Recover an Appliance from a full Backup
Use the recovery wizard to rebuild an appliance whose machines were lost. Work as a Management administrator while no appliance is connected. Use a separate fresh Management instance if the existing one remains connected to an appliance. Full recovery restores the backed-up release; any later release update is a separate operation.
Before you begin
Prepare all of these inputs:
-
A completed full appliance backup. A database-only point is insufficient.
-
The matching artifact bundle, including the private keys required to read that backup.
-
A release bundle for the exact appliance version recorded in the backup, available in Management’s release sources.
-
Management compatible with that appliance release.
-
Replacement machines with the required disks and network connectivity.
The captured cluster name, application hostname, and existing node names remain unchanged. The wizard lets you choose the replacement topology, platform, and network. Check replacement resources against the requirements and the release’s supported deployment configuration.
Keep any surviving original machines isolated from the replacement deployment. Recovery writes the selected target disks. Verify the full disk identity and destructive confirmation before submitting.
Run Recovery
-
In Settings > Bundles, upload the full backup for use as a recovery bundle. Retrieve or upload the matching release bundle through bundle management. Stored recovery bundles remain until an administrator deletes them.
-
Open Installation > Recover and select Start the recovery wizard. Resolve an already-open installation or draft before starting another wizard.
-
Select the matching release. In Recovery bundles, select the stored recovery bundle and provide its Matching artifacts bundle.
-
Select Load recovery settings. Management validates the input before changing target machines. Confirm the displayed appliance version, cluster name, and captured nodes.
-
Complete the replacement topology, platform, and network steps. Discover the replacement machines and select their disks as described in the installation procedure.
-
Review every target and the recovery settings, then confirm and submit the recovery.
-
Follow the operation through verification and any GitOps finalization. Download and verify the resulting artifact bundle when prompted, and retain it outside Management.
Management keeps the matching artifact upload in memory. Its size limit is 10 MB. Submit within six hours of loading the recovery settings. After a reload or expiry, select the stored recovery bundle again and supply the matching artifacts; the stored backup remains available.
Verify the Restored Appliance
Follow the post-installation checks. Confirm the restored release and appliance identity, application access, database-backed records expected at the backup’s capture time, and HSM connectivity where configured. Check that scheduled backups resume and that a new completed full backup becomes available.
Expect excluded telemetry history and Grafana UI-created state to be absent. External HSM objects are not recreated from an appliance backup.
Troubleshooting stopped Recovery
Record the current stage and exact error. Retain the original full backup, artifacts, and matching release bundle. Correct missing connectivity or invalid inputs before another attempt. Cancellation does not undo writes already made to target disks. Collect diagnostics and contact support if the recovery cannot complete.