---
title: "Backups and restore"
description: "What a database backup holds, and how to bring wervt back from one."
canonical_url: "https://wervt.app/self-hosting/backups"
---
# Backups and restore

> What a database backup holds, and how to bring wervt back from one.

All app data lives in the `wervt` database, one schema per app (`app_<name>`). A backup is a
dump of that database, for example Coolify's scheduled backups
(`pg_dump --format=custom --no-acl --no-owner`).

The dump doesn't hold:

- **App roles.** Roles are cluster-wide, not part of a database dump. Their passwords are
derived from `WERVT_DB_SECRET`, so wervt can recreate them.
- **Ownership and grants**, with `--no-owner --no-acl`. After a restore, everything belongs to
the restoring superuser and the app roles can't connect.

`wervt reprovision` puts both back. It needs the same `WERVT_DB_SECRET` as before.

## Restore

1. Stop the runtime, so apps don't write during the restore.
2. Restore the dump into an empty `wervt` database:```bash
pg_restore --username postgres --dbname wervt --no-owner --no-acl wervt.dump
```
3. Recreate the roles, CONNECT grants and ownership, and run each app's migrations:```bash
wervt reprovision --all
```

<br />

Migrations only run when the backup is older than the active release.
4. Clear Electric's storage (the `electric` volume) and restart Electric. Its shape logs belong
to the old database.
5. Start the runtime.

`wervt reprovision <app>` does the same for one app. It is safe to run any time.

## Files (Garage)

App files live in Garage, one bucket per app (`app-<name>`). The `storage-backup` service copies
Garage to a Hetzner Storage Box every night:

- `data/`: Garage's data blocks. They never change once written, so each night only new blocks
are sent.
- `meta/`: a metadata snapshot taken right before the copy.

It needs `STORAGE_BOX_HOST` (e.g. `u123456.your-storagebox.de`), `STORAGE_BOX_USER` and
`STORAGE_BOX_PASSWORD`, plus optionally `STORAGE_BOX_DIR` (default `wervt/garage`). It connects over SFTP on
port 23. Until they're set it doesn't back anything up, and says so in its log.

### Restore

1. Stop Garage.
2. Copy the backup into the `garage` volume: `data/` to `/var/lib/garage/data`, and the
contents of `meta/` to `/var/lib/garage/meta`:```bash
rclone copy box:wervt/garage/data /var/lib/garage/data
rclone copy box:wervt/garage/meta /var/lib/garage/meta
```
3. Start Garage. Buckets and keys come back with the metadata. The keys are derived from
`WERVT_DB_SECRET`, so with the same secret apps reach their files as before.


## Sitemap

See the full [sitemap](https://wervt.app/sitemap.md) for all pages.
