Export backup

Download a snapshot of this router's canonical configuration for offline disaster recovery.

{{#ERROR}}
{{ERROR}}
{{/ERROR}} {{#FLASH}}
{{FLASH}}
{{/FLASH}} {{#APPLY_JOB}}
Generating backup export…

Working… this page updates automatically.

{{/APPLY_JOB}} {{#EXPORT_DOWNLOAD}}
Backup ready

The signed bundle was generated and staged on the router. Download it now — the staged copy is removed once it is downloaded.

{{/EXPORT_DOWNLOAD}}

Download backup

Full configuration bundle for this router

Format .ogma archive
Contents manifest.yaml + per-domain YAML
Scope Up to 15 config domains

Generates a snapshot of this router's canonical configuration with per-fragment SHA-256 integrity hashes. Store offline for disaster recovery or lab migration.

Included — up to 15 config domains

interfaces & addressing (net), kernel network sysctls — forwarding, ARP & HA tuning (sysctl), static routes (routes), gateway groups (gateways), firewall / pf (pf), DNS resolver (dns), DHCP server (dhcp), dynamic routing — OSPF & BGP (routing), static ARP (arp), NTP / time (time), TLS certificate intent (cert), system hostname (identity), IPsec tunnels (ipsec), remote syslog (remotelog), and email alerts (alerts).

Domains you have not configured are simply omitted — the bundle's manifest.yaml lists exactly which are present.

Not included — a restore does not recover these

User accounts & access control — the auth database (accounts, RBAC roles, MFA/TOTP seeds, recovery codes).

Secrets store — WireGuard keys, IPsec PSK/EAP, the IPsec CA passphrase, OSPF and BGP authentication keys, CARP passphrase, PPPoE authkey, TLS private keys. OSPF and BGP keys are the exception that bites: they are read during a restore, and one missing from the store aborts it and rolls back every change already made.

The backup anchor.backup-anchor.{sec,pub} is the per-deployment signing key, not configuration, so it is in no bundle. Replacement hardware cannot verify this bundle's signature without it; keep it (and re-take custody after every upgrade).

The deployment root key.cap-master roots capability tokens and audit integrity (and verifies any pre-upgrade backup). Also in no bundle.

Back these up separately and keep them with your DR recovery runbook.

Encrypts the signed bundle at rest with ChaCha20-Poly1305 (key derived from this passphrase). Leave blank to download a signed but unencrypted bundle. The passphrase is never stored — if it is lost the bundle cannot be restored.