Backup and restore
Versioned local archive backups include a manifest, SHA-256 checksums, and offline restore.
Create a backup
Section titled “Create a backup”While the server is running:
./bin/chronacta backup create -archive ./backups/node-$(date +%Y%m%d-%H%M%S).tar.gzThe server seals the active segment, syncs WAL/segments, and writes a .tar.gz archive containing:
manifest.json- sealed
segments/*.logandsegments/*.index - non-empty
wal/*.log schemas/schemas.jsonwhen presentsubscriptions/subscriptions.jsonwhen presentprojections/<name>/...definition and state files when present
Use -dry-run to validate the snapshot plan without writing the archive.
Inspect a backup
Section titled “Inspect a backup”./bin/chronacta backup inspect -archive ./backups/node.tar.gzRestore offline
Section titled “Restore offline”Stop the server. Restore only into an empty target directory:
./bin/chronacta-admin restore \ --archive ./backups/node.tar.gz \ --target ./restored-data \ --confirmRestore validates manifest checksums, extracts into a staging directory, runs read-only verification, then publishes the target atomically. Use --dry-run to validate without writing files.
Verify restored data
Section titled “Verify restored data”Offline restore already runs storage verification before publishing the target. To re-check through the live API, start a server on the restored directory:
CHRONACTA_DATA_DIR=./restored-data ./bin/chronacta-server./bin/chronacta verify./bin/chronacta stream-info -stream <stream-id>Compare stream contents with the source node if needed.
Upload to S3 (cloud backup)
Section titled “Upload to S3 (cloud backup)”Configure the server with S3 settings (see cloud backup architecture):
export CHRONACTA_BACKUP_S3_BUCKET=my-dr-bucketexport CHRONACTA_BACKUP_S3_PREFIX=chronacta/prodexport CHRONACTA_BACKUP_S3_REGION=eu-central-1Create a local backup, then upload:
./bin/chronacta backup create -archive ./backups/node-$(date +%Y%m%d-%H%M%S).tar.gz./bin/chronacta backup upload -archive ./backups/node-20260101-120000.tar.gz./bin/chronacta backup list-remoteUse -dry-run on upload to validate the archive without transferring bytes. For MinIO or other S3-compatible stores, set CHRONACTA_BACKUP_S3_ENDPOINT.
Disaster recovery from cloud: download the object locally, then run offline restore as above.
HA cluster DR drill
Section titled “HA cluster DR drill”- Backup from leader —
chronacta backup createon the current write leader (only leader accepts destructive admin ops in cluster mode). - Simulate leader loss — stop leader process; confirm majority elects new leader (
cluster status). - Restore drill (staging) — restore backup into a fresh directory on a follower or staging host:
./bin/chronacta-admin restore --archive ./backups/leader.tar.gz --target ./drill-data --confirm./bin/chronacta verify-db -data-dir ./drill-data- RPO check — compare
manifest.jsonhigh_water_global_positionwith last acknowledged client write. - RTO check — time from leader stop to successful append on new leader (target < 30s lab default).
Do not point production followers at restored data without following membership change procedures in HA rolling upgrade.

