Choose recovery objectives for database changes and uploaded files, and enable the database provider’s appropriate backup or point-in-time recovery service. Keep an independent Ralti export for migration and recovery exercises. Maintenance commands use RALTI_DATABASE_ADMIN_URL and may also load .env.local; verify the intended environment before running them.
mkdir -p -m 700 ../ralti-private-backups
npm run database -- backup --directory ../ralti-private-backups/release-1 --uploads .atlas/uploads
npm run database -- verify-backup --directory ../ralti-private-backups/release-1The export captures the Ralti public schema in a consistent PostgreSQL snapshot, creates a custom-format dump, and records row counts and content hashes. Optional uploaded files receive checksums. Pause attachment writes for an upload-inclusive snapshot because filesystem copying is outside the database transaction. Keep backup directories outside public roots and source control.
What verification proves#
The verifier creates a disposable random database, installs pgvector in the original schema, restores the dump, checks table fingerprints and upload checksums, and drops the temporary database. It never restores over the application database. It requires permission to create databases; an isolated compatible PostgreSQL server can host verification when your managed service does not allow it. Use a pg_dump client at least as new as the source database major version.
- Preserve ATLAS_EMAIL_ENCRYPTION_KEY in a separate recoverable secret store.
- Back up uploaded bytes and other private document files alongside database recovery planning.
- After a real restore, reapply the runtime permission boundary and provision appropriate runtime credentials. Portable dumps exclude role credentials.
- Keep a previous compatible application image and its configuration with each release.
The current v2 backup manifest uses portable ordering and hashes nongenerated columns. Older v1 manifests retain their original verification requirements. Do not rename or rewrite a manifest version to bypass a mismatch.