maqpna backup verify
Verify a backup's checksums and, with its key, its sealed Secrets
Synopsis#
maqpna backup verify DIR [--open-key RECIPIENT.key]Description#
From the help of maqpna backup:
Secrets are sealed with X25519 (maqpna-sovereign x25519-keygen) and are skipped without --seal-to. HSM/KMS key URIs are referenced by the Secrets and never exported. verify exits 3 on any failure. See docs/runbooks/backup-restore.md.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--open-key | string | X25519 recipient private key: also open every sealed Secret | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna backup verify /backups/2026-10-02 --open-key recipient.keyWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |