> For the complete documentation index, see [llms.txt](https://docs.nxcframework.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nxcframework.net/running-your-server/backups.md).

# Backups and recovery

> **Status: Planned, and incomplete.** No backup schedule, retention policy, or tested restore exists, because no server environment has been identified.

## What must be backed up

| Data                              | Why                                                                                             |
| --------------------------------- | ----------------------------------------------------------------------------------------------- |
| The database                      | Every authoritative record — accounts, characters, money, items, vehicles, properties, evidence |
| Configuration publication history | Rollback targets and the audit trail                                                            |
| Audit records                     | Long-retention accountability data                                                              |
| `server.cfg`                      | Holds operator-supplied secrets and is outside every repository                                 |

Code does not need backing up — it is in version control. **`server.cfg` does**, because it holds secrets that exist nowhere else by design.

## The rule that matters

**A backup nobody has restored from is not a backup.**

A restore is performed on staging as part of establishing the backup process, and again whenever the process changes. This catches the ordinary failures: an export omitting a table, a format nothing can read any more, a compression step whose parameters nobody recorded.

## Before a destructive migration

A documented backup and rollback plan is required **before it runs**. The plan names what is backed up, where, how the restore is performed, and that the restore has been tested.

## Recovery scenarios

| Scenario                      | Response                                                                 |
| ----------------------------- | ------------------------------------------------------------------------ |
| Bad configuration publication | Configuration rollback — no code release, no restore                     |
| Bad code release              | Reinstall the previous compatibility set                                 |
| Bad data migration            | Restore from backup taken before it, or roll back during the soak period |
| Corrupted individual records  | Restore from backup to a staging copy and repair selectively             |
| A committed secret            | **Rotate.** Restoring does not un-publish a secret                       |

The last one is worth stating: a credential that has been pushed to a repository is compromised regardless of whether the commit is removed. Rotation is the only remedy.

## What is outstanding

Backup schedule · retention policy · a tested restore · a staging environment to test it on. All four await a server environment.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.nxcframework.net/running-your-server/backups.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
