Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Encrypted backups

It is necessary to prevent the backup archive from being unauthorized to read, encrypt the backup with the public key, and separate the recovery private key from the backup node.

Recommended process:

  1. Use ppk key generate to generate the key pair.
  2. Configure only the public key in the backup configuration, first perform a dry-run check of inputs, outputs, and destinations.
  3. Perform a backup and confirm the generation of the .ppke file.
  4. Private keys are kept in an independent recovery environment, and decryption and recovery exercises are performed regularly.

See Encryption and Decryption for the parameters and compatible formats of the encryption archive. Do not write private key passwords to configurations, scripts, or tickets.