Operator notice
The first step of the setup wizard is a short notice, Your responsibility as operator. It says what kind of tool Restow is: a tool for backup and archiving that writes your data to storage you operate and helps you get it back. It does not run that storage for you, and it cannot make your infrastructure safe. What happens on the hardware and storage layer is yours to take care of. Restow cannot be set up until you have accepted the notice.
What it says
Section titled “What it says”The notice has eight points. In short:
- No replacement for a backup strategy. Follow the 3-2-1 rule: three copies, on two kinds of media, one of them off site or offline, and keep one independent copy that Restow can neither reach nor delete. During the beta, Restow must never be your only backup.
- Hardware and storage. Servers, disks, networks and storage targets, and their redundancy, capacity and health, are your responsibility. If a target fails, fills up or is lost without a separate copy, Restow can neither repair it nor bring the data back.
- Ransomware and deletion. Data is only immutable if the storage makes it immutable. Without WORM or Object Lock on the target, anyone who can reach it, ransomware or a compromised account included, can change or delete backups and archive alike.
- Encryption keys. Your data is encrypted with keys derived from the master key of this installation. Keep that key safe and apart from the data. If it is lost, nobody can decrypt the data.
- Network and access. The security of the server, the network, the accounts and the credentials that reach Restow and its storage is yours: updates, firewall, HTTPS, strong sign-in, and who may access what.
- Test your restores. Do it regularly and check the results, in addition to the verification Restow runs itself.
- Archive and GoBD. The archive features are designed for GoBD-compliant use. Whether your whole procedure is compliant is yours to answer: process documentation, retention periods, access rights, organizational measures and the storage behind the archive. Restow gives no legal or tax advice.
- No warranty. Restow comes under its license terms, without warranty beyond them and beyond what mandatory law requires. The core is AGPL-3.0, the Business and Service Provider modules are under the source-available license in the
eedirectory, and both are part of what you install. See License and editions.
You must accept it first
Section titled “You must accept it first”You tick a box that says you have read the notice and understand that, as operator, you are responsible for these points, and continue with the rest of the wizard.
- The server enforces it. Until the current text is accepted, the server refuses the setup itself (HTTP status 428, “Operator notice not accepted”). The order of the screens is not the protection: a script that skips the first step gets the same refusal.
- What is stored. The version of the text you accepted, the time and the client address are stored in the installation settings, and an entry is written to the audit log (
settings.disclaimer_accepted, with whether it happened in the setup wizard or after sign-in and which version it replaced). Recording runs in every edition, the viewer for the log is a Business feature, see Audit log. - It is a record, not configuration. Accepting the notice does not complete the setup. If you stop after the first step, nothing else is left behind.
Installations that predate the notice
Section titled “Installations that predate the notice”An installation that was set up before the notice existed shows it once, after sign-in, to a provider owner or administrator. It is a dialog that cannot be dismissed: you read it and accept, or you sign out. A technician or a read-only member of the provider team sees a message that an owner or administrator has to accept first. See Team and roles.
Nothing else is held up. Tenant administrators and members never see the dialog, and jobs, integrations and API keys keep running while it waits.
A new text version asks again
Section titled “A new text version asks again”The text has a version, a date, that the server holds. When the wording changes in a way an operator has to acknowledge, the version changes, and every installation is asked again: an acceptance of an older version does not count. An existing installation shows the dialog again the next time a provider owner or administrator opens the web interface. If the text changes while someone is reading it, the page says so and asks for a reload before accepting.
What you should have in place
Section titled “What you should have in place”The notice is not something to tick and forget. A short checklist for what it asks of you:
-
RESTOW_MASTER_KEYis backed up offline, apart from the server, together with your.env. Without it no backup can be read. See Backing up Restow itself. - The storage has redundancy, you watch its free space and health, and for anything that matters there is a second target (a copy target) or a separate backup of it.
- WORM or Object Lock is set up on the storage where you rely on immutability, the archive above all. Restow is only as immutable as the storage under it.
- An independent copy exists that Restow cannot reach or delete, and during the beta Restow runs alongside your existing backups.
- You test restores on a schedule, into a place where a mistake costs nothing, and you read the result. See Backup and restore.
- Access is secured: the server is updated (see Updates), only the ports you need are open, the address is served over HTTPS, sign-in uses passkeys where possible, and roles give people no more than they need.
- Restow itself is backed up: its database,
.envand chunk store, and you know how to restore without a running server. - For the archive: your process documentation, retention periods and access rights are written down, and you have had them checked by whoever is responsible for that in your organization, for example your tax advisor.