Skip to content

Off-site backups

Keep an encrypted copy of your site in your own S3-compatible or Google Cloud Storage bucket, restore it into staging, and restore it without Avaloi if you ever need to.

Parts of this feature are still being built. The Not yet section lists them.

Off-site backups put an encrypted copy of your site in a bucket you own. Avaloi uses restic, so each copy is a restic snapshot, and only new data is uploaded after the first one. You keep the bucket and the repository password, so you can restore the site even without Avaloi.

Each snapshot holds the site's code, its uploads, and a dump of its database.

Connect a bucket

  1. Open a site, then Backups. You can also open Add-ons and select Connect a bucket on the external backups card.
  2. In Off-site backups, select Connect a bucket.
  3. Pick the storage provider and fill in the fields below.
  4. Select Connect and test. Avaloi stores the key encrypted, tests the bucket, and creates the repository.
  5. Copy the repository password and save it in your password manager. Avaloi shows it only once.

The Folder field is the folder in the bucket for this site's repository. It starts as avaloi/<site slug>. Use one folder per site.

If you already have a restic repository in that folder, tick I already have a repository in this folder and enter its password. Avaloi then uses that repository and does not show a new password.

S3-compatible storage

Enter the endpoint, the bucket, an access key ID, and a secret access key. The endpoint must be an https address on the public internet. Some common endpoints:

  • AWS S3: https://s3.<region>.amazonaws.com, such as https://s3.us-east-1.amazonaws.com. Enter the region too.
  • Backblaze B2: the S3 endpoint of your bucket, such as https://s3.us-west-004.backblazeb2.com.
  • Cloudflare R2: https://<account id>.r2.cloudflarestorage.com.
  • Wasabi: https://s3.<region>.wasabisys.com, such as https://s3.us-east-1.wasabisys.com.

Make a key that can read, write, list, and delete in this bucket only. Avaloi needs delete to apply the retention rules.

Google Cloud Storage

  1. In the Google Cloud console, create a service account.
  2. Give it the Storage Object Admin role on the bucket.
  3. Create a JSON key for the service account.
  4. Paste the key into Service account key (JSON), or pick the file.

When backups run

Avaloi runs an off-site backup about one hour after the daily backup of live. Turn Back up every day off to pause the daily run. You can still run one at any time.

To run one now, select Back up to my bucket. It backs up the environment you have open. You can watch it in the jobs drawer.

Test connection checks that Avaloi can still reach the bucket. If a test or a run fails, the card shows the error, such as a key that no longer works.

Retention

After each run, Avaloi removes old snapshots with restic's forget and prune. The defaults keep:

  • 14 daily snapshots.
  • 4 weekly snapshots.
  • 0 extra latest snapshots.

Change the numbers under Retention and schedule and select Save retention. Set a rule to 0 to turn it off. At least one rule must keep something.

Price

Off-site backups are metered. Each backup that succeeds costs a fixed amount, plus an amount per GB it uploads. The card shows both prices. Avaloi records the usage on each run. Your storage provider bills you for the bucket on its own.

See your snapshots

The snapshot list shows what is in the bucket, newest first. It comes from the last time Avaloi read the bucket. Select Refresh list to read it again.

Restore a snapshot

  1. Select Restore on a snapshot.
  2. Pick the target: a staging or multidev environment of this site. Live is never a target.
  3. Pick what to restore: the database, the uploads, the code, or more than one.
  4. Type the name of the target environment and select Restore.

Code restores only into an environment in SFTP mode, because code in Git mode is a read-only release. Restore into staging, check the result, then push it to live.

Restore without Avaloi

With the bucket and the repository password, you can restore with restic on any computer. For S3-compatible storage:

export AWS_ACCESS_KEY_ID=<access key id>
export AWS_SECRET_ACCESS_KEY=<secret access key>
export RESTIC_PASSWORD=<repository password>
restic -r s3:https://s3.us-east-1.amazonaws.com/<bucket>/avaloi/<site slug> snapshots
restic -r s3:https://s3.us-east-1.amazonaws.com/<bucket>/avaloi/<site slug> restore latest --target ./restore

For Google Cloud Storage, set GOOGLE_APPLICATION_CREDENTIALS to the key file and use -r gs:<bucket>:/avaloi/<site slug>.

The restored folder holds the site's files and a database dump that you can import with mysql.

Remove the connection

Select Remove, then Remove connection. Avaloi stops the backups and deletes the key it stored. The snapshots stay in your bucket. You can still restore them with restic and your password, or connect the bucket again later.

Who can do what

  • Connect a bucket, run a backup, test, refresh the list, restore, and remove: people with database access.
  • Change the retention and pause the daily run: people who can update environments.
  • See the card: everyone who can see the site.

API

  • GET /v1/sites/{id}/offsite-backup
  • PUT /v1/sites/{id}/offsite-backup (connect; send confirm: true)
  • PATCH /v1/sites/{id}/offsite-backup (retention and pause)
  • DELETE /v1/sites/{id}/offsite-backup?confirm=true
  • POST /v1/sites/{id}/offsite-backup/test
  • POST /v1/sites/{id}/offsite-backup/snapshots/refresh
  • POST /v1/sites/{id}/offsite-backup/restore
  • POST /v1/environments/{id}/offsite-backup/run

MCP

The MCP server offers get_offsite_backup, run_offsite_backup, restore_offsite_backup, and disconnect_offsite_backup. Connecting works only in the dashboard or the API, because bucket keys must never go into a chat.

Not yet

  • Stripe metering is not wired yet. Avaloi records the usage on each run, and billing reads it later.
  • A run against a real node and a real bucket still needs to be proven end to end.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.