with sk_restore_.
In the dashboard, open the server's Credential section. The first three lines are ready to copy, with the server identifier and restore credential filled in. The encryption password is not included: Safenix does not possess it and cannot provide it.
Set the four values as environment variables before running the command:
export SAFENIX_AGENT_ID=<identificativo del server> export SAFENIX_CONTROL_PLANE_URL=https://api.safenix.eu export SAFENIX_API_TOKEN=<la credenziale sk_restore_...> export SAFENIX_ENCRYPTION_PASSWORD='<la password di cifratura>'The encryption password can also be provided as
RESTIC_PASSWORD.Run the verification:
safenix-agent verify-restore
Why the upload token does not work
The token used by the agent to upload backups cannot be used for this command. That token can write data but cannot read it. The same restriction applies on the original server, so use the restore credential from the dashboard instead.
When to run it
Safenix automatically performs a separate verification every month. It checks that the objects required for a restore are present, complete, the correct size, and unaltered. It does not decrypt the data and cannot prove that the backups can be opened. The two checks are complementary.
Safenix does not track when you run verify-restore, and there is no automatic reminder. You decide when to perform this verification.