Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Basic application and database general encryption backup

Backup to local

enforce_provisioning_action

1.bak.toml

bak_location_type = "local"

[object_storage]
enabled = false

[backup_encryption]
# Turn on encryption
enabled = true

cryptographic algorithm
algorithm = "aes-256-gcm"

# Key encapsulation method
key_wrap_algorithm = "x25519"

# Path to the public key file.The public key of the recipient (viewer of the backup) is stored here
public_key_file = "/tmp/key/ppk.pub"

# Delete clear text after encryption
delete_plain_after_encrypt = true
  1. Generate key see –––––––––––––– Link pending

Perform the preliminary checks: §.

Perform application data or database backup pre-checks

# Performing an App Data Backup
peppykeep backup run --bak-type app-data --config-home ~/.peppykeep/conf
or @
# Performing a Database Backup
peppykeep backup run --bak-type db --config-home ~/.peppykeep/conf

When the pre-test is successful, the output is as follows:

=== Dry Run ===
Action     : backup run
Project    : test_717_file
BakType    : AppData
DataDir    : /tmp/test_file_717
Location   : Local
Encryption : true
Force      : false
Next       : Re-run with --apply to execute.

or @

=== Dry Run ===
Action     : backup run
Project    : test_717_file
BakType    : Db
DataDir    : /tmp/test_file_717
Location   : Local
Encryption : true
Force      : false
Next       : Re-run with --apply to execute.

⚠️ Note: The suffix name of the encrypted file is .ppke

Perform a backup

Perform application data or database backups

# Performing an App Data Backup
peppykeep backup run --bak-type app-data --apply --config-home ~/.peppykeep/conf
or @
# Performing a Database Backup
peppykeep backup run --bak-type db --apply --config-home ~/.peppykeep/conf

When the pre-test is successful, the output is as follows:

=== Completed ===
Action       : backup run
Project      : test_717_file
BakType      : AppData
DataDir      : /tmp/test_file_717
Location     : Local
Force        : false
Artifact     : /tmp/backup/peppykeep/test_717_file/test_717_file-bak_20260717_142418.ppke
ArtifactSize : 480 B
Status       : Command completed successfully.

or @

=== Completed ===
Action       : backup run
Project      : test_717_file
BakType      : Db
DataDir      : /tmp/test_file_717
Location     : Local
Force        : false
Artifact     : /tmp/backup/peppykeep/test_717_file/test_717_file-bak_20260717_142437.ppke
ArtifactSize : 1.3 KiB
Status       : Command completed successfully.

⚠️ Note: The suffix name of the encrypted file is .ppke

Backup to remote

enforce_provisioning_action

1.bak.toml

bak_location_type = "local_and_remote"

[object_storage]
enabled = true

[backup_encryption]
# Turn on encryption
enabled = true

cryptographic algorithm
algorithm = "aes-256-gcm"

# Key encapsulation method
key_wrap_algorithm = "x25519"

# Path to the public key file.The public key of the recipient (viewer of the backup) is stored here
public_key_file = "/tmp/key/ppk.pub"

# Delete clear text after encryption
delete_plain_after_encrypt = true
  1. Generate key see –––––––––––––– Link pending

Perform the preliminary checks: §.

Perform application data or database backup pre-checks

# Performing an App Data Backup
peppykeep backup run --bak-type app-data --config-home ~/.peppykeep/conf
or @
# Performing a Database Backup
peppykeep backup run --bak-type db --config-home ~/.peppykeep/conf

When the pre-test is successful, the output is as follows:

=== Dry Run ===
Action     : backup run
Project    : test_717_file
BakType    : AppData
DataDir    : /tmp/test_file_717
Location   : LocalAndRemote
Encryption : true
Force      : false
Next       : Re-run with --apply to execute.

or @

=== Dry Run ===
Action     : backup run
Project    : test_717_file
BakType    : Db
DataDir    : /tmp/test_file_717
Location   : LocalAndRemote
Encryption : true
Force      : false
Next       : Re-run with --apply to execute.

⚠️ Note: The suffix name of the encrypted file is .ppke

Perform a backup

Perform application data or database backups

# Performing an App Data Backup
peppykeep backup run --bak-type app-data --apply --config-home ~/.peppykeep/conf
or @
# Performing a Database Backup
peppykeep backup run --bak-type db --apply --config-home ~/.peppykeep/conf

When the pre-test is successful, the output is as follows:

=== Completed ===
Action       : backup run
Project      : test_717_file
BakType      : AppData
DataDir      : /tmp/test_file_717
Location     : LocalAndRemote
Force        : false
Artifact     : /tmp/backup/peppykeep/test_717_file/test_717_file-bak_20260717_142723.ppke
ArtifactSize : 481 B
Bucket       : VoosTestBucket
RemoteKey    : test_717_file/test_717_file-bak_20260717_142723.ppke
Provider     : s3
Target       : s3://VoosTestBucket/test_717_file/test_717_file-bak_20260717_142723.ppke
LocalCleanup : applied
Status       : Command completed successfully.

or @

=== Completed ===
Action       : backup run
Project      : test_717_file
BakType      : Db
DataDir      : /tmp/test_file_717
Location     : LocalAndRemote
Force        : false
Artifact     : /tmp/backup/peppykeep/test_717_file/test_717_file-bak_20260717_142749.ppke
ArtifactSize : 1.3 KiB
Bucket       : VoosTestBucket
RemoteKey    : test_717_file/test_717_file-bak_20260717_142749.ppke
Provider     : s3
Target       : s3://VoosTestBucket/test_717_file/test_717_file-bak_20260717_142749.ppke
LocalCleanup : applied
Status       : Command completed successfully.

⚠️ Note: The suffix name of the encrypted file is .ppke