Skip to content

Uninstall and re-enroll

Removing an endpoint has two parts: removing the agent on the machine, and revoking the endpoint in Restow. Backups that already exist stay in your storage target in both cases.

Terminal window
sudo restow-agent uninstall

On a terminal, the command asks for confirmation first. --yes skips the question.

If the agent is broken or already gone, use the install script with --uninstall. The script also removes leftovers when the restow-agent binary is missing.

Terminal window
# Linux
curl -fsSL https://<your instance>/install/linux.sh | sudo sh -s -- --uninstall
# macOS
curl -fsSL https://<your instance>/install/macos.sh | sudo sh -s -- --uninstall
  • the service (the systemd unit or the LaunchDaemon),
  • the stored credentials (/etc/restow-agent/state.json),
  • the working data (/var/lib/restow-agent: cache, temporary files, status, undelivered run reports),
  • the binaries: restow-agent, restow-agent.prev and restic,
  • the log folder /var/log/restow-agent.
Option Effect
--yes Do not ask for confirmation.
--keep-logs Keep the log folder.

The backups stay on the instance, in your storage target. The endpoint also stays in Restow until you revoke it, and until then the daily retention run keeps applying its rules to the backups. A server that has been removed but not revoked is reported as silent after 2 hours.

There is no function yet to delete an endpoint’s repository. Revoking is what you can do today. A revoked endpoint is no longer pruned, so its snapshots stay as they are, and you can still browse them and download files as a ZIP. See Restore.

Open the endpoint, the Settings tab, and the section Remove this machine. Backups that already exist stay restorable in both cases.

Action What happens
Uninstall agent Restow sends an uninstall task. The agent removes itself from the machine with its next contact, and the endpoint is revoked when it does. If the machine is off or offline, this waits until it reports back.
Revoke machine The machine is refused at once: no more backups and no more tasks. The agent stays installed and keeps trying until you uninstall it on the machine. Revoking cannot be undone. To back the machine up again, enroll it anew.

Use Uninstall agent when the machine is reachable. Use Revoke machine when it is lost, stolen or cannot be reached, or when you want to cut it off right now. Both are recorded in the audit log (endpoint.uninstall.requested, endpoint.revoked).

To connect a machine again, for example after it was revoked or its credentials were lost:

  1. In Restow, choose New server or New client and copy the new install command. It contains a new one-time token.
  2. On the machine, enroll again with the new token. The URL is the address of your Restow instance.
Terminal window
sudo RESTOW_TOKEN='<token>' RESTOW_URL='https://<your instance>' restow-agent enroll --force
sudo restow-agent service restart

Alternatively, uninstall the agent first and then run the install command as usual.

Running the install command on a machine that is already enrolled does not enroll it again. The script keeps the existing enrollment.

A new enrollment creates a new endpoint with its own repository. The old endpoint and its backups stay in Restow until you revoke the old endpoint. Its backups do not merge into the new one.

The uninstall removes the agent, but it does not change the privacy settings. Remove the entry yourself:

  1. Open System Settings > Privacy & Security > Full Disk Access.
  2. Select restow-agent and restic if they are still listed and remove them.

On a Mac that is managed through MDM, remove the Privacy Preferences Policy Control profile for the agent in your MDM.