Skip to content

§ Databases · Key-value

etcd backups, natively.

An etcd snapshot written beside the data and collected, with endpoints and certificates passed in the environment.

What Xtic runs

etcdctl
etcdctl snapshot save /var/lib/etcd/xtic-<run>.snapshot.db

Shown with placeholders. Credentials never appear on a command line: they reach the tool through the environment, a file descriptor or a short-lived file in memory.

Restore paths

  • On every member, from the same snapshot: etcdutl snapshot restore, swap the data directory, restart

Verification

etcdutl snapshot status (hash, revision, key count). Every artifact is also hashed, and the stored copy is read back and compared before the run counts as verified.

Version rule

etcd 3.6 restores with etcdutl; upgrade to 3.5.20 or later before 3.6.

Good to know

  • Restoring a Kubernetes control plane's etcd takes the API server down
  • Licence and editions: Apache 2.0.