stackapRequest access

Product

Backups

Stackap backs up every project database to a bucket you own, encrypts the backup before it leaves the server, and restores it into a new database to prove it works.

What it does

Each project's Postgres database is dumped from a single consistent snapshot, so the data and the row counts recorded alongside it describe the same instant. The dump is encrypted with AES-256-GCM using a key derived from the master key, and the object's own name is bound into the encryption so a backup cannot be swapped for another and still verify. It is then uploaded to a Cloudflare R2 bucket in your account.

A backup that has never been restored is a hope, not a backup. So once a week Stackap restores each backup into a fresh database and compares the table row counts with the manifest taken at dump time. A passing comparison sets a "restore verified" timestamp you can see. A failing one raises an alert.

Restores only ever go into new databases. There is deliberately no button that overwrites a live database with a backup, because the most dangerous moment in recovery is the one where the fix destroys what survived.

How it works

A background loop checks hourly and does the work that is due: a backup per database each day, a verification each week, and pruning of old backups under a retention rule. Three things are backed up beyond the application databases:

If a backup fails or goes stale, the monitor reports it, and a Telegram alert repeats every six hours until it is resolved. Errors from a failed backup are redacted so a database password cannot leak into a log or an API response.

The one key that matters

Backups and encrypted environment variables are unreadable without the master key. If it is lost, they are unrecoverable. Keep a copy somewhere other than the server, such as a password manager.

In practice

$ stackap status        # overall health plus each monitor check, including backups

Early-access scope

Questions

Where do the backups live?
In a Cloudflare R2 bucket in your own account, encrypted before upload. Stackap runs on your server and your bucket, so there is no Stackap-operated storage anywhere in the path.
Can I restore over the live database?
No, by design. Restores go into a new database, and you then point the app at it or copy what you need.
How do I know a backup is good?
The weekly verification restores it into a scratch database and compares row counts with the manifest. The result is stored and shown, and a failure raises an alert.

Stackap is in early access. Tell us what you run and we will reply with a straight answer about whether it fits.

Ask for an invitation

Last updated .