Server
A Linux host the platform reaches over SSH. Its host key is pinned when you add it.
Server
A Linux host the platform reaches over SSH. Its host key is pinned when you add it.
SSH credential
The user name plus private key or password used to log in to servers. Stored encrypted, never shown again.
Database instance
A database engine on a server or in a container, registered so plans can dump it natively.
Source
One thing a plan backs up: a folder, a volume, a container, a compose project, a database or a command.
Environment
A group such as Production or Staging that carries rules - encryption required, restore approval.
Plan
A reusable backup definition: sources, output format, encryption, storage, retention, schedules, notifications.
Schedule
When a plan runs - a cron expression or a simple builder, with an optional time window.
Run
One execution of a plan, with its stages, log and results.
Hook
A script run before or after a capture - stop an app, flush a cache, start it again.
Preflight
Checks before anything is written: connection, host key, tools, free space, target health, policy.
Artifact
One stored backup file produced by a run, e.g. orders.dump.zst.bmenc, with its checksum.
Manifest
A signed _manifest.json written last in each run folder. The catalog can be rebuilt from it.
Storage target
Where artifacts go: an S3-compatible bucket or a local or NAS folder.
Retention policy
How long artifacts are kept: keep last N, daily, weekly, monthly, yearly (GFS).
Object Lock
S3 write-once protection: nobody, not even an administrator, can delete a locked artifact early.
Restore point
A backup you can restore from, listed under Restore › Restore points.
Drill
A scheduled test restore into a sandbox that proves a backup works and measures how long it takes.
Recovery kit
Offline material that decrypts your backups even if the platform itself is gone.
bmctl
The stand-alone recovery tool: inspect, verify, decrypt and extract artifacts without the platform.
| Term | Meaning |
|---|---|
| RPO | Recovery point objective: the most data you can afford to lose. A plan with RPO 24 h must succeed at least once a day, or the dashboard flags a breach. |
| RTO | Recovery time objective: how long a restore may take. Drills measure the real figure. |
| 3-2-1 | Three copies, on two kinds of media, one off-site. In the platform: the primary target plus a second-copy target. |
| GFS | Grandfather-father-son retention: keep some daily, weekly, monthly and yearly backups. |
| Step-up | A fresh second-factor code asked for right before a sensitive action. |
| Scope | The environments, servers or plans a scoped role may act on. |