quraba / quraba-backup
Backup and disaster-recovery foundation for single Laravel applications on VPS and shared hosting (Backblaze B2 + Restic).
Requires
- php: ^8.5
- ext-json: *
- guzzlehttp/guzzle: ^7.9 || ^8.0
- illuminate/console: ^13.0
- illuminate/contracts: ^13.0
- illuminate/database: ^13.0
- illuminate/filesystem: ^13.0
- illuminate/http: ^13.0
- illuminate/support: ^13.0
- league/flysystem-aws-s3-v3: ^3.35
- spatie/laravel-backup: ^10.3
- symfony/process: ^7.4|^8.0
Requires (Dev)
- filament/filament: ~5.0
- larastan/larastan: ^3.0
- laravel/pint: ^1.20
- orchestra/testbench: ^11.0
- phpunit/phpunit: ^12.0
Suggests
- ext-bz2: Lets quraba:backup:install-restic decompress the official Restic release without an external bzip2 binary.
- ext-pdo_mysql: Required for MySQL/MariaDB application databases.
- ext-posix: Improves permission diagnostics in quraba:backup:doctor.
- filament/filament: Required only for the optional Filament 5 admin panel.
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-02 10:55:41 UTC
README
quraba/quraba-backup — backup and disaster-recovery package for single Laravel applications on Linux
VPS and cPanel shared hosting. Offsite storage is the customer's own Backblaze B2 bucket (S3 API);
Spatie Laravel Backup builds the encrypted database + .env archive and Restic takes media snapshots.
Status: backups, health, retention, restore and disaster recovery. The package creates verified encrypted application archives, verified Restic media snapshots and coordinated Recovery Points with immutable remote manifests; reports recovery health; applies exact retention; and restores one exact run — as a dry run by default, live only with
--force --confirm=RESTORE_APPLICATION, journaled, behind a verified safety backup and proven quiescence — including onto a clean host. An optional Filament 5 panel provides health, run history and read-only recovery tools.
Requirements
- PHP 8.5+, Laravel 13
- Linux (x86_64; arm64 is structurally supported) — VPS or shared hosting
proc_openenabled for PHP CLI, writable private storage, outbound HTTPS, one cron entry- MySQL or MariaDB with
mariadb-dump/mysqldump(andmariadb/mysql) client tools - PHP
zipwith AES-256 support (checked by the doctor) - No root, sudo, Docker, systemd, Supervisor, Redis or queue worker
Quick start
composer require quraba/quraba-backup php artisan migrate php artisan quraba:backup:identity --generate # add the printed QURABA_BACKUP_APP_ID to .env, once php artisan quraba:backup:install-restic # pinned Restic 0.19.1, SHA-256 verified, no root # configure B2, archive password and Restic password file (docs/configuration.md) php artisan quraba:backup:restic:init # explicit; binds this application to the repository php artisan quraba:backup:doctor # fix every FAIL php artisan quraba:backup:run # first Recovery Point
Then add one cron entry: * * * * * cd /path/to/app && php artisan schedule:run >> /dev/null 2>&1.
Commands
All package commands use the quraba:backup:* namespace (bare backup:* belongs to Spatie).
| Command | Purpose |
|---|---|
quraba:backup:run [--profile=database|media|recovery] [--json] |
Create a verified backup (default recovery); exit 0 completed, 2 partial, 3 indeterminate, 1 failed |
quraba:backup:pending [--json] |
Process one authorized pending panel request under the operation lock; scheduled when enabled |
quraba:backup:list [--limit=] [--profile=] [--json] |
Browse the local catalog |
quraba:backup:reconcile [--dry-run] [--json] |
Resolve interrupted runs from physical evidence |
quraba:backup:health [--json] |
Recovery health: healthy, degraded, failed or unknown; optional transition alerts |
quraba:backup:retention [--execute] [--json] |
Plan (default) or apply exact retention |
quraba:backup:restic:check [--read-data] [--json] |
Audited Restic repository check |
quraba:backup:restic:prune [--execute] [--json] |
Restic prune (dry run by default, never scheduled) |
quraba:backup:discover --remote [--json] |
List backups from remote manifests and expiry records (no local catalog needed) |
quraba:backup:restore --run=UUID [--profile=database|media|full] [--json] |
Dry run of one exact run: reconstruct and validate privately |
quraba:backup:restore --run=UUID … --force --confirm=RESTORE_APPLICATION [--clean-host] |
Live restore; exit 0 completed, 1 failed (nothing changed), 3 indeterminate |
quraba:backup:restore-reconcile [--restore=UUID] [--abandon --confirm=ABANDON_RESTORE] [--cleanup-parked] |
List restore journals; decide an interrupted live restore from evidence |
quraba:backup:bootstrap-env --run=UUID [--target=PATH] |
Clean host: recover the archived .env only |
quraba:backup:catalog:rebuild [--apply] [--json] |
Rebuild the local catalog from remote truth (plan by default) |
quraba:backup:recovery-checklist [--remote] [--json] |
Which recovery materials are configured (never prints a secret) |
quraba:backup:doctor [--json] |
Environment and backup readiness (PASS/WARN/FAIL/SKIP) |
quraba:backup:identity [--generate] [--json] |
Show the stable application identity |
quraba:backup:install-restic [--force] |
Install the pinned Restic release |
quraba:backup:restic:init [--force] |
Explicitly initialize and bind the Restic repository |
quraba:backup:restic:health [--json] |
Cheap Restic health (not restic check) |
quraba:backup:workspace:list [--older-than=H] [--json] |
List operation workspaces |
quraba:backup:workspace:cleanup [--older-than=H] [--execute] [--restore=UUID] [--json] |
Plan (default) or remove abandoned workspaces; retained restore evidence requires exact resolved restore UUID |
Documentation
- Installation
- Configuration (B2, passwords, media roots, consistency, schedules)
- Backups: profiles, Recovery Points, verification, reconciliation, scheduling
- Health, retention, maintenance, discovery, restore dry run, catalog rebuild
- Restore: the live gate, the journal, failure and reconciliation
- Disaster recovery onto a clean host (runbook)
- Shared hosting / cPanel
- Doctor & health
- Security model
- Troubleshooting
- Optional notifications
- Optional Filament 5 panel
- Upgrading
- Architecture: specification, master plan
Development
composer check # composer validate, pint --test, phpstan (max), phpunit
Opt-in integration suites: QURABA_BACKUP_TEST_RESTIC_BINARY (real pinned Restic, local repositories),
QURABA_BACKUP_TEST_MYSQL_HOST (+ _PORT, _USERNAME, _PASSWORD; creates and drops its own
quraba_backup_it_* databases and quraba_it_* accounts — including the end-to-end live restore and
clean-host tests) and QURABA_BACKUP_TEST_B2=1 plus the QURABA_BACKUP_TEST_B2_* variables for a
disposable test bucket. In CI, real B2 runs only through the manual run_b2 input, never on normal push
or pull-request runs.