Requirements
- Linux (amd64 or arm64) or Windows (amd64)
- Outbound HTTPS (443) to agent-gw.minu.mn and your kopia-<tenant>.minu.mn host
- Kopia installed for file backups; Velero or pgBackRest for those engines
- A Minu Cloud organization — contact sales to create one
1. Create an agent in the console
Open Console → Agents → Add agent. Name it and pick the engines it should run. The console issues a client certificate and a one-time bundle named after the agent, for example agent-t001-02.tar.gz.
2. Install on Linux
Copy the bundle to the host, extract it and run setup. Setup installs the binary, the certificates and the systemd unit, then starts the service.
scp agent-t001-02.tar.gz admin@app-01:/tmp/
ssh admin@app-01
sudo tar -xzf /tmp/agent-t001-02.tar.gz -C /opt
cd /opt/agent-t001-02
sudo ./setup.sh
sudo systemctl enable --now backup-agent
journalctl -u backup-agent -f3. Install on Windows
Extract the bundle in an elevated PowerShell and register the agent as a service. Enable Volume Shadow Copy once so open files are captured consistently.
tar -xzf agent-t003-01.tar.gz -C C:\minu
cd C:\minu\agent-t003-01
kopia policy set --global --enable-volume-shadow-copy=when-available
nssm install minu-backup-agent C:\minu\agent-t003-01\backup-agent.exe -config C:\minu\agent-t003-01\agent.json
nssm start minu-backup-agent4. Review the agent config
agent.json is yours: the allowlists inside it limit what any job can touch, even if the orchestrator were compromised. Edit allowed_sources and allowed_restore_targets to match your data.
{
"agent_id": "agent-t001-02",
"tenant_id": "t001",
"orchestrator_url": "https://agent-gw.minu.mn",
"tls": {
"ca_file": "/etc/backup-agent/ca.crt",
"cert_file": "/etc/backup-agent/agent.crt",
"key_file": "/etc/backup-agent/agent.key"
},
"job_signing_public_key": "<base64 ed25519>",
"engines": {
"kopia": {
"binary": "/usr/bin/kopia",
"config_file": "/etc/backup-agent/kopia/repository.config",
"password_file": "/etc/backup-agent/kopia/password",
"allowed_sources": ["/var/lib/app", "/etc"],
"allowed_restore_targets": ["/restore"]
},
"pgbackrest": {
"binary": "/usr/bin/pgbackrest",
"allowed_stanzas": ["main"]
}
}
}5. Kubernetes (Velero)
In a cluster the agent runs as a pod next to Velero. List the namespaces it may protect in allowed_namespaces.
"engines": {
"velero": {
"binary": "/usr/local/bin/velero",
"namespace": "velero",
"storage_location": "t001-velero",
"default_ttl": "720h",
"allowed_namespaces": ["app", "payments"]
}
}6. Create a backup policy
In Console → Policies, create a policy. A full_incremental policy needs a cron schedule (Asia/Ulaanbaatar time by default); full_once runs a single full backup on demand.
- backup_mode
- full_once or full_incremental
- schedule_cron
- e.g. 0 2 * * * — every day at 02:00
- retention_days
- How long restore points are kept
- tier
- warm or cold
- copy_to_site2
- Replicate to the second site (default on)
7. Restore
Open Console → Restore points, choose a point and a target path from your allowlist. Kopia and Velero restores run automatically; PostgreSQL restores are done with our DBA team because the database must be stopped.