Administration

Backups, updates and rollback

How backups work, what an update actually does, and what happens if one fails.

Backups

Download backup (Settings → System) captures everything needed to restore the instance in one file: state, encrypted secrets, configuration and the instance ID.

Runlogs and artifacts are retained for 90 days by default. Adjust the retention window in Settings → System if you need longer.

Restoring a backup needs your master key, the same one that decrypts your stored secrets. Keep a copy of it somewhere outside the instance itself: without it, a backup file on its own can't be restored.

Updates

Settings → System → Check for updates shows what's new before you touch anything. Confirming an update:

It backs up first

Automatically, before anything else changes.

It downloads and verifies

The release is downloaded and its signature verified before it's applied.

It waits for a safe point

Any ticket currently running finishes its current stage first. Nothing is interrupted mid-stage.

If a migration fails partway through, the backup taken in step one is restored automatically. An update either lands cleanly or leaves you back where you started, never half-migrated.

On Docker, the actual command is docker compose pull && docker compose up -d. See Docker install. On bare metal, the same Check for updates flow applies the update in place. See Bare metal & Raspberry Pi.