Backups and undelete¶
Two different things, for two different accidents:
- Undelete keeps what people delete, for a while, so it can be brought back. It protects against mistakes. It doesn't protect against losing the server, because the copies live on it.
- Export and import copy a whole server's data out and back in. That is the backup, and the way to move a server.
Neither replaces the other.
Undelete¶
Off in a new install. It is switched on by a length of time, under Settings › Storage › Retention › Archiving, or on the retention summary:
| Field | What it keeps |
|---|---|
| Archived Items | Mail, files, calendar events, contacts and Sieve scripts, when they are deleted for good |
| Archived Accounts | Whole accounts, when an administrator deletes one |
A change takes effect at once. Shortening the time later doesn't cut short anything already kept: each item keeps the deadline it was given.
What counts as deleted¶
Only removal for good. Moving mail to Trash keeps nothing, because the mail still exists; emptying Trash, or Trash emptying itself on its schedule, does. So does deleting from any client or protocol: IMAP, POP3, JMAP, WebDAV, CalDAV, CardDAV, ManageSieve, or a filter that removes a message.
Mail that was refused or discarded before it was ever delivered was never stored, and can't be brought back.
Archived copies don't count toward anyone's quota, so deleting mail to free space still works. They do take space on the server.
Bringing something back¶
In the console, Account › Archived Items lists what can be restored, with the account it came from, when it was deleted, and until when it's kept. An administrator sees the accounts they manage, and can filter by account. Set an item's status to Request item restoration to restore it.
A restored item goes back where it was:
- Mail goes back to the folders it was in, read or unread and flagged as it was, in its thread. If those folders are gone, it goes to the Inbox.
- Files go back to their folder, or the top level if it's gone, with
(restored)added if the name is taken. - Events and contacts go back to their calendar or address book, or the default one.
- Sieve scripts come back switched off, so a restored filter never starts running by itself.
A restore counts against quota, and is refused if it would go over. The item stays archived, and the task says why.
People can also delete their own archived items early. Undelete protects against accidents, not against the person whose data it is, so it isn't a legal hold.
Deleted accounts¶
With Archived Accounts set, deleting an account keeps all of it, mail, files, calendars, contacts and settings, for that long. While it's kept, it can't sign in or receive mail, and its name and addresses stay reserved so nobody else can take them.
Restoring a deleted account has no screen yet. It is done over the API, with
inbuxa:DeletedAccount/set under the urn:inbuxa:jmap capability, which
also lists the accounts being kept and when each goes for good.
How long things are kept¶
Every page under Settings › Storage › Retention opens with every "how long is this kept" setting as one sentence, grouped three ways:
- In people's mailboxes: emptying Trash and Junk, clearing handled calendar invitations, forgetting "shared with you" notices, and forgetting the sending status apps show for sent mail (the sent message itself stays).
- Getting deleted things back: how long deleted mail, contacts and events, and deleted accounts, can be brought back.
- The server's own records: delivery history, which Emails › History and "why was this rejected?" read from; the charts' history; DMARC and TLS reports from other servers; and old log files, which hold IP and email addresses.
Each sentence can be changed where it stands: set a time in days or hours, or turn it off, or keep forever, whichever that setting allows. Each saves on its own. Mail under a legal hold is kept whatever these say: deleting it archives it, and it doesn't expire while held.
The schedules and every other setting are in the form under it.
Export and import¶
The server binary exports and imports its own data:
inbuxa --config /etc/inbuxa/config.json --export /var/backups/inbuxa
inbuxa --config /etc/inbuxa/config.json --import /var/backups/inbuxa
An export holds everything in the data store and the blob store: accounts, mail, settings, the queue, reports, telemetry, tasks, archived items, the spam filter's training samples and its trained model. It leaves out short-lived state, such as rate limits, locks and greylisting, and the full-text search index, which belongs to one search backend.
Importing into an empty store queues the search index to be rebuilt when the server next starts. Until that finishes, searches find less than they should.
To export only some of it, set EXPORT_TYPES to a comma-separated list of
data, registry, blob, changelog, queue, report, telemetry and
tasks.
Stop the server for a consistent copy
An export taken while mail is arriving can catch the store halfway through a change. Stop the server, export, and start it again. With the built-in RocksDB store, the server has to be stopped anyway, because only one process can open it.
An export is also how a server moves: export on the old machine, and import on the new one into an empty store.