Skip to content

Backups, restore and PITR

Tested with: zb CLI 0.1 · CloudNativePG barman-cloud · PostgreSQL 17 · MySQL 8.4

Each engine’s backup method is listed on its page and in the engine catalogue: barman-cloud base backups with WAL archiving for PostgreSQL and TimescaleDB, logical dumps (mysqldump, mongodump) for MySQL, MariaDB and MongoDB, RDB/AOF for Valkey and Redis, libSQL bottomless, clickhouse-backup, and data directory snapshots for the other engines. Point-in-time recovery is available only where the engine page says so. Backups stream from inside your instance’s namespace straight to the cell’s object storage. Every backup is checksummed on upload and a restore is rehearsed weekly per engine per cell. The last backup of an instance is never pruned.

Backup policy ceilings per plan
PlanScheduledRetentionPITR windowManual snapshotsCross-region copyImmutableRetained after delete
Freenone——1nono0 days
Solodaily7 daysadd-on3nono7 days
Teamdaily14 daysadd-on10nono14 days
Enterprisehourly35 days35 daysUnlimitedyesyes (Object Lock)90 days

Point-in-time recovery is an add-on on the other paid plans: $100 per instance / month / 7 days of retention. Instances on secure placement always get immutable (Object Lock) backups.

Tighten within the ceiling under Instance → Backups → Policy (schedule time in UTC, retention, PITR on/off, cross-region target). A backup is always taken before a resize or version upgrade; that is not configurable.

shell
zb backups create pg-prod --label pre-release-1.4 # counts against the plan's manual_max
zb backups list pg-prod
  1. Pick a backup or a point in time.

    shell
    zb backups list pg-prod
    zb backups restore pg-prod bk_01J9... --name pg-prod-restore # new instance (default)
    zb backups pitr-window pg-prod
    zb backups restore pg-prod bk_01J9... --at "2026-09-27T08:15:00Z" --name pg-prod-pitr # PITR
  2. The new instance provisions with restoreFrom set, the operator runs the engine’s restore, verification runs, and the instance becomes ready. The original is untouched.

  3. Point your app at it (or use zb migrate --from pg-prod-pitr --to pg-prod to copy data back).

In-place restore (--in-place) asks you to type the instance name, takes a pre-change backup, scales down, restores, scales up and verifies; the downtime estimate is shown first.

There is no one-step export yet. To take a logical copy out, run the engine’s own dump tool (pg_dump, mysqldump, mongodump) against the instance over TLS. Egress is billed.

Weekly restore tests per engine per cell are kept two years; Team, Enterprise and secure-placement orgs see a monthly backup-health report (last successful backup, last verified restore, retention compliance) under Compliance. Every backup, restore, export and delete is an audit event with actor and reason.