Backups
OPanel backs up sites with restic: deduplicated, encrypted, incremental snapshots. Each site’s backup lives in its own encrypted repository, so one leaked destination credential never exposes another customer’s data in the clear.
Destinations
Section titled “Destinations”Under Admin → Backups, add one or more destinations:
| Kind | What it is |
|---|---|
| Local | A folder on the node itself (or a mounted volume) |
| S3-compatible | Any S3-compatible bucket — AWS S3, Backblaze B2, Wasabi, MinIO, and similar |
The first destination you add becomes the default. A destination can’t be deleted while a plan or site still uses it; its restic repositories stay in storage either way.
Plan policies
Section titled “Plan policies”Each plan carries a backup policy: whether backups are on, a UTC cron schedule, retention, and whether database dumps are included alongside files.
| Field | Purpose |
|---|---|
schedule |
UTC cron expression; runs at least an hour apart |
retention |
How many snapshots to keep, by keepLast, keepHourly, keepDaily, keepWeekly, keepMonthly, keepYearly |
includeDatabases |
Back up the site’s databases (mariadb-dump --single-transaction) alongside its files |
manualPerDay |
How many backups a site’s own users may start by hand in 24 hours |
A plan’s features.backups and features.backupRetentionDays decide whether the plan includes
backups at all, and the outer bound on how long snapshots are kept. Operators can override any of
these fields for a single site without touching the plan.
Running and restoring
Section titled “Running and restoring”Customers with permission see their site’s backup status, trigger a manual backup (within their plan’s daily limit), and self-serve a restore:
- The whole site
- Files only, or a single file or directory
- Database only
Restores run as a job the customer can follow in real time; whatever a restore replaces is moved
to the server’s trash first, not deleted outright, so a bad restore is itself recoverable within
the cluster’s trash retention window (trashRetentionHours in platform settings, 72 hours by
default).
Operator overrides
Section titled “Operator overrides”Staff can back up any site on demand, without the customer’s daily limit, and can override a site’s schedule, retention or destination independently of its plan — useful for a customer who paid for extra retention, or a migration you want snapshotted more aggressively during cutover.
| Task | Request |
|---|---|
| List backup destinations | GET /api/v1/backup-destinations |
| Add/edit a destination | POST / PATCH /api/v1/backup-destinations/{id} |
| Get/set a plan’s policy | GET, PUT /api/v1/plans/{id}/backup-policy |
| Override a site’s policy | PATCH /api/v1/sites/{id}/backup-policy |
| Start a backup | POST /api/v1/sites/{id}/backups |
| List snapshots | GET /api/v1/sites/{id}/backups/snapshots |
| Restore | POST /api/v1/sites/{id}/restores |
See Backups and cron for the customer-facing version of this page.