Basic Application Data Backup
Taking the reference configuration directory ~/.peppykeep/conf as an example, this article demonstrates the backup application directory file on macOS. It is recommended to dry-run (without --apply) every step before formally executing.
Prepare test data
mkdir -p /tmp/test_file_717
echo "sample content" > /tmp/test_file_717/sample.txt
Backup to local
enforce_provisioning_action
1. app.toml — 详见 app.toml 配置说明
2. bak.toml — Key Fragments (local, non-encrypted examples only):
[public]
bak_type = "app_data"
bak_location_type = "local"
history_bak_num = 3
log_level = "INFO"
log_dir = "/tmp/logs/peppykeep"
local_bak_home = "/tmp/backup/peppykeep"
local_tmp_home = "/tmp/.peppykeep_tmp"
max_bak_queue_size = 1
[backup_encryption]
enabled = false
完整参数见 bak.toml 配置说明。
3. prj.toml — Key Fragments:
[local]
prj_key = "test_717_file"
data_dir = "/tmp/test_file_717"
详见 prj.toml 配置说明。
Perform the preliminary checks: § .
peppykeep backup run \
--config-home ~/.peppykeep/conf \
--bak-type app-data
When the pre-test is successful, the output is as follows:
=== Dry Run ===
Action : backup run
Project : test_717_file
BakType : AppData
DataDir : /tmp/test_file_717
Location : Local
Encryption : false
Force : false
Next : Re-run with --apply to execute.
| Field | Description |
|---|---|
Project | Identification of the currently backed up item (prj_key in prj.toml) |
BakType | Backup type: AppData means file only |
Location | Local means local storage only |
Encryption | Whether encryption is enabled |
Next | Formal execution after adding `--apply’ |
Perform a backup
peppykeep backup run \
--config-home ~/.peppykeep/conf \
--apply \
--bak-type app-data
Example output on success:
=== Completed ===
Action : backup run
Project : test_717_file
BakType : AppData
DataDir : /tmp/test_file_717
Location : Local
Force : false
Artifact : /tmp/backup/peppykeep/test_717_file/test_717_file-bak_20260730_114551.ppk
ArtifactSize : 291 B
Status : Command completed successfully.
Product extension: unencrypted as
.ppk;.ppke 'when[backup_encryption] enabled = true `is enabled.
Backup to local and upload object store
When bak_location_type = "local_and_remote" and [object_storage] enabled = true in ’bak.toml`, the object storage is automatically uploaded after the backup is completed.
enforce_provisioning_action
bak.toml Key Fragments (S3 compatible storage example):
[public]
bak_type = "app_data"
bak_location_type = "local_and_remote"
history_bak_num = 3
log_level = "INFO"
log_dir = "/tmp/logs/peppykeep"
local_bak_home = "/tmp/backup/peppykeep/test_717_file"
local_tmp_home = "/tmp/.peppykeep_tmp"
max_bak_queue_size = 1
[object_storage]
enabled = true
provider = "s3"
bucket = "VoosTestBucket"
prefix = ""
endpoint = "https://s3.ca-east-006.backblazeb2.com"
region = "ca-east-006"
access_key_id = "<YOUR_ACCESS_KEY_ID>"
access_key_secret = "<YOUR_ACCESS_KEY_SECRET>"
path_style = true
[backup_encryption]
enabled = true
algorithm = "aes-256-gcm"
key_wrap_algorithm = "x25519"
public_key_file = "/tmp/ppk_key/ppk.pub"
delete_plain_after_encrypt = true
Perform the preliminary checks: § .
peppykeep backup run \
--config-home ~/.peppykeep/conf \
--bak-type app-data
When the pre-test is successful, the output is as follows:
=== Dry Run ===
Action : backup run
Project : test_717_file
BakType : AppData
DataDir : /tmp/test_file_717
Location : LocalAndRemote
Encryption : true
Force : false
Next : Re-run with --apply to execute.
Perform a backup
peppykeep backup run \
--config-home ~/.peppykeep/conf \
--apply \
--bak-type app-data
Example output on success:
[1/5] Prepare local workspace
[2/5] Copy application data
[3/5] Create and encrypt backup artifact
Encryption progress: started (292 B)
Encryption progress: 100% (292 B/292 B)
[4/5] Upload artifact to object storage
=== Upload Target ===
Provider : s3
Bucket : VoosTestBucket
RemoteKey : test_717_file/test_717_file-bak_20260730_114555.ppke
Target : s3://VoosTestBucket/test_717_file/test_717_file-bak_20260730_114555.ppke
Upload progress: 100% (456 B/456 B)
[5/5] Apply local retention policy
=== Completed ===
Action : backup run
Project : test_717_file
BakType : AppData
DataDir : /tmp/test_file_717
Location : LocalAndRemote
Force : false
Artifact : /tmp/backup/peppykeep/test_717_file/test_717_file/test_717_file-bak_20260730_114555.ppke
ArtifactSize : 456 B
Bucket : VoosTestBucket
RemoteKey : test_717_file/test_717_file-bak_20260730_114555.ppke
Provider : s3
Target : s3://VoosTestBucket/test_717_file/test_717_file-bak_20260730_114555.ppke
LocalCleanup : applied
Status : Command completed successfully.
| Field | Description |
|---|---|
Artifact | Local backup file path; encrypted as.ppke |
RemoteKey | Object Storage Object Key |
Target | Object store full S3 uri |
LocalCleanup | Local History Cleanup Status |
Local Only, No Upload (Temporary Override)
When configured to local_and_remote but only want to keep local this time:
peppykeep backup run \
--config-home ~/.peppykeep/conf \
--apply \
--bak-type app-data \
--no-upload