Configuration backup and restore

Create immutable configuration revisions, restore safely, and schedule retention-aware backups in AIFW.

AIFW can create immutable configuration revisions before a rule or settings change. Backups cover configuration only. Logs, history, tasks, and credentials are never included, and secrets are represented by placeholders rather than stored values.

Open Backup & Restore#

Open AI Firewall -> Agent Config -> Backup & Restore.

Take a backup#

Use Take a backup to create a revision before a change.

FieldMeaning
NoteOptional explanation, such as the change the revision protects.
Keep newestOptional trimming limit. 0 keeps all revisions created by this action.
Back up nowCreates the immutable configuration revision.

Each revision records when it was created, who or what created it, the application version, and its integrity status.

Automatic backups#

Use Automatic backups to schedule revisions:

SettingDefaultAllowed range
EnabledOffTurn scheduled backups on or off.
Every (minutes)Deployment setting5 to 10080 minutes.
Keep newestDeployment setting1 to 200 revisions.

Automatic revisions are attributed to the scheduler. Older revisions are trimmed after the retention limit is applied.

Restore a revision#

Review the revision list before restoring. Verify the integrity status and note the revision you intend to use. Restore is a configuration operation, so review the resulting settings and rules after the application reloads them.

Do not treat a configuration backup as a disaster-recovery database backup. Preserve PostgreSQL data and deployment assets using your normal infrastructure process.

Security boundary#

  • Credentials and secret values are not included.
  • Transaction logs, audit history, tasks, and other runtime history are not included.
  • Revisions are immutable and integrity-checked.
  • Backup and restore activity should be reviewed in the audit trail.

Where to go next#