maqpna restore
Restore a backup (signing keys, MAQPNA resources, PostgreSQL state, audit ledger)
Synopsis#
maqpna restore DIR [--components secrets,crs,postgres,ledger] [--open-key RECIPIENT.key] [--namespace-map FROM=TO]...
[--ledger-out FILE] [--postgres-dsn-file F] [--include-runtime] [--dry-run] [--force] [--yes]Description#
Order: Secrets (opened with --open-key), cluster-scoped then namespaced objects, PostgreSQL (pg_restore), the ledger file. The CRDs must be installed (helm install or maqpna install) first. AgentSessions, snapshots and connected-account mirrors are runtime state and are skipped unless --include-runtime. A ledger or audit_chain whose live head is ahead of the backup is never overwritten without --force. Afterwards run maqpna doctor. --dry-run uses server-side dry run.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--components | string | what to restore | secrets,crs,postgres,ledger |
--dry-run | switch | server-side dry run: validate, change nothing | none |
--force | switch | restore although checks fail or the live ledger is ahead of the backup | none |
--include-runtime | switch | also restore AgentSessions, snapshots and connected-account mirrors | none |
--ledger-out | string | write the restored ledger here (copy it onto the gateway's audit volume) | none |
--namespace-map | string | restore namespace FROM into TO (repeatable) | none |
--open-key | string | X25519 recipient private key opening the sealed Secrets | none |
--postgres-dsn-file | string | PostgreSQL DSN file to pg_restore the state schema into | none |
-y, --yes | switch | do not ask for confirmation (required when stdin is not a terminal) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna restore /backups/2026-10-02 --open-key recipient.key --dry-run
maqpna restore /backups/2026-10-02 --open-key recipient.key --components secrets,crsWhat happens when you run it#
--dry-run: server-side dry run: validate, change nothing.--yes: do not ask for confirmation (required when stdin is not a terminal).--force: restore although checks fail or the live ledger is ahead of the backup.- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.