Skip to content

Backup and restore

There are two layers:

  • Configuration versions inside the database: fast, for undoing a change.
  • Backups: whole archives of the router’s state, kept on the router and copied off it.

The configuration lives in /opt/dtvsol/data/dtvsol.db. Keep a named version before any important change:

Terminal window
dtvsol config save "before moving OLT 2"
dtvsol config status # the running configuration against the last version
dtvsol config versions # the list (automatic ones are marked)
dtvsol config diff 14 running # what changed since version 14
dtvsol config show 14 # what version 14 holds

Restore a version:

Terminal window
dtvsol config restore 14 # shows how many files would change
dtvsol config restore 14 --yes

The restore tells you the version it replaced, so you can go back. It takes effect when what uses it runs again, for example:

Terminal window
sudo systemctl restart dtvsol-vlans dtvsol-api isc-dhcp-server radvd

Edit a configuration document safely (checked JSON, a version kept first):

Terminal window
dtvsol config docs # the documents and where each lives
dtvsol config edit plans

dtvsol-backup.timer runs once a day. It:

  1. Saves a configuration version, if the configuration changed.
  2. Archives etc/, data/ (with a consistent copy of the database), the CGNAT mapping logs and the machine id that the OLT passwords are bound to, as /opt/dtvsol/backups/dtvsol-<host>-<stamp>.tar.gz.
  3. Keeps the last 14 archives on the router (readable by root only).
  4. If off-site backup is set up, encrypts a copy to your OpenPGP public key and uploads it over SSH.
Terminal window
dtvsol backup status # last local and off-site backup, errors, next run
dtvsol backup list # the archives on the router
dtvsol backup now # run it now

The off-site copy is encrypted on the router with a public key. The private key never touches the router, so a copy on the backup server cannot be read without it. The copy is removed from the router after the upload.

Set it up in /opt/dtvsol/etc/config.php:

  • backup_gpg_recipient: the fingerprint of your OpenPGP public key. Import the public key into the router’s backup keyring:

    Terminal window
    sudo gpg --homedir /opt/dtvsol/data/backup-gnupg --import backup-public-key.asc
  • backup_remote: user@host[:port] of the backup server. The SSH key (id_ed25519) and known_hosts for it live in /opt/dtvsol/data/backup-ssh. Give that account upload access only.

Then run dtvsol backup now and check dtvsol backup status. Until both settings are present, the status says the off-site copy is not configured.

Download an archive of etc/ and data/ through the API:

Terminal window
dtvsol backup /root/router-1-before-upgrade.tar.gz

Restore an archive that is on the router. Everything is reapplied: DHCP, shaping, CGNAT, anti-spoofing and the rest.

Terminal window
dtvsol restore /root/router-1-before-upgrade.tar.gz

The answer names a configuration version to go back to if the restore was a mistake.

From an off-site copy: decrypt it with your private key on your own machine, copy the archive to the router, and restore it as above.

  1. Install the router software on the new server.
  2. Copy the archive to it and run dtvsol restore <file>.
  3. Enrol the licence for the new machine (dtvsol licence enrol …).
  4. Run dtvsol doctor.

The OLTs’ own configurations are backed up separately, as a history you can diff. See OLTs.

This site was written with the help of AI and checked by our team.