Backup & Disaster Recovery
A complete backup of Lioran S3 requires snapshotting both the Metadata Store (RocksDB) and the Physical Payload Volumes.
1. What to Backup
To achieve full disaster recovery, you must preserve:
- RocksDB Metadata Directory:
/data/metadata/Contains all bucket definitions, quota tracking, object keys, ETags, SHA-256 digests, timestamps, and user accounts. - Object Payload Directory:
/data/objects/Contains all committed physical binary data files. - Configuration & Secrets:
.envfile containingBASTION_ADMIN_PASSWORDandBASTION_SIGNING_SECRET.
:::caution Atomic Backup Consistency Because metadata and object payloads are decoupled, backup snapshots should be taken concurrently (e.g. via storage volume snapshots) or while the server is gracefully stopped to avoid inconsistencies. :::
2. Backup Strategies
Option A: Block Volume Snapshots (Recommended)
If running on AWS (EBS), Google Cloud (Persistent Disks), or Hetzner Cloud:
- Trigger a point-in-time snapshot of the underlying block storage volume hosting
/data. - Block storage snapshots are atomic and preserve both RocksDB SSTables and payload blobs in a consistent state.
Option B: Tarball Archive (Offline Backup)
- Stop the container stack:
docker compose stop
- Create a compressed archive of the persistent volume:
tar -czvf /backups/bastion-backup-$(date +%Y%m%d).tar.gz /data/metadata /data/objects
- Restart the stack:
docker compose start
3. Disaster Recovery Procedure
To restore Lioran S3 from a backup:
- Deploy a new server instance with Docker and Docker Compose.
- Extract the backup archive into the
/datadirectory:tar -xzvf /backups/bastion-backup-20261001.tar.gz -C / - Restore the
.envfile containing the matchingBASTION_SIGNING_SECRET. - Launch the Docker stack:
docker compose up -d
- Verify health and metadata integrity:
liorans3 doctorliorans3 bucket ls