maqpna backup
Back up the audit ledger, MAQPNA resources, sealed signing keys and PostgreSQL state
Synopsis#
maqpna backup create --out DIR [--gateway URL] [-n NS] [--include ledger,crs,secrets,postgres] [--seal-to RECIPIENT.pub] [--postgres-dsn-file F] [--postgres-schema maqpna]
maqpna backup verify DIR [--open-key RECIPIENT.key]Description#
Secrets are sealed with X25519 (maqpna-sovereign x25519-keygen) and are skipped without --seal-to. HSM/KMS key URIs are referenced by the Secrets and never exported. verify exits 3 on any failure. See docs/runbooks/backup-restore.md.
Subcommands#
maqpna backup createBack up the ledger, MAQPNA resources, sealed Secrets and PostgreSQL state
maqpna backup verifyVerify a backup's checksums and, with its key, its sealed Secrets
Examples#
maqpna backup create --out /backups/2026-10-02 --seal-to recipient.pub
maqpna backup verify /backups/2026-10-02 --open-key recipient.keyWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |