Configuration backup and restore
Create immutable configuration revisions, restore safely, and schedule retention-aware backups in AIFW.
AIFW can create immutable configuration revisions before a rule or settings change. Backups cover configuration only. Logs, history, tasks, and credentials are never included, and secrets are represented by placeholders rather than stored values.
Open Backup & Restore#
Open AI Firewall -> Agent Config -> Backup & Restore.
Take a backup#
Use Take a backup to create a revision before a change.
| Field | Meaning |
|---|---|
| Note | Optional explanation, such as the change the revision protects. |
| Keep newest | Optional trimming limit. 0 keeps all revisions created by this action. |
| Back up now | Creates the immutable configuration revision. |
Each revision records when it was created, who or what created it, the application version, and its integrity status.
Automatic backups#
Use Automatic backups to schedule revisions:
| Setting | Default | Allowed range |
|---|---|---|
| Enabled | Off | Turn scheduled backups on or off. |
| Every (minutes) | Deployment setting | 5 to 10080 minutes. |
| Keep newest | Deployment setting | 1 to 200 revisions. |
Automatic revisions are attributed to the scheduler. Older revisions are trimmed after the retention limit is applied.
Restore a revision#
Review the revision list before restoring. Verify the integrity status and note the revision you intend to use. Restore is a configuration operation, so review the resulting settings and rules after the application reloads them.
Do not treat a configuration backup as a disaster-recovery database backup. Preserve PostgreSQL data and deployment assets using your normal infrastructure process.
Security boundary#
- Credentials and secret values are not included.
- Transaction logs, audit history, tasks, and other runtime history are not included.
- Revisions are immutable and integrity-checked.
- Backup and restore activity should be reviewed in the audit trail.
Related documentation#
- Settings reference
- Prompt and response guardrails
- Audit logs & export
- Compliance module administration