maqpna dr drill
Restore a backup into scratch space and report recovery time and data-loss window
Synopsis#
maqpna dr drill [--from DIR | --gateway URL] [--scratch-namespace maqpna-drill] [--open-key K] [--seal-to P] [--postgres-scratch-dsn-file F] [--keep]Description#
From the help of maqpna dr:
Without --from a fresh backup is taken first (ledger and objects; Secrets with --seal-to). The drill restores the ledger to a scratch file and requires the same head hash, validates every object with a server-side dry run in scratch namespaces (<scratch>-<namespace>), opens the sealed Secrets (--open-key) and restores PostgreSQL into a scratch database (--postgres-scratch-dsn-file) and verifies its audit_chain. Nothing in the live installation changes; scratch namespaces are deleted unless --keep. Exit 3 when a check fails.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--from | string | backup DIR to drill (default: take a fresh backup through --gateway) | none |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--keep | switch | keep the scratch namespaces | none |
--oidc-token-file | string | file holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --token | none |
--open-key | string | X25519 recipient private key: open every sealed Secret | none |
--postgres-scratch-dsn-file | string | scratch PostgreSQL database to pg_restore into and verify | none |
--scratch-namespace | string | prefix of the scratch namespaces | maqpna-drill |
--seal-to | string | with a fresh backup: also seal and drill the Secrets | none |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna dr drill --from /backups/2026-10-02 --open-key recipient.key
maqpna dr drill --gateway "$GW" --keepWhat happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). - Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.