MAQPNADocs

maqpna backup

Back up the audit ledger, MAQPNA resources, sealed signing keys and PostgreSQL state

Operate-o json | yaml

Synopsis#

maqpna backup create --out DIR [--gateway URL] [-n NS] [--include ledger,crs,secrets,postgres] [--seal-to RECIPIENT.pub] [--postgres-dsn-file F] [--postgres-schema maqpna]
maqpna backup verify DIR [--open-key RECIPIENT.key]

Description#

Secrets are sealed with X25519 (maqpna-sovereign x25519-keygen) and are skipped without --seal-to. HSM/KMS key URIs are referenced by the Secrets and never exported. verify exits 3 on any failure. See docs/runbooks/backup-restore.md.

Subcommands#

Examples#

maqpna backup create --out /backups/2026-10-02 --seal-to recipient.pub
maqpna backup verify /backups/2026-10-02 --open-key recipient.key

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna backup.cast