MAQPNADocs

maqpna restore

Restore a backup (signing keys, MAQPNA resources, PostgreSQL state, audit ledger)

Operate-o json | yaml

Synopsis#

maqpna restore DIR [--components secrets,crs,postgres,ledger] [--open-key RECIPIENT.key] [--namespace-map FROM=TO]...
               [--ledger-out FILE] [--postgres-dsn-file F] [--include-runtime] [--dry-run] [--force] [--yes]

Description#

Order: Secrets (opened with --open-key), cluster-scoped then namespaced objects, PostgreSQL (pg_restore), the ledger file. The CRDs must be installed (helm install or maqpna install) first. AgentSessions, snapshots and connected-account mirrors are runtime state and are skipped unless --include-runtime. A ledger or audit_chain whose live head is ahead of the backup is never overwritten without --force. Afterwards run maqpna doctor. --dry-run uses server-side dry run.

Flags#

FlagTypeDescriptionDefault
--componentsstringwhat to restoresecrets,crs,postgres,ledger
--dry-runswitchserver-side dry run: validate, change nothingnone
--forceswitchrestore although checks fail or the live ledger is ahead of the backupnone
--include-runtimeswitchalso restore AgentSessions, snapshots and connected-account mirrorsnone
--ledger-outstringwrite the restored ledger here (copy it onto the gateway's audit volume)none
--namespace-mapstringrestore namespace FROM into TO (repeatable)none
--open-keystringX25519 recipient private key opening the sealed Secretsnone
--postgres-dsn-filestringPostgreSQL DSN file to pg_restore the state schema intonone
-y, --yesswitchdo not ask for confirmation (required when stdin is not a terminal)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna restore /backups/2026-10-02 --open-key recipient.key --dry-run
maqpna restore /backups/2026-10-02 --open-key recipient.key --components secrets,crs

What happens when you run it#

  • --dry-run: server-side dry run: validate, change nothing.
  • --yes: do not ask for confirmation (required when stdin is not a terminal).
  • --force: restore although checks fail or the live ledger is ahead of the backup.
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna restore --help.cast

This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.