Backups, updates and rollback
How backups work, what an update actually does, and what happens if one fails.
Backups
Download backup (Settings → System) captures everything needed to restore the instance in one file: state, encrypted secrets, configuration and the instance ID.
Runlogs and artifacts are retained for 90 days by default. Adjust the retention window in Settings → System if you need longer.
Restoring a backup needs your master key, the same one that decrypts your stored secrets. Keep a copy of it somewhere outside the instance itself: without it, a backup file on its own can't be restored.
Updates
Settings → System → Check for updates shows what's new before you touch anything. Confirming an update:
It backs up first
Automatically, before anything else changes.
It downloads and verifies
The release is downloaded and its signature verified before it's applied.
It waits for a safe point
Any ticket currently running finishes its current stage first. Nothing is interrupted mid-stage.
If a migration fails partway through, the backup taken in step one is restored automatically. An update either lands cleanly or leaves you back where you started, never half-migrated.
On Docker, the actual command is docker compose pull && docker compose up -d. See
Docker install. On bare metal, the same Check for
updates flow applies the update in place. See
Bare metal & Raspberry Pi.