Skip to main content
Cedros

Restoring a site from a backup

Plan a recovery, choose a restore point, follow the supported restore process, and check your site before resuming normal use.

Restoring a backup replaces the selected site data with an earlier version. Changes made after that restore point can be lost. Plan the recovery with your site operator, preserve anything you still need, and verify the restored site before reopening it to visitors.

Some deployments allow restoration from Tools → Backups. Others require your operator to perform recovery separately. Confirm which method your site supports before following the on-page restore steps below.

Prepare for recovery

Agree on the restore point and the data you need to recover: the site database, Vault, native mail, or a combination. Check the backup's creation time and contents in Available backups. A recent database backup does not necessarily include Vault or mail data.

If the current site is accessible, preserve important changes and, where practical, create and download a fresh backup before replacing anything. Keep the older restore point you intend to use as well. Save the complete bundle and its recovery phrase somewhere independent of the site.

Arrange a maintenance window with your operator. Restoring can interrupt access and background work. If Vault or native mail will be restored, their services must be stopped before their data is replaced. Checking a confirmation box does not stop a service for you.

You need backup operations access for uploads and restores. Ask your administrator to check your feature access if these controls are unavailable. First-time backup setup also requires settings access; see Setting up automatic backups.

Confirm the recovery method

Ask your operator to confirm that the selected backup is compatible with the recovery method and target site.

Restore from Backups. Use the steps below only when restoration through the admin page is enabled for your deployment and your operator has confirmed the selected data can be restored that way.

Operator-led recovery. Use this route if the site is unavailable, on-page restoration is disabled, or the backup requires a separate recovery procedure. Give your operator the site name, intended restore point, required data, and the location of the backup. Arrange secure access to the recovery phrase; do not paste it into a support message or assistant conversation.

Vault recovery. PostgreSQL-backed Vault backups require a separate operator-led procedure with the matching keys and files. A Vault checkbox in the form does not establish that the archive supports on-page restoration. Do not omit required Vault data merely to get past an error.

Older database backups or backups reported as inconsistent may also require operator-led recovery. Keep the original bundle unchanged so your operator can assess it.

Upload a saved backup if needed

Skip this section if the intended restore point is already in Available backups.

  1. Under Upload an existing backup, select Choose backup.
  2. Select Choose file, or drop the complete Cedros .zip bundle into the file area. Check the displayed filename.
  3. Select Upload backup and wait for Backup uploaded and ready to restore from the list above.
  4. Find the uploaded entry in Available backups and check its creation time and contents.

Uploading registers the backup; it does not restore the site or prove the backup can be decrypted. Keep the phrase used when that backup was created, including for a bundle from another deployment.

Restore through the Backups page

Continue only after the recovery method, maintenance window, and service shutdowns have been agreed with your operator.

  1. In Available backups, open the chosen row's actions menu and select Restore backup.
  2. In the restore form, check Backup point and the bundle filename. Confirm this is the intended restore point before selecting any data.
  3. Under Restore which artifacts?, review the selected items and choose the data to replace. At least one item is required. An item marked target directory not configured needs your operator to prepare its destination first.
  4. If you selected Vault or native mail, confirm the relevant service has actually stopped, then select I have stopped the Cedros Vault service. or I have stopped the native mail service. as applicable.
  5. Leave Backup encryption phrase override (optional) blank if this deployment already stores the needed phrase. Otherwise, enter the backup's phrase directly in that password field. It is used for this restore; it does not change the phrase used for new backups.
  6. Type RESTORE in Type RESTORE to confirm, then select Restore backup.
  7. Review the Restore this backup? dialog, including the selected backup and data. Select Restore backup only when ready to replace that data, or Cancel to stop before submission.

Cedros tries its stored current and historical phrases as well as any phrase you provide. A phrase from a different backup may not decrypt this one.

The restore replaces selected data; it does not merge newer records into the older copy. Use Cancel before the final confirmation if the restore point or selection is wrong.

Follow the restore to completion

Restore queued means the request was accepted. Restore in progress means work is still running. Neither means the site has finished recovering.

The status identifies the backup and the current stage, such as validating files, restoring the database, restoring Vault or native mail, or refreshing the running site's state. Let the operation finish before starting another restore.

If the page disconnects or the request times out, check the status again when access returns, or ask your operator to check it. A lost connection does not establish whether the restore stopped, completed, or changed data.

Wait for Restore completed. If the status recommends restarting the server, have your operator do that before relying on restored extension behavior. Restart any stopped services only after the operator confirms their data is ready.

Check the recovered site

Before resuming normal use, confirm that the site opens and you can sign in. Check representative pages, settings, and records against the chosen restore point.

If Vault or native mail was recovered, verify those services separately. Check that the expected Vault data and mailboxes are accessible. Check the integrations and background work your site depends on before allowing them to resume.

Review the backup schedule and storage settings after recovery, then confirm a new backup completes. Keep the recovery files until you have verified the result and agreed what to retain.

Resolve blocked or interrupted restores

Restoration is disabled. Contact your site operator for recovery. Seeing the restore form does not guarantee that the deployment permits it.

No phrase can decrypt the backup. Check that you have the phrase for that restore point. Use the optional override for a phrase not stored on the deployment. If you cannot locate it, stop and ask your operator about available recovery options.

Vault or native mail cannot be selected. The backup must contain that data and the destination must be configured. Ask your operator to prepare the destination and confirm the supported recovery method.

The backup is rejected as incomplete, inconsistent, or incompatible. Preserve the original bundle and share the error with your operator. Do not edit its manifest or remove required files to make it pass validation.

Restore failed or Restore interrupted. Record the restore point, stage, and error. Data may already have changed. If the status says to keep the deployment in maintenance mode, leave it there until your operator verifies or completes recovery. Do not assume an automatic rollback occurred or retry blindly.