Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Basic application and database general encryption backup

Backup to local

enforce_provisioning_action

1.bak.toml

bak_location_type = "local"

[object_storage]
enabled = false

[backup_encryption]
# Turn on encryption
enabled = true

cryptographic algorithm
algorithm = "aes-256-gcm"

# Key encapsulation method
key_wrap_algorithm = "x25519"

# Path to the public key file.The public key of the recipient (viewer of the backup) is stored here
public_key_file = "C:\\test_key\\ppk.pub"

# Delete clear text after encryption
delete_plain_after_encrypt = true
  1. Generate key see –––––––––––––– Link pending

Perform the preliminary checks: §.

Perform application data or database backup pre-checks

# Performing an App Data Backup
peppykeep backup run --bak-type app-data --config-home %USERPROFILE%\.peppykeep\conf
or @
# Performing a Database Backup
peppykeep backup run --bak-type db --config-home %USERPROFILE%\.peppykeep\conf

When the pre-test is successful, the output is as follows:

=== Dry Run ===
Action     : backup run
Project    : test_717_file
BakType    : AppData
DataDir    : C:\tmp\prj_a
Location   : Local
Encryption : true
Force      : false
Next       : Re-run with --apply to execute.

or @

=== Dry Run ===
Action     : backup run
Project    : test_717_file
BakType    : Db
DataDir    : C:\tmp\prj_a
Location   : Local
Encryption : true
Force      : false
Next       : Re-run with --apply to execute.

⚠️ Note: The suffix name of the encrypted file is .ppke

Perform a backup

Perform application data or database backups

# Performing an App Data Backup
peppykeep backup run --bak-type app-data --apply --config-home %USERPROFILE%\.peppykeep\conf
or @
# Performing a Database Backup
peppykeep backup run --bak-type db --apply --config-home %USERPROFILE%\.peppykeep\conf

When the pre-test is successful, the output is as follows:

[1/3] Prepare local workspace
[2/3] Copy application data
[3/3] Create and encrypt backup artifact
Encryption progress: started (160 B)
Encryption progress: 100% (160 B/160 B)
Encryption progress: 100% (160 B/160 B)
=== Completed ===
Action       : backup run
Project      : test_717_file
BakType      : AppData
DataDir      : C:\tmp\prj_a
Location     : Local
Force        : false
Artifact     : C:\Users\admin\AppData\Local\Temp\backup\peppykeep\test_717_file\test_717_file-bak_20260716_184601.ppke
ArtifactSize : 324 B
Status       : Command completed successfully.

or @

[1/3] Prepare local workspace
[2/3] Export database
mysqldump output:

[3/3] Create and encrypt backup artifact
Encryption progress: started (1.2 KiB)
Encryption progress: 100% (1.2 KiB/1.2 KiB)
Encryption progress: 100% (1.2 KiB/1.2 KiB)
=== Completed ===
Action       : backup run
Project      : test_717_file
BakType      : Db
DataDir      : C:\tmp\prj_a
Location     : Local
Force        : false
Artifact     : C:\Users\admin\AppData\Local\Temp\backup\peppykeep\test_717_file\test_717_file-bak_20260716_190508.ppke
ArtifactSize : 1.3 KiB
Status       : Command completed successfully.

⚠️ Note: The suffix name of the encrypted file is .ppke

Backup to remote

enforce_provisioning_action

1.bak.toml

bak_location_type = "local_and_remote"

[object_storage]
enabled = true

[backup_encryption]
# Turn on encryption
enabled = true

cryptographic algorithm
algorithm = "aes-256-gcm"

# Key encapsulation method
key_wrap_algorithm = "x25519"

# Path to the public key file.The public key of the recipient (viewer of the backup) is stored here
public_key_file = "C:\\test_key\\ppk.pub"

# Delete clear text after encryption
delete_plain_after_encrypt = true
  1. Generate key see –––––––––––––– Link pending

Perform the preliminary checks: §.

Perform application data or database backup pre-checks

# Performing an App Data Backup
peppykeep backup run --bak-type app-data --config-home %USERPROFILE%\.peppykeep\conf
or @
# Performing a Database Backup
peppykeep backup run --bak-type db --config-home %USERPROFILE%\.peppykeep\conf

When the pre-test is successful, the output is as follows:

=== Dry Run ===
Action     : backup run
Project    : test_717_file
BakType    : AppData
DataDir    : C:\tmp\prj_a
Location   : LocalAndRemote
Encryption : true
Force      : false
Next       : Re-run with --apply to execute.

or @

=== Dry Run ===
Action     : backup run
Project    : test_717_file
BakType    : Db
DataDir    : C:\tmp\prj_a
Location   : LocalAndRemote
Encryption : true
Force      : false
Next       : Re-run with --apply to execute.

⚠️ Note: The suffix name of the encrypted file is .ppke

Execute Encryption

Perform application data or database backups

# Performing an App Data Backup
peppykeep backup run --bak-type app-data --apply --config-home %USERPROFILE%\.peppykeep\conf
or @
# Performing a Database Backup
peppykeep backup run --bak-type db --apply --config-home %USERPROFILE%\.peppykeep\conf

When the pre-test is successful, the output is as follows:

[1/5] Prepare local workspace
[2/5] Copy application data
[3/5] Create and encrypt backup artifact
Encryption progress: started (161 B)
Encryption progress: 100% (161 B/161 B)
Encryption progress: 100% (161 B/161 B)
[4/5] Upload artifact to object storage
=== Upload Target ===
Provider  : s3
Bucket    : contentwork-dev
RemoteKey : test_717_file/test_717_file-bak_20260716_191434.ppke
Target    : s3://contentwork-dev/test_717_file/test_717_file-bak_20260716_191434.ppke
Upload progress: started single-part upload (325 B)
Upload progress: 100% (325 B/325 B)
=== Upload Completed ===
Provider  : s3
Bucket    : contentwork-dev
RemoteKey : test_717_file/test_717_file-bak_20260716_191434.ppke
Target    : s3://contentwork-dev/test_717_file/test_717_file-bak_20260716_191434.ppke
[5/5] Apply local retention policy
=== Completed ===
Action       : backup run
Project      : test_717_file
BakType      : AppData
DataDir      : C:\tmp\prj_a
Location     : LocalAndRemote
Force        : false
Artifact     : C:\Users\admin\AppData\Local\Temp\backup\peppykeep\test_717_file\test_717_file-bak_20260716_191434.ppke
ArtifactSize : 325 B
Bucket       : contentwork-dev
RemoteKey    : test_717_file/test_717_file-bak_20260716_191434.ppke
Provider     : s3
Target       : s3://contentwork-dev/test_717_file/test_717_file-bak_20260716_191434.ppke
LocalCleanup : applied
Status       : Command completed successfully.

or @

[1/5] Prepare local workspace
[2/5] Export database
mysqldump output:

[3/5] Create and encrypt backup artifact
Encryption progress: started (1.2 KiB)
Encryption progress: 100% (1.2 KiB/1.2 KiB)
Encryption progress: 100% (1.2 KiB/1.2 KiB)
[4/5] Upload artifact to object storage
=== Upload Target ===
Provider  : s3
Bucket    : contentwork-dev
RemoteKey : test_717_file/test_717_file-bak_20260716_191440.ppke
Target    : s3://contentwork-dev/test_717_file/test_717_file-bak_20260716_191440.ppke
Upload progress: started single-part upload (1.3 KiB)
Upload progress: 100% (1.3 KiB/1.3 KiB)
=== Upload Completed ===
Provider  : s3
Bucket    : contentwork-dev
RemoteKey : test_717_file/test_717_file-bak_20260716_191440.ppke
Target    : s3://contentwork-dev/test_717_file/test_717_file-bak_20260716_191440.ppke
[5/5] Apply local retention policy
=== Completed ===
Action       : backup run
Project      : test_717_file
BakType      : Db
DataDir      : C:\tmp\prj_a
Location     : LocalAndRemote
Force        : false
Artifact     : C:\Users\admin\AppData\Local\Temp\backup\peppykeep\test_717_file\test_717_file-bak_20260716_191440.ppke
ArtifactSize : 1.3 KiB
Bucket       : contentwork-dev
RemoteKey    : test_717_file/test_717_file-bak_20260716_191440.ppke
Provider     : s3
Target       : s3://contentwork-dev/test_717_file/test_717_file-bak_20260716_191440.ppke
LocalCleanup : applied
Status       : Command completed successfully.

⚠️ Note: The suffix name of the encrypted file is .ppke