Backups, restore and PITR
Tested with: zb CLI 0.1 · CloudNativePG barman-cloud · PostgreSQL 17 · MySQL 8.4
Each engine’s backup method is listed on its page and in the engine catalogue: barman-cloud base backups with WAL archiving for PostgreSQL and TimescaleDB, logical dumps (mysqldump, mongodump) for MySQL, MariaDB and MongoDB, RDB/AOF for Valkey and Redis, libSQL bottomless, clickhouse-backup, and data directory snapshots for the other engines. Point-in-time recovery is available only where the engine page says so. Backups stream from inside your instance’s namespace straight to the cell’s object storage. Every backup is checksummed on upload and a restore is rehearsed weekly per engine per cell. The last backup of an instance is never pruned.
Policies by plan
Section titled “Policies by plan”| Plan | Scheduled | Retention | PITR window | Manual snapshots | Cross-region copy | Immutable | Retained after delete |
|---|---|---|---|---|---|---|---|
| Free | none | — | — | 1 | no | no | 0 days |
| Solo | daily | 7 days | add-on | 3 | no | no | 7 days |
| Team | daily | 14 days | add-on | 10 | no | no | 14 days |
| Enterprise | hourly | 35 days | 35 days | Unlimited | yes | yes (Object Lock) | 90 days |
Point-in-time recovery is an add-on on the other paid plans: $100 per instance / month / 7 days of retention. Instances on secure placement always get immutable (Object Lock) backups.
Tighten within the ceiling under Instance → Backups → Policy (schedule time in UTC, retention, PITR on/off, cross-region target). A backup is always taken before a resize or version upgrade; that is not configurable.
Manual snapshots
Section titled “Manual snapshots”zb backups create pg-prod --label pre-release-1.4 # counts against the plan's manual_maxzb backups list pg-prodRestore
Section titled “Restore”-
Pick a backup or a point in time.
shell zb backups list pg-prodzb backups restore pg-prod bk_01J9... --name pg-prod-restore # new instance (default)zb backups pitr-window pg-prodzb backups restore pg-prod bk_01J9... --at "2026-09-27T08:15:00Z" --name pg-prod-pitr # PITR -
The new instance provisions with
restoreFromset, the operator runs the engine’s restore, verification runs, and the instance becomes ready. The original is untouched. -
Point your app at it (or use
zb migrate --from pg-prod-pitr --to pg-prodto copy data back).
In-place restore (--in-place) asks you to type the instance name, takes a pre-change backup, scales down, restores,
scales up and verifies; the downtime estimate is shown first.
Export
Section titled “Export”There is no one-step export yet. To take a logical copy out, run the engine’s own dump tool (pg_dump,
mysqldump, mongodump) against the instance over TLS. Egress is billed.
Verification and evidence
Section titled “Verification and evidence”Weekly restore tests per engine per cell are kept two years; Team, Enterprise and secure-placement orgs see a monthly backup-health report (last successful backup, last verified restore, retention compliance) under Compliance. Every backup, restore, export and delete is an audit event with actor and reason.