maqpna backup create
Back up the ledger, MAQPNA resources, sealed Secrets and PostgreSQL state
Synopsis#
maqpna backup create --out DIR [--gateway URL] [-n NS] [--include ledger,crs,secrets,postgres] [--seal-to RECIPIENT.pub] [--postgres-dsn-file F] [--postgres-schema maqpna]Description#
From the help of maqpna backup:
Secrets are sealed with X25519 (maqpna-sovereign x25519-keygen) and are skipped without --seal-to. HSM/KMS key URIs are referenced by the Secrets and never exported. verify exits 3 on any failure. See docs/runbooks/backup-restore.md.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--include | string | components: ledger, crs, secrets, postgres | ledger,crs,secrets,postgres |
--oidc-token-file | string | file holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --token | none |
--out | string | output directory (must not exist or be empty; required) | none |
--postgres-dsn-file | string | file with the state PostgreSQL DSN (pg_dump of --postgres-schema) | none |
--postgres-schema | string | state schema | maqpna |
--seal-to | string | X25519 recipient public key (file or base64) sealing the Secrets | none |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna backup create --out /backups/2026-10-02 --seal-to recipient.pubWhat happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). - Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |