Skip to main content

Backup & Disaster Recovery

A complete backup of Lioran S3 requires snapshotting both the Metadata Store (RocksDB) and the Physical Payload Volumes.


1. What to Backup​

To achieve full disaster recovery, you must preserve:

  1. RocksDB Metadata Directory: /data/metadata/ Contains all bucket definitions, quota tracking, object keys, ETags, SHA-256 digests, timestamps, and user accounts.
  2. Object Payload Directory: /data/objects/ Contains all committed physical binary data files.
  3. Configuration & Secrets: .env file containing BASTION_ADMIN_PASSWORD and BASTION_SIGNING_SECRET.

:::caution Atomic Backup Consistency Because metadata and object payloads are decoupled, backup snapshots should be taken concurrently (e.g. via storage volume snapshots) or while the server is gracefully stopped to avoid inconsistencies. :::


2. Backup Strategies​

If running on AWS (EBS), Google Cloud (Persistent Disks), or Hetzner Cloud:

  1. Trigger a point-in-time snapshot of the underlying block storage volume hosting /data.
  2. Block storage snapshots are atomic and preserve both RocksDB SSTables and payload blobs in a consistent state.

Option B: Tarball Archive (Offline Backup)​

  1. Stop the container stack:
    docker compose stop
  2. Create a compressed archive of the persistent volume:
    tar -czvf /backups/bastion-backup-$(date +%Y%m%d).tar.gz /data/metadata /data/objects
  3. Restart the stack:
    docker compose start

3. Disaster Recovery Procedure​

To restore Lioran S3 from a backup:

  1. Deploy a new server instance with Docker and Docker Compose.
  2. Extract the backup archive into the /data directory:
    tar -xzvf /backups/bastion-backup-20261001.tar.gz -C /
  3. Restore the .env file containing the matching BASTION_SIGNING_SECRET.
  4. Launch the Docker stack:
    docker compose up -d
  5. Verify health and metadata integrity:
    liorans3 doctor
    liorans3 bucket ls