Server and client backup
Restow backs up Linux and macOS servers and client machines with a small agent that drives restic, into your own Restow instance. It is part of the Community edition, so every edition has it, and it is available since 0.1.0 (beta). The backups are file-level, stored deduplicated and encrypted, and they are checked the same way mailbox backups are: a backup that has never been read back is not counted as proven.
What it does
The agent is a small Go program for Linux (systemd, x86_64 and aarch64) and macOS 13 or newer (Intel and Apple Silicon). It backs up the folders you choose with restic 0.19.1 into a repository on your Restow instance, deduplicated, compressed and encrypted. It is file-level on purpose: no disk images and no bare-metal restore. Restoring a whole machine means reinstalling the operating system and restoring the files.
How a machine is added
In the Restow web interface you add a new server or a new client. Restow shows one command with a one-time token; the token is valid for 24 hours and works once. You copy the command and run it with sudo on the machine. The install script is served by your own instance: it downloads the agent and restic from that instance, checks the SHA-256 of both binaries before anything is installed, sets up the service (systemd or launchd), enrolls the machine and starts it. Running it again repairs or upgrades in place. Because the token reaches the script as an environment variable of sudo, it is briefly visible in that machine's process list; it is single-use and expires.
The agent opens outbound HTTPS connections to your Restow instance and to nothing else, and it opens no port on the machine. On macOS you grant the agent Full Disk Access; without it, protected folders are skipped and the backup is reported as partial, with the reason in the run log.
Why the agent cannot destroy its own backups
Append-only is enforced by your Restow instance, not left to the agent's good behavior. The agent writes to a restic repository that the instance exposes in append-only mode: it can add backups but cannot delete or overwrite them. Restow's own end-to-end tests check that forget, prune, delete and overwrite with the agent's access are refused and the stored bytes stay unchanged. Retention, pruning and integrity checks run only on the Restow server.
The agent never holds credentials for the storage target, such as S3 keys or mount paths. It knows only its own agent secret and the password of its own repository. Every machine has one repository and one random password; the server keeps that password encrypted with the tenant key, so an administrator can still restore when the machine itself is gone.
Restore
A restore on the machine always goes into a new folder and never over existing files: the target must not exist or must be empty, otherwise the run fails and nothing is touched. The alternative is to browse a backup in the Restow interface and download files or folders as a ZIP. Browsing, downloads and restore requests are written to the audit log. The repository is a plain restic repository, so a restore without Restow is possible with the repository password. An administrator can have Restow show that password; keep a copy in a password manager, because without the Restow database and its master key the password cannot be reconstructed. The general restore rules are on the restore page.
Proven restorable
After every backup the agent records the SHA-256 of up to 20 random files. Later the server restores those files from the snapshot and compares the hashes; the result is green only when they match. That result feeds Recovery Readiness, the same status used for mailboxes, so a machine shows as proven only when its latest backup was read back. More on the approach is on the verification page.
Every week the server also checks each repository, reading one twentieth of the data per run, so the whole repository is read over roughly five months. Retention runs on the server as well; the default keeps 30 daily, 12 weekly and 12 monthly backups and can be changed per machine.
Alerts
Restow raises an alert, through the same channels as every other job (notification bell, email, webhook), when:
- a server has been silent: by default no contact for more than 2 hours;
- a client has had no good backup for a while: by default 7 days, because a laptop is off at night;
- a backup fails, or a restore on a machine fails;
- a restore test fails, or a repository check finds damage.
Profiles and hooks
The Server profile backs up daily (the default time is 22:00). The Client profile backs up when the machine can reach your Restow instance, at most once every 4 hours, and can be limited in bandwidth and set to run only on AC power (power detection is best effort). Optional pre and post hooks run commands around a backup, for example a database dump. Hooks run as root and are an administrator function: whoever can change a machine's configuration in Restow can run commands as root on that machine, so treat that access accordingly.
Stated limits, not hidden ones
- No Windows agent yet. It is planned, see the roadmap.
- No LVM, ZFS or btrfs snapshots yet, and no APFS snapshots on macOS. Consistency comes from the optional hooks (a database dump, for example); files that change while they are read can end up inconsistent in the snapshot.
- No mTLS yet: each agent authenticates with its own secret over HTTPS. A stolen secret does not allow deleting anything.
- No image or bare-metal backups, by design: the backup is file-based.
- The agent runs as root, because it has to read every file it backs up.
- The agent checks for updates every 6 hours, and verifies each one by SHA-256. The checksum comes from your own instance, so it protects against damaged downloads, not against a compromised instance, and agent updates are not signed.
- This is a beta (0.1.0). Run it beside your existing backups until you have restored from it yourself.
Documentation
The administrator guide has the overview and the install steps, including the macOS permission.
Frequently asked
Does the agent need an inbound port on the machine?
No. The agent only opens outbound HTTPS connections to your own Restow instance and to nothing else, and it opens no listening port. Your instance never connects to the machine: tasks such as a restore request travel in the answer to the agent's regular check-in.
Can the agent delete or change its own backups?
No. Your Restow instance enforces append-only on the server side: the agent can add backups but cannot delete or overwrite them, and it never calls forget or prune. Retention and pruning run only on the Restow server. The agent also holds no credentials for the storage target, only its own agent secret and the password of its own repository. One limit is stated plainly: there is no client certificate yet, so a stolen agent secret (root on the machine) would allow writing new backups to that machine's repository and reading it, but not deleting anything.
Does Restow back up Windows machines?
Not yet. The agent ships for Linux and macOS in 0.1.0 (beta). A Windows agent is planned and listed on the roadmap; nothing Windows-specific is part of this release, and the server refuses to enroll a Windows machine.
Does server and client backup cost extra?
It is part of the Community edition and therefore available in every edition. For what the editions cost, see the pricing page.