MAQPNADocs

maqpna backup create

Back up the ledger, MAQPNA resources, sealed Secrets and PostgreSQL state

Operate-o json | yaml

Synopsis#

maqpna backup create --out DIR [--gateway URL] [-n NS] [--include ledger,crs,secrets,postgres] [--seal-to RECIPIENT.pub] [--postgres-dsn-file F] [--postgres-schema maqpna]

Description#

From the help of maqpna backup:

Secrets are sealed with X25519 (maqpna-sovereign x25519-keygen) and are skipped without --seal-to. HSM/KMS key URIs are referenced by the Secrets and never exported. verify exits 3 on any failure. See docs/runbooks/backup-restore.md.

Flags#

FlagTypeDescriptionDefault
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--includestringcomponents: ledger, crs, secrets, postgresledger,crs,secrets,postgres
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--outstringoutput directory (must not exist or be empty; required)none
--postgres-dsn-filestringfile with the state PostgreSQL DSN (pg_dump of --postgres-schema)none
--postgres-schemastringstate schemamaqpna
--seal-tostringX25519 recipient public key (file or base64) sealing the Secretsnone
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna backup create --out /backups/2026-10-02 --seal-to recipient.pub

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna backup create.cast