API

The contract, written down

This page describes what each call is for. The app in this browser keeps sources and destinations in local storage and does not send these calls. No server here answers them. There is no sign-in.

Overview

Every call below shares one rule. The source is only read. A backup never stops, restarts, pauses, locks out writers, fails over, or writes to it. A failed call leaves the source as it was.

The sections are destinations, sources, backups, restore checks, and restores. Later detail can sit under those same headings.

Destinations

A destination is a bucket you own. Saving one records the provider and a region, a location, or an endpoint URL. The probe writes a tiny object and deletes it. An empty name is rejected before anything is checked. A bucket named denied is refused. The source is not contacted.

A saved destination can be reused by another source. Customer-owned storage is the same monthly fee for every provider. Creating a destination does not start a backup.

Sources

A source is a database, server, service, or computer. Creating one stores how to reach it, including a jump host when you set one. Saving a source does not write to it, stop it, or start a backup.

We will not back this up. A consistent copy would have to pause the writer or step down a primary, and BackupSanity never touches the source.

Backups

A backup reads the source and writes the snapshot to the destination. It never stops, restarts, pauses, locks out writers, fails over, or writes to the source. A failed backup did not change the source. Retention drops older snapshots on the next successful backup, not by touching the live data.

Restore checks

A restore check runs in isolated scratch space and is deleted when it finishes. It does not connect back to the source as a writer. A source is healthy only after a check passes. There is nothing to check until a successful snapshot is still inside retention.

Restores

A restore cannot replace live data. It writes a new copy in a new location and does not connect to the source as a writer. The call takes a snapshot that is still inside retention and a new location. It does not overwrite the source, and it does not offer a way to.