Skip to content

Recovery and moves

Terminal window
./ophiolite-ops backup nightly-2026-09-28
./ophiolite-ops copy-out nightly-2026-09-28.tar.gz # to this directory, for your off-host copy

The server is stopped for the backup and started again afterwards. The archive holds the project database, the stored files and records of every exact version, the configuration and a manifest with a checksum for every file. Tokens are not in it; the operator keeps them.

Restore into an empty deployment: a new directory with its own compose.yaml, config.json and secrets (or the same directory after docker compose down -v).

Terminal window
docker compose up -d postgres
./ophiolite-ops copy-in nightly-2026-09-28.tar.gz
./ophiolite-ops restore nightly-2026-09-28

The archive is checked completely before anything is written. A restore into a deployment that already has data is refused. While a restore runs the deployment carries a marker; if the restore is interrupted the server will not start until you remove the deployment (docker compose down -v) and restore again. People sign in with the tokens they already have.

A move transfers the project: afterwards the destination accepts changes and the origin keeps serving reads but refuses changes. People are mapped explicitly; the destination must already have every mapped person as a member.

Terminal window
# destination
./ophiolite-ops identity # note the printed identity
# origin
./ophiolite-ops export-project --project geoscience --out move-1 --transfer \
--target <destination identity> --target-project geoscience
./ophiolite-ops copy-out move-1
# destination: map.json is {"<origin person>": "<destination person>", ...}
./ophiolite-ops copy-in move-1 && ./ophiolite-ops copy-in map.json
./ophiolite-ops import-project --package move-1 --project geoscience \
--identity-map /backups/map.json --authority transfer

An import whose map leaves out a person the project names is refused and changes nothing.