Minu Backup test environment is open for early customers.Talk to us

Minu Backup

Managed backup and recovery for your servers, clusters and databases

One lightweight agent, three engines, immutable storage in two sites and a console your whole team can use.

Architecture

The agent runs in your environment and polls the orchestrator over mutual TLS. Jobs are signed, checked against your local allowlist and executed by the matching engine. Data goes to your own encrypted Kopia repository on S3 storage with Object Lock, and can be copied to a second site.

YOUR ENVIRONMENTServersKubernetesPostgreSQLbackup-agentKopia · Velero · pgBackRestmTLSoutbound onlyMINU CLOUDSNI router · 443Orchestratorsigned jobsKopia servergRPCSite 1S3Site 2S3Object Lock · COMPLIANCE

Features

  • Full and incremental

    Run a one-time full backup or a schedule of incrementals with periodic fulls.

  • Warm and cold tiers

    Keep recent restore points warm for fast recovery and archive the rest to cold storage.

  • Second-site copy

    Replicate restore points to site 2 per policy, on by default.

  • Retention you control

    Set retention per policy; Object Lock keeps data immutable until it expires.

  • Windows VSS

    Consistent snapshots of open files on Windows through Volume Shadow Copy.

  • Deduplication

    Kopia only stores changed blocks, even on full backups.

  • Allowlisted paths

    You decide which paths, namespaces and stanzas can be backed up or restored to.

  • Audit log

    Every login, restore request and policy change is recorded in an append-only log.

Supported engines

EngineWorkloadBackupRestore
KopiaLinux, Windows, file systemsPaths in allowed_sources; full re-hashes all filesSnapshot to an allowed restore target
VeleroKubernetes namespacesNamespaces with TTL, agent runs as a podBy backup name
pgBackRestPostgreSQLFull or incremental by stanzaGuided by a DBA runbook (database must be stopped)

Tested against real attack scenarios

Results from the agent's lab test suite with Kopia 0.23.1.

ScenarioResult
Full backupSnapshot created; size and file count reported
Incremental backupPassed
Restore to an allowed locationIdentical to the source (diff -r)
Back up /etc/shadowRejected by allowlist
Restore into /etc/cron.dRejected by allowlist
Job for another tenantRejected
Job for a disabled engineRejected
Job signed with a forged keyDropped

On the roadmap

  • One-time enrollment tokens with automatic certificate renewal
  • Native Windows service
  • Progress reporting for long jobs
  • Signed, centrally managed agent updates
  • Oracle RMAN and Microsoft SQL Server engines

Ready to protect your data?

Our team will set up your tenant, issue agent certificates and help with your first backup policy.