# Database backups

> Back up Falak-managed databases to S3, Cloudflare R2, Backblaze B2, DigitalOcean Spaces or MinIO — schedules, retention, on-demand backups and restores.

Source: https://falak.sh/docs/databases/backups/

Falak dumps your databases on the database server and uploads the dump straight to object storage. Servers never hold storage credentials: the control plane hands the agent a presigned upload URL for each backup.

This page is about **your apps' databases**. To back up Falak itself (its own database, Fleet CA and settings), see [Back up and restore Falak](/docs/operations/backup-restore/).

## 1. Add backup storage

1. Open **Settings → Backup storage** → **Add** (permission `databases.storage.manage`, owners and admins).
2. Pick the driver and fill in the bucket and credentials:

   | Driver | Value | Region hint |
   |---|---|---|
   | Amazon S3 | `s3` | e.g. `eu-central-1` |
   | Cloudflare R2 | `r2` | `auto` |
   | Backblaze B2 | `b2` | e.g. `us-west-004` |
   | DigitalOcean Spaces | `spaces` | e.g. `fra1` |
   | MinIO / S3-compatible | `minio` | `us-east-1` unless configured otherwise; **endpoint required** (https) |

   | Field | Rule |
   |---|---|
   | Name | Unique in the organization |
   | Bucket | 3–63 characters, lowercase |
   | Prefix | Optional path prefix |
   | Endpoint | `https://` URL; required for MinIO |
   | Path-style | For S3-compatible services that need it |

3. Save. Falak verifies access and stores the credentials encrypted.

![Settings → Backup storage: storage providers with their driver, bucket and status.](./_images/settings-storage.png)

Endpoints on private, loopback or link-local addresses (a MinIO on your LAN) are refused unless the operator sets `FALAK_STORAGE_ALLOW_PRIVATE_ENDPOINTS=true`. This stops storage admins from making the control plane probe internal services.

## 2. Schedule backups

1. Open the database panel → **Backups** → **New schedule**.
2. Fill in:

   | Field | Rule |
   |---|---|
   | Name | Up to 100 characters |
   | Storage | A storage provider |
   | Databases | One or more databases on this engine (up to 200) |
   | Cron | A cron expression, for example `0 3 * * *` |
   | Keep the newest N | 1–1000 (optional) |
   | Keep for N days | 1–3650 (optional) |
   | Compression | `gzip` (default) or `none` |

3. Save. Old backups beyond the retention are pruned from storage.

![Database panel → Backups: schedules and the backup history with status, size and actions.](./_images/canvas-db-backups.png)

## Back up now

Run a one-off backup of a single database from its row in **Databases & users** or **Backups**, choosing the storage provider and compression.

## Restore

1. Open **Backups**, pick a successful backup and choose **Restore**.
2. Choose the target database and type its name to confirm.
3. The agent downloads the dump through a presigned URL and restores it. **The target's data is overwritten.**

Restoring needs `databases.restore` (owners and admins).

## Timing

| Setting | Value |
|---|---|
| Backup command timeout | 3600 s |
| Restore command timeout | 3600 s |
| Upload URL lifetime | 12 h (`FALAK_BACKUP_UPLOAD_URL_TTL`) |
| Download URL lifetime | 6 h (`FALAK_BACKUP_DOWNLOAD_URL_TTL`) |

## Alerts

| Alert type | Severity |
|---|---|
| `databases.backup_failed` | critical |
| `databases.backup_recovered` | info (backups succeed again) |
| `databases.restore_failed` | critical |
| `databases.restore_succeeded` | info |

Route them to a channel in [Alerts](/docs/observability/alerts/).

## Limits

- Backups and restores against real S3 are covered by unit and feature tests, not yet by the end-to-end suite. Test a restore before you rely on it.
- There is no local-disk storage driver; use an S3-compatible bucket (MinIO works).

## Next steps
