Novij Backup Agent
Changes
- File copies and SQL dumps can use a separate disk through `agent.staging_dir`.
Prepared tar files and downloaded archives remain in `temp_dir`; interrupted
uploads still resume from an immutable checkpoint. Existing configurations keep
their previous placement. The fleet guide documents staggered overnight timers.
- ZK coupon creation, block signing, funding and balance verification share
one financial session on the active Registry primary. Its role is verified
before payment; another Relay's replication delay cannot trigger a second top-up.
- An interrupted resume preserves all previously verified checkpoint blocks.
Checkpoint updates also reject changes to the original snapshot archive.
- Temporary Relay unavailability during block reads uses bounded retries with
a fresh nonce. Uncertain payments, access denials and integrity failures are
not retried; exhausted attempts still report failure and retain the checkpoint.
- Fleet profiles support calendar-day intervals without resetting at month or
year boundaries. Interrupted snapshots resume before checking the next due
date; a completed resume avoids an unnecessary second capture in that interval.
- Fleet profiles run and retain only their selected job. Docker projects can use
separate schedules for files, images and SQL dumps; a shared lock serializes
profiles whose schedules overlap.
- Repeated block references in a batch retain complete data at every position.
Storage and ZK Registry caches use the private agent data directory, including
systemd runs without `HOME`, and no longer affect shared `/tmp` permissions.
- Selected endpoints remain fixed within the backend session. New transport
clients do not repeat discovery or select Storage independently of billing identity.
- Block commits and payment nonces use native Relay batch requests. Verification
reads identify the issuing Relay to avoid an extra hop; Storage only accepts
issuer addresses from its trusted topology.
- Interrupted uploads retain the tar and a private checkpoint. `resume` continues
the same snapshot without new dumps and reuses verified blocks. Fleet snapshot
resumes pending uploads before the next cycle. Complete archives from older
agents can be validated and registered for continuation.
- Large archives stream with bounded RAM usage. Version 2 snapshots contain
independently compressed and encrypted content-defined chunks. Unchanged
chunks are reused after read-back and decryption checks.
- Each manifest describes a complete snapshot. Large manifests use authenticated
parts; retention preserves every block needed by retained snapshots.
- Fleet snapshots discover projects, Docker images, MySQL/MariaDB, PostgreSQL,
SQLite and Redis. Nontransactional MySQL tables use READ locks during dumping;
PostgreSQL preserves databases and roles, and SQLite uses online backup.
- Preparation and retention failures use the configured Telegram transport.
Success notifications include a recovery code for rebuilding a lost local
index with `novij-backup recover-index`.
- Storage failover discovers the new billing wallet before issuing payment
nonces. Confirmed batch items are not written again. Write responses wait up
to 45 seconds to accommodate the normal quorum commit deadline.
- Publishing verifies and preserves package history over HTTPS with write-only
SSH credentials. Repeated CMake configuration keeps project tests enabled.
Compatibility and operation
- Existing v1 snapshots remain readable; restoring v2 requires a current agent.
- Local staging and the uncompressed tar need up to twice the source files and
SQL dumps. Online file snapshots do not provide one atomic point in time
across independent services.
- Each production agent needs a separate ZK coupon. Keep decryption keys,
passwords, configuration, index and coupon in a separate private recovery set.
- Validate permissions, ownership, ACLs and service configuration during restore.
The file snapshot is not a disk image for automatic bare-metal recovery.
- Update with `sudo novij-backup update`. Configuration and keys are preserved.