Synopsis #
bastille export produces an archive or ZFS image that bastille import can restore. That artifact is only one part of a jail backup. Host firewall rules, DNS, secrets held outside the jail, and separately mounted datasets need their own records and backups.
The safest general export stops the application and jail first. Bastille can export a running ZFS-backed jail, but a storage snapshot alone does not guarantee application consistency.
Inventory everything the service needs #
Record the jail, release, network, redirections, mounts, packages, and enabled services:
# bastille list all
# bastille rdr web list
# bastille cmd web mount
# bastille cmd web pkg info
# bastille cmd web service -e
Inspect the jail’s fstab and identify every source path outside the managed jail root:
# less /usr/local/bastille/jails/web/fstab
A dataset added through Mount a ZFS dataset in a Bastille jail is not made safe merely because the jail root is exported. Replicate that dataset separately with Snapshot and replicate a ZFS dataset .
Create a consistent export #
Stop or quiesce the application according to its own backup procedure. Then stop and export the jail to a backup filesystem with adequate space. For ZFS-backed Bastille storage:
# bastille stop web
# bastille export --xz web /var/backups/bastille
For UFS-backed Bastille storage, use an archive format instead:
# bastille stop web
# bastille export --txz web /var/backups/bastille
UFS-backed jails must be stopped for export. ZFS-backed jails support live exports, but use that option only after defining the application’s consistency guarantee. The optional path and resulting filename follow the installed Bastille version; confirm the destination printed by the command before restarting the application.
Find the resulting artifact, record its size, and create a checksum:
$ ls -lh /var/backups/bastille
# sha256 /var/backups/bastille/WEB-EXPORT-FILE > /var/backups/bastille/WEB-EXPORT-FILE.sha256
Replace WEB-EXPORT-FILE with the exact generated filename. Do not use a wildcard in an unattended checksum or transfer command.
Restart the original jail and verify its service:
# bastille start web
# bastille service web nginx status
Store the complete recovery set elsewhere #
Copy the following to another failure domain:
- the Bastille export and its checksum;
- replicated application datasets;
- the relevant PF and DNS configuration;
- a record of release, architecture, Bastille version, network mode, and mappings;
- encrypted application secrets and the separate material needed to decrypt them.
An export stored under the same pool and host is a staging artifact, not a disaster-recovery copy.
Prove restoration on an isolated target #
Prepare a compatible FreeBSD host and Bastille storage. Confirm that no jail with the exported name exists, copy the archive locally, calculate its checksum, and compare the complete digest with the protected record from the source host:
# sha256 /var/backups/bastille/WEB-EXPORT-FILE
# bastille list jail
# bastille import /var/backups/bastille/WEB-EXPORT-FILE
Do not use --force to bypass checksum validation as a normal restore step. If the import needs an explicit release, use the RELEASE argument documented by the installed Bastille version.
Keep the restored jail isolated until its address and redirections have been reviewed. Restore separately mounted datasets to a deliberate destination, confirm numeric ownership, and update the jail fstab before starting the application.
Verify the recovered state without immediately publishing it:
# bastille list all
# bastille cmd web freebsd-version
# bastille cmd web pkg check -d
# bastille cmd web service -e
# bastille cmd web mount
Only after the local service works should Publish a Bastille service through PF be applied to the recovered host.
Define retention by recoverability #
Retain at least one known-good export from before an upgrade and multiple independent recovery points for application data. Monitor backup age, transfer failures, destination capacity, and restore-test results. A backup job that exits successfully but has never been imported does not establish recoverability.