Backups - What Is Captured, Where It Lands, What Is Not Covered

Backups - What Is Captured, Where It Lands, What Is Not Covered A data-flow diagram generated by Archify. 01 / Sources 02 / Capture 03 / Landing 04 / Second copy LAX containers · 12 CTs · 01 / Sources LAX containers 12 CTs NYC containers · 24 CTs · 01 / Sources NYC containers 24 CTs Production DBs · panel · NetBox · mail · 01 / Sources Production DBs panel · NetBox · mail Game volumes · 1567 servers · 01 / Sources · crown jewels Game volumes 1567 servers crown jewels Proxmox vzdump · LAX sat · NYC sun · 02 / Capture Proxmox vzdump LAX sat · NYC sun DB dumps · logical, nightly · 02 / Capture DB dumps logical, nightly Volume backup · 3 designs · weekly · 02 / Capture · DATA-1 Volume backup 3 designs · weekly DATA-1 LAX local store · /var/lib/vz · keep 3 · 03 / Landing LAX local store /var/lib/vz · keep 3 NYC backuppool1 · ZFS · keep 2 · 03 / Landing NYC backuppool1 ZFS · keep 2 Cross-site copy · daily 06:50 UTC · 04 / Second copy · VIRT-13 Cross-site copy daily 06:50 UTC VIRT-13 mode suspend weekly mode snapshot weekly mysqldump / pg_dump nightly LVM snapshot / raw rsync per volume 12 CT archives 3 restore points 22 CT archives 2 restore points nightly dumps logical tar.zst + ZFS snapshots per node rsync to NYC second copy Legend primary data policy / PII async batch data store data flow

What is protected now

  • • Every running LXC on both clustered hosts, weekly, with 3 (LAX) and 2 (NYC) restore points
  • • All 1567 customer game volumes, weekly, since DATA-1 landed 2026-07-26
  • • node002 restore has been tested end to end: 901 of 901 files byte-identical
  • • LAX archives and CT139 mail dumps now replicate to NYC nightly

Three designs, and the differences are forced

  • • node002 (paid): LVM snapshot for consistency, per-volume tar.zst at rest - only node002 has free extents
  • • node001 (free): no snapshot possible, so it reads live; acceptable only because the free tier is mostly asleep
  • • wings-eu: no LVM at all, raw rsync with --no-D because one volume is a proot sandbox full of device nodes
  • • Shipping compressed archives would defeat rsync's delta algorithm, so the big nodes stay raw + ZFS

What is still owed

  • • Weekly cadence means a seven-day worst-case loss
  • • The replica lands in NYC, inside the same estate - that is cross-site, not offsite
  • • No restore has been proven from node001's or wings-eu's own snapshots, only the mechanism
  • • dracobyte-eu is standalone, so it inherits no cluster vzdump job and its guest images are unprotected
  • • Nothing yet proves wings will boot a restored server