Download a snapshot of this router's canonical configuration for offline disaster recovery.
Working… this page updates automatically.
The signed bundle was generated and staged on the router. Download it now — the staged copy is removed once it is downloaded.
Full configuration bundle for this router
.ogma archive
Generates a snapshot of this router's canonical configuration with per-fragment SHA-256 integrity hashes. Store offline for disaster recovery or lab migration.
Included — up to 15 config domains
interfaces & addressing (net), kernel network sysctls — forwarding, ARP & HA tuning (sysctl), static routes (routes), gateway groups (gateways), firewall / pf (pf), DNS resolver (dns), DHCP server (dhcp), dynamic routing — OSPF & BGP (routing), static ARP (arp), NTP / time (time), TLS certificate intent (cert), system hostname (identity), IPsec tunnels (ipsec), remote syslog (remotelog), and email alerts (alerts).
Domains you have not configured are simply omitted — the bundle's
manifest.yaml lists exactly which are present.
Not included — a restore does not recover these
User accounts & access control — the auth database (accounts, RBAC roles, MFA/TOTP seeds, recovery codes).
Secrets store — WireGuard keys, IPsec PSK/EAP, the IPsec CA passphrase, OSPF and BGP authentication keys, CARP passphrase, PPPoE authkey, TLS private keys. OSPF and BGP keys are the exception that bites: they are read during a restore, and one missing from the store aborts it and rolls back every change already made.
The backup anchor
— .backup-anchor.{sec,pub} is the per-deployment
signing key, not configuration, so it is in no bundle. Replacement hardware cannot verify
this bundle's signature without it; keep it (and re-take custody after every upgrade).
The deployment root key
— .cap-master roots capability tokens and audit
integrity (and verifies any pre-upgrade backup). Also in no bundle.
Back these up separately and keep them with your DR recovery runbook.