Files
sencho/docs/features/fleet-backups.mdx
T
Anso 32a7d53b2b feat: RBAC, atomic deployments, fleet backups, and licensing (Pro) (#185)
* feat: add RBAC viewer accounts, atomic deployments, and fleet-wide backups (Pro)

Introduces three Pro-tier features:

- RBAC: Multi-user system with admin/viewer roles, user management UI,
  automatic migration from single-admin credentials, viewer restrictions
  across the entire UI (read-only editor, hidden action buttons)

- Atomic Deployments: Pre-deploy file backup to .sencho-backup/, automatic
  rollback on health probe failure, manual rollback button, health probes
  added to stack updates, webhook-triggered deploys use atomic rollback

- Fleet-Wide Backups: Point-in-time snapshots of compose files across all
  nodes (local + remote), stored centrally in SQLite, per-stack restore
  with optional redeploy, graceful handling of offline nodes

* fix(settings): use correct ProGate prop name in UsersSection

* fix(settings): remove unused isPro prop from UsersSection

* fix(auth): fetch user info after login and setup so isAdmin is set correctly

* feat(pricing): revise pricing strategy and enforce variant-based seat limits

Raise Personal Pro from $49/yr to $69/yr with 3 viewer seats (up from 1).
Add $15/mo billing option for Team Pro. Mark lifetime pricing as a
90-day early-adopter offer. Store Lemon Squeezy variant_name on
activation/validation and enforce seat limits server-side per variant.

* feat(licensing): add Lemon Squeezy checkout, webhook, and billing portal integration

Server-side checkout URL generation (POST /api/checkout) with admin email
pre-fill and instance_id custom data. HMAC-SHA256 verified webhook endpoint
(POST /api/webhooks/lemonsqueezy) handling order, subscription, and payment
lifecycle events for automatic license activation. Customer billing portal
link stored from webhook events and exposed via GET /api/billing/portal.
In-app checkout buttons in Settings with manual license key fallback.

* fix(licensing): exempt Lemon Squeezy webhook from auth middleware

The catch-all auth middleware on /api/* was blocking the public webhook
endpoint. Added /webhooks/lemonsqueezy to the exemption list alongside
/auth/* and /webhooks/:id/trigger.

* feat(pricing): update pricing to final live rates

Personal Pro: $7.99/month, $69.99/year, $249 lifetime.
Team Pro: $49.99/month, $499.99/year, $1,499 lifetime.
Added personal_monthly checkout variant across backend, frontend, and website.

* refactor(licensing): remove server-side checkout/webhook for self-hosted model

Sencho is self-hosted — each user runs their own instance, so there is
no central server to receive webhooks or hold the store API key. Replaced
in-app checkout buttons with a "View Pricing" redirect to sencho.io and
kept manual license key activation as the primary flow.

- Delete LemonSqueezyService (checkout, webhook, HMAC verification)
- Remove POST /api/checkout, GET /api/billing/portal, POST /api/webhooks/lemonsqueezy
- Remove raw body parser and auth exemption for webhook route
- Remove all LEMONSQUEEZY_* env vars from .env.example
- Replace checkout buttons in SettingsModal with single "View Pricing" button
- Simplify LicenseContext checkout to open sencho.io pricing page
- Update licensing docs to reflect website-based purchase flow

* chore: normalize em-dashes to hyphens across codebase (linter)

* chore: remove accidentally tracked directories from index
2026-03-26 21:58:24 -04:00

85 lines
3.2 KiB
Plaintext

---
title: Fleet-Wide Backups
description: Snapshot compose files across all nodes for disaster recovery and auditing.
---
<Note>
Fleet-Wide Backups require a Sencho Pro license. The feature is available to Pro admins in the Fleet View.
</Note>
Create point-in-time snapshots of every `compose.yaml` and `.env` file across your entire fleet - local and remote nodes alike. Snapshots are stored centrally in Sencho's database and can be browsed, previewed, and restored at any time.
## Creating a snapshot
1. Navigate to **Fleet View** and select the **Snapshots** tab
2. Click **Create Snapshot**
3. Optionally enter a description (e.g. "Before v2 migration")
4. Click **Create** - Sencho captures files from every reachable node
During creation, Sencho connects to each node in parallel:
- **Local nodes** - reads files directly from the compose directory
- **Remote nodes** - fetches files via the Distributed API proxy using the node's API token
If a remote node is offline or unreachable, it is **skipped gracefully**. The snapshot is still created with data from all reachable nodes, and skipped nodes are recorded with the reason for the failure.
## Browsing snapshots
The snapshot list shows:
- **Date** - when the snapshot was taken
- **Description** - your optional label
- **Scope** - how many nodes and stacks were captured
- **Warnings** - an indicator if any nodes were skipped
Click **View** to open the detail view, which presents a collapsible tree:
```
Node A (local)
├── traefik/
│ ├── compose.yaml
│ └── .env
└── postgres/
└── compose.yaml
Node B (remote)
└── grafana/
├── compose.yaml
└── .env
```
Expand any file to preview its contents inline.
## Restoring from a snapshot
Admins can restore individual stacks from any snapshot:
1. Open a snapshot's detail view
2. Find the stack you want to restore
3. Click **Restore**
4. Optionally check **Redeploy stack after restore** to immediately apply the restored configuration
5. Confirm the action
Sencho writes the snapshot's files back to the target node:
- **Local nodes** - files are written directly, and the current files are backed up first (creating a rollback point via the atomic deployment system)
- **Remote nodes** - files are pushed via the Distributed API proxy
<Warning>
Restoring overwrites the current compose and environment files on the target node. If atomic deployments are enabled, the current files are backed up before restoration.
</Warning>
## Deleting snapshots
Admins can delete snapshots from the list view. Deleting a snapshot permanently removes all captured file data from the database. This action cannot be undone.
## Access control
| Action | Admin | Viewer |
|--------|-------|--------|
| View snapshot list | Yes | Yes |
| Browse snapshot contents | Yes | Yes |
| Create snapshot | Yes | No |
| Restore from snapshot | Yes | No |
| Delete snapshot | Yes | No |
## Storage
Snapshots are stored in Sencho's SQLite database. Compose files are typically small (under 10 KB each), so even hundreds of snapshots consume minimal disk space. For very large fleets, consider periodically deleting old snapshots to keep the database lean.