Skip to content

Frequently asked questions

browse

Do I need to install an agent on my servers?

Section titled “Do I need to install an agent on my servers?”

No. The platform connects over SSH. The onboarding script only creates a backup account and, if you want, the small bmp-helper that limits what that account may read and restore.

Linux servers reachable over SSH with a POSIX shell. Windows hosts are not supported as sources.

31 engines, from PostgreSQL and MySQL to SQL Server, MongoDB, Redis, Oracle and more - on the host or in a container - plus any you add with an engine definition. See Supported databases.

On storage targets you add: S3-compatible buckets (MinIO, AWS S3, Wasabi, Backblaze B2, Cloudflare R2, Ceph and others) or local and mounted directories. Nothing goes anywhere else.

By default yes, with the platform key (AES-256-GCM, one key per backup). You can choose a password, recipients’ public keys, or none - unless an environment or target forbids it. See Encryption and keys.

Can anyone read my stored passwords and keys?

Section titled “Can anyone read my stored passwords and keys?”

No. Credentials are write-only: they are encrypted at rest, never shown again, and passed to tools on standard input, never on a command line.

What if we lose the platform and its master key?

Section titled “What if we lose the platform and its master key?”

The offline recovery kit and bmctl decrypt platform-key backups without the platform. Generate the kit and store it safely - see Keys and the recovery kit.

Not if the bucket uses Object Lock: locked backups cannot be deleted early even with a stolen key. Add a second copy in another account for 3-2-1. See Object Lock.

Why am I asked for an authenticator code again?

Section titled “Why am I asked for an authenticator code again?”

Sensitive actions need a fresh second factor (step-up). One code unlocks them for 5 minutes.

Keep the defaults - tar.zst for files and native + zstd for databases. Choose zip or 7z only when someone needs to open the files on a desktop.

Register it as a database instance and add it as a Database source: the engine’s own dump tool makes a consistent copy. Do not back up its data folder as files.

Can I back up a Docker container without stopping it?

Section titled “Can I back up a Docker container without stopping it?”

Yes. Leave it running, or pause its containers for a crash-consistent copy without a restart. Stopping gives a fully consistent copy with a short downtime.

What happens to scheduled backups while the platform is down?

Section titled “What happens to scheduled backups while the platform is down?”

Each schedule decides: run once when the platform is back, wait for the next time, or record them as skipped.

As long as the plan’s retention policy says. Pin an artifact, keep it until a date, or put it on legal hold to keep it longer. See Retention policies.

It stored the backup but skipped or dropped something - unreadable files, metadata a zip cannot hold. The run console’s Warnings tab lists them.

Run a drill: it restores the backup into a sandbox, validates it and marks it Restore proven. See Prove restores with drills.

Can I restore one file instead of the whole backup?

Section titled “Can I restore one file instead of the whole backup?”

Yes - browse the backup’s files on Restore points, select what you need, and restore or download it. See Browse and restore single files.

Four eyes: a second person checks every restore that needs approval. The requester can never approve their own request.

Before overwriting, the platform takes a safety snapshot of the target and keeps it 14 days. A failed or cancelled restore offers Roll back from safety snapshot.

How do I give someone access to only some servers?

Section titled “How do I give someone access to only some servers?”

Give them a scoped role (Backup Operator, Restore Operator or Viewer) and set their Scopes on Admin › Users.

They sign in with a recovery code. Without one, an administrator uses Reset MFA, and they set up a new authenticator at the next sign-in.

How do we pause all backups for maintenance?

Section titled “How do we pause all backups for maintenance?”

Switch on Maintenance mode at the top of Admin › Settings, optionally with an end time.

Open the complete manual from the knowledge base home, then Print or Download PDF. Any single article prints from its own Print button.