MAQPNADocs

maqpna dr drill

Restore a backup into scratch space and report recovery time and data-loss window

Operate-o json | yaml

Synopsis#

maqpna dr drill [--from DIR | --gateway URL] [--scratch-namespace maqpna-drill] [--open-key K] [--seal-to P] [--postgres-scratch-dsn-file F] [--keep]

Description#

From the help of maqpna dr:

Without --from a fresh backup is taken first (ledger and objects; Secrets with --seal-to). The drill restores the ledger to a scratch file and requires the same head hash, validates every object with a server-side dry run in scratch namespaces (<scratch>-<namespace>), opens the sealed Secrets (--open-key) and restores PostgreSQL into a scratch database (--postgres-scratch-dsn-file) and verifies its audit_chain. Nothing in the live installation changes; scratch namespaces are deleted unless --keep. Exit 3 when a check fails.

Flags#

FlagTypeDescriptionDefault
--fromstringbackup DIR to drill (default: take a fresh backup through --gateway)none
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--keepswitchkeep the scratch namespacesnone
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--open-keystringX25519 recipient private key: open every sealed Secretnone
--postgres-scratch-dsn-filestringscratch PostgreSQL database to pg_restore into and verifynone
--scratch-namespacestringprefix of the scratch namespacesmaqpna-drill
--seal-tostringwith a fresh backup: also seal and drill the Secretsnone
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna dr drill --from /backups/2026-10-02 --open-key recipient.key
maqpna dr drill --gateway "$GW" --keep

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna dr drill --help.cast

This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.