Settings
Every capability is a module. A module works only when this build has it, your licence includes it and it is switched on here. Changes are written to the configuration and audited.
Backup locations
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Local / NFS-mounted directory source.local Backups in a directory on the validation host, including NFS or SMB mounts made by the host. | On | No network connections | |
| S3-compatible object storage source.s3 AWS S3, Cloudflare R2, Wasabi, Backblaze B2, MinIO, VersityGW and other S3-compatible services. | On | Connects to: customer-configured S3 endpoint (HTTPS unless configured otherwise) | |
| SFTP source.sftp SFTP servers and NAS devices, with a pinned host key. | On | Connects to: customer-configured SFTP server | |
| SMB / CIFS share source.smb Windows shares and NAS devices over SMB 2/3. | On | Connects to: customer-configured SMB server |
Database engines
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| MySQL and MariaDB engine.mysql Restores mysqldump / mariadb-dump logical backups (.sql, .sql.gz, .sql.zst) and MariaDB physical backups (mariadb-backup xbstream or tar) in a version-matched container. | On | No network connections | |
| PostgreSQL engine.postgres Restores pg_dump plain, custom (-Fc) and directory (-Fd) backups in a version-matched container. | On | No network connections | |
| MongoDB engine.mongodb Restores mongodump archives (--archive, --gzip) and directory dumps in a version-matched container, replaying a --oplog dump's oplog. | On | No network connections | |
| Microsoft SQL Server engine.mssql Restores SQL Server full database backups (.bak) in Microsoft's SQL Server image, under the licence terms and edition the customer sets in mssql: (Express for databases up to 10 GB, or a licensed edition). | On | No network connections |
Checks
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Level 1: integrity check.integrity Backup exists and is fresh, size trend, format, checksum sidecar, entropy. | On | No network connections | |
| Backup copies and the 3-2-1 rule check.copies Checks each copy listed in targets[].copies is present and fresh, and warns when the 3-2-1 rule is not met (two backups on two devices, one off site). | Off Off until you switch it on. | Needs check.integrity Connects to: customer-configured backup locations holding the copies (listing only) | |
| Encrypted backups check.encrypted Validates backups encrypted by other tools or by backup mode: age, GnuPG, OpenSSL enc, ZIP and 7-Zip passwords, SQL Server certificates; decrypted in memory into the restore only (targets[].encryption). | On | Needs check.integrity No network connections | |
| Recovery key test check.key_test On demand: proves an age recovery (escrow) key, given at the time and never stored, decrypts a database's newest encrypted backup. | On | Needs check.integrity No network connections | |
| Level 2: restore check.restore Restores into a version-matched sandbox and records the duration (RTO trend). | On | Needs check.integrity No network connections | |
| Level 3: consistency check.consistency CHECK TABLE / amcheck, row counts, schema drift and emptied tables versus the previous run. | On | Needs check.restore No network connections | |
| Live row count comparison check.live_compare Row counts of the restored copy versus the production server, over a read-only connection (outbound to the configured host). | Off Off until you switch it on. | Needs check.consistency Connects to: customer-configured production database (read-only session, from a probe container on an egress network) | |
| Level 4: custom SQL checks check.custom_sql Customer SQL with typed expectations, run read-only on the restored copy. | On | Needs check.restore No network connections |
Addon
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Point-in-time restore test addon.pitr Replays the archived PostgreSQL WAL on top of the newest base backup, to its end, and records the last transaction it reached (targets[].pitr). | Off Off until you switch it on. | Needs check.restore Connects to: customer-configured backup location holding the WAL archive (read only) | |
| Sanitised staging copies addon.staging After a validation, masks personal data in the restored copy by rules and writes it as a dump for development and test (targets[].staging). | Off Off until you switch it on. | Needs check.restore Connects to: customer-configured backup location the staging copies are written to |
Reports
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Canonical JSON reports report.core RFC 8785 canonical JSON reports and per-target history. | On | No network connections | |
| Signed, hash-chained reports report.signing Ed25519 signature and hash chain on every report (needs a master key for the signing key). | On | Needs report.core No network connections | |
| PDF reports report.pdf PDF renderings of signed reports: per run and monthly per target or site. | On | Needs report.core No network connections | |
| NIS2 / ISO 27001 report templates report.templates.nis2 Backup controls evidence for a period, mapped to NIS2 (Implementing Regulation 2024/2690, point 4.2) and ISO/IEC 27001:2022 (A.8.13, A.5.30). | On | Needs report.pdf No network connections | |
| Co-branded reports report.branding A managed IT provider's name, contact and logo on monthly and evidence PDFs (branding: in the configuration). | On | Needs report.pdf No network connections |
Metrics
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Prometheus metrics metrics.prometheus /metrics on the agent listener: last outcome, last success, restore duration and backup age per target. | On | No network connections | |
| Provider dashboard metrics.dashboard Sends this site's status every 15 minutes to a managed IT provider's central dashboard: outcomes, times and sizes per database; no hostnames, paths, check details or data. | Off Off until you switch it on. | Connects to: provider dashboard: POST <dashboard.url>/v1/dashboard/push (HTTPS; default the licence server); none with agent.network: offline |
Notifications
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Email notifications notify.email Run outcomes and weekly summaries by SMTP (STARTTLS or implicit TLS). | On | No network connections | |
| Slack notifications notify.slack Run outcomes and weekly summaries to a Slack incoming webhook. | On | No network connections | |
| Microsoft Teams notifications notify.teams Adaptive Card messages to a Teams Workflows webhook. | On | No network connections | |
| Webhook notifications notify.webhook JSON (restorly.notification/v1) POSTed to a URL of your choice. | On | No network connections |
API
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| REST API api.rest Token-authenticated JSON API on the agent listener: status, targets, runs, reports, modules, config, secrets. | On | No network connections |
Backup mode
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Backup mode backup Takes logical dumps of production in a version-matched container and writes them to the target's location. | Off Off until you switch it on. | Needs check.integrity Connects to: customer-configured production database (backup user); customer-configured backup locations (write) |
Panel
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Local web panel panel Browser panel and Admin console on the agent listener: sign-in with two-factor codes, status, runs, reports, settings. | On | No network connections | Always on: this screen needs it. |
| Sign-in with your identity provider (OIDC) auth.oidc Keycloak, Entra ID, Google and other OpenID Connect providers: code flow with PKCE, groups mapped to roles, MFA required for admins. | Off Off until you switch it on. | Needs panel Connects to: customer-configured OpenID Connect provider (https) | |
| Import many databases at once targets.bulk_import Adds every database found in a backup location (by the {db} in a naming pattern) at once, copying an existing database's settings: in the panel (Databases → Import databases) and with restorly import databases. | On | No network connections |
Platform
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Clients (managed IT providers) multisite Databases belong to clients; a client switcher filters every screen, and reports are produced per client. | Off Off until you switch it on. | Needs panel No network connections | |
| Update check update.check Checks daily for a new signed release and, by agent.update_policy, offers it to admins or installs it with restorly update apply. Off with agent.network: offline or update_policy: pinned. | On | Connects to: update manifest: GET <agent.update_url>/stable/latest.json (HTTPS) | |
| Online licence license.online Renews the licence once a day from the licence server (online lease) and starts the 14-day trial from the setup wizard. Sends the licence ID, an install ID and the version; nothing about databases or backups. | Off Off until you switch it on. | Connects to: licence server: POST <agent.licence_url>/v1/lease and /v1/trial (HTTPS); none with agent.network: offline |
Core
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Capacity view capacity Whether the schedules fit in a day on the runners online, from real run times (ADR 0081) | On | No network connections | |
| Validate new backups at once schedule.watch Schedule on_new_backup: list the location every agent.watch_interval and validate a new backup once it is complete (ADR 0082) | On | No network connections |
Runners
| Module | State | Needs and connects to | Switch |
|---|---|---|---|
| Remote runners runners.remote Runners on other hosts, sites or VLANs join this hub and validate backups there; they dial out over mutual TLS. | Off Off until you switch it on. | Needs panel Connects to: inbound only: customer's own runners dial the hub (hub.listen, mutual TLS) |