Backup and restore
There are two layers:
- Configuration versions inside the database: fast, for undoing a change.
- Backups: whole archives of the router’s state, kept on the router and copied off it.
Configuration versions
Section titled “Configuration versions”The configuration lives in /opt/dtvsol/data/dtvsol.db. Keep a named version before any
important change:
dtvsol config save "before moving OLT 2"dtvsol config status # the running configuration against the last versiondtvsol config versions # the list (automatic ones are marked)dtvsol config diff 14 running # what changed since version 14dtvsol config show 14 # what version 14 holdsRestore a version:
dtvsol config restore 14 # shows how many files would changedtvsol config restore 14 --yesThe restore tells you the version it replaced, so you can go back. It takes effect when what uses it runs again, for example:
sudo systemctl restart dtvsol-vlans dtvsol-api isc-dhcp-server radvdEdit a configuration document safely (checked JSON, a version kept first):
dtvsol config docs # the documents and where each livesdtvsol config edit plansThe daily backup
Section titled “The daily backup”dtvsol-backup.timer runs once a day. It:
- Saves a configuration version, if the configuration changed.
- Archives
etc/,data/(with a consistent copy of the database), the CGNAT mapping logs and the machine id that the OLT passwords are bound to, as/opt/dtvsol/backups/dtvsol-<host>-<stamp>.tar.gz. - Keeps the last 14 archives on the router (readable by root only).
- If off-site backup is set up, encrypts a copy to your OpenPGP public key and uploads it over SSH.
dtvsol backup status # last local and off-site backup, errors, next rundtvsol backup list # the archives on the routerdtvsol backup now # run it nowThe encrypted off-site copy
Section titled “The encrypted off-site copy”The off-site copy is encrypted on the router with a public key. The private key never touches the router, so a copy on the backup server cannot be read without it. The copy is removed from the router after the upload.
Set it up in /opt/dtvsol/etc/config.php:
-
backup_gpg_recipient: the fingerprint of your OpenPGP public key. Import the public key into the router’s backup keyring:Terminal window sudo gpg --homedir /opt/dtvsol/data/backup-gnupg --import backup-public-key.asc -
backup_remote:user@host[:port]of the backup server. The SSH key (id_ed25519) andknown_hostsfor it live in/opt/dtvsol/data/backup-ssh. Give that account upload access only.
Then run dtvsol backup now and check dtvsol backup status. Until both settings are present,
the status says the off-site copy is not configured.
A one-off download
Section titled “A one-off download”Download an archive of etc/ and data/ through the API:
dtvsol backup /root/router-1-before-upgrade.tar.gzRestore an archive
Section titled “Restore an archive”Restore an archive that is on the router. Everything is reapplied: DHCP, shaping, CGNAT, anti-spoofing and the rest.
dtvsol restore /root/router-1-before-upgrade.tar.gzThe answer names a configuration version to go back to if the restore was a mistake.
From an off-site copy: decrypt it with your private key on your own machine, copy the archive to the router, and restore it as above.
Onto a new server
Section titled “Onto a new server”- Install the router software on the new server.
- Copy the archive to it and run
dtvsol restore <file>. - Enrol the licence for the new machine (
dtvsol licence enrol …). - Run
dtvsol doctor.
OLT configuration backups
Section titled “OLT configuration backups”The OLTs’ own configurations are backed up separately, as a history you can diff. See OLTs.