Recover an Appliance from a full Backup

Use the recovery wizard to rebuild an appliance whose machines were lost. Work as a Management administrator while no appliance is connected. Use a separate fresh Management instance if the existing one remains connected to an appliance. Full recovery restores the backed-up release; any later release update is a separate operation.

Before you begin

Prepare all of these inputs:

  • A completed full appliance backup. A database-only point is insufficient.

  • The matching artifact bundle, including the private keys required to read that backup.

  • A release bundle for the exact appliance version recorded in the backup, available in Management’s release sources.

  • Management compatible with that appliance release.

  • Replacement machines with the required disks and network connectivity.

The captured cluster name, application hostname, and existing node names remain unchanged. The wizard lets you choose the replacement topology, platform, and network. Check replacement resources against the requirements and the release’s supported deployment configuration.

Keep any surviving original machines isolated from the replacement deployment. Recovery writes the selected target disks. Verify the full disk identity and destructive confirmation before submitting.

Run Recovery

  1. In Settings > Bundles, upload the full backup for use as a recovery bundle. Retrieve or upload the matching release bundle through bundle management. Stored recovery bundles remain until an administrator deletes them.

  2. Open Installation > Recover and select Start the recovery wizard. Resolve an already-open installation or draft before starting another wizard.

  3. Select the matching release. In Recovery bundles, select the stored recovery bundle and provide its Matching artifacts bundle.

  4. Select Load recovery settings. Management validates the input before changing target machines. Confirm the displayed appliance version, cluster name, and captured nodes.

  5. Complete the replacement topology, platform, and network steps. Discover the replacement machines and select their disks as described in the installation procedure.

  6. Review every target and the recovery settings, then confirm and submit the recovery.

  7. Follow the operation through verification and any GitOps finalization. Download and verify the resulting artifact bundle when prompted, and retain it outside Management.

Management keeps the matching artifact upload in memory. Its size limit is 10 MB. Submit within six hours of loading the recovery settings. After a reload or expiry, select the stored recovery bundle again and supply the matching artifacts; the stored backup remains available.

Screenshot pending: Matching recovery inputs

Capture the selected recovery bundle, matching artifacts input and loaded appliance identity before target changes. Use demonstration identities and keep credentials hidden.

Verify the Restored Appliance

Follow the post-installation checks. Confirm the restored release and appliance identity, application access, database-backed records expected at the backup’s capture time, and HSM connectivity where configured. Check that scheduled backups resume and that a new completed full backup becomes available.

Expect excluded telemetry history and Grafana UI-created state to be absent. External HSM objects are not recreated from an appliance backup.

Troubleshooting stopped Recovery

Record the current stage and exact error. Retain the original full backup, artifacts, and matching release bundle. Correct missing connectivity or invalid inputs before another attempt. Cancellation does not undo writes already made to target disks. Collect diagnostics and contact support if the recovery cannot complete.