Skip to content

Setup wizard

The first time anyone opens Restow, it runs a one-time setup wizard: “Initial setup: five steps and Restow is ready to run.” It cannot be re-run once it completes: it creates the first administrator, the installation’s settings and an audit entry in a single transaction, and locks itself the moment that transaction commits. If it’s interrupted partway through, nothing of the setup itself is left behind (an accepted operator notice stays recorded), and you start over. A lost admin account is recovered from the server’s command line afterward, never through the wizard.

Language. The wizard’s header carries the same language switcher (English/German) and theme toggle as every sign-in page; there is no separate language step, so switch at any point while filling it in.

The wizard opens with a notice titled “Your responsibility as operator”. You must accept it before anything else in the setup can be saved. It says that Restow is a tool for backup and archiving that writes your data to storage you operate, and that what happens on the hardware and storage layer is your responsibility as operator. Its points are: Restow is no replacement for a backup strategy (keep an independent copy, follow the 3-2-1 rule), hardware and storage, ransomware and deletion (data is only immutable if the storage makes it so, with WORM or Object Lock), encryption keys, network and access security, regular restore tests, the archive and GoBD (the archive features are designed for GoBD-compliant use; whether your whole procedure is compliant is your responsibility, and Restow gives no legal or tax advice), and no warranty beyond the license terms. The full text is in the wizard; Operator notice explains what it covers.

Tick the box to continue. Restow stores which version of the text you accepted, when, and from which client address, and writes the acceptance to the audit log. The server refuses the later steps until the notice is accepted. An installation that was set up before the notice existed, or one whose notice text changed, shows it once to a provider owner or administrator after sign-in; jobs, integrations and other users are not held up.

Choose how Restow will be reached:

  • Local mode: reachable via IP address or localhost, no public domain. Admins sign in with the emergency password and an authenticator app code.
  • Public mode: reachable via your own domain over HTTPS. This is what unlocks passkeys, Entra SSO for end users, and self-service restore.

In public mode you also set the public URL: exactly the address browsers open (for example https://restow.example.com), no path. It defines the passkey domain and the Entra redirect URI everywhere else in Restow. You can change the mode later in Settings.

Restow only offers passkeys once it can verify the domain is cleanly connected: the public URL must be set, served over HTTPS, and the browser’s reported origin must match it exactly. The wizard checks this live and shows one of:

Reason shown What it means
Local mode does not bind a domain, which WebAuthn requires. You’re in local mode.
No valid public URL is set. The public URL field is empty or invalid.
The public URL is not served over HTTPS. Certificate or proxy isn’t in place yet.
The browser reports a different origin than the configured URL. DNS or a proxy points somewhere other than what you typed.

Until passkey readiness is reached, sign-in falls back to the emergency password path with a mandatory authenticator app (TOTP): this is the designed fallback, not a degraded mode.

This account is the provider admin: it sets up Restow and creates tenants. Give it a name, an email and an emergency password (at least 12 characters). Right after signing in for the first time, you set up an authenticator app; from then on Restow asks for its code together with the password on every sign-in. Once passkey readiness is reached, add a passkey under Sign-in security in the user menu; it’s optional at setup time.

How Restow sends notifications: reports, alerts, invitations. (The archive’s journal intake is separate and receive-only; it has nothing to do with this setting.) Pick a transport:

  • SMTP server: host, port, connection security (STARTTLS on 587, implicit TLS on 465, or unencrypted for an internal relay only), optional username/password, sender address.
  • Microsoft Graph (Mail.Send): sends as the Restow Entra app registration, as an application. Requires the Mail.Send application permission with admin consent (see First steps and docs/MICROSOFT.md in the product repository); an Exchange Online Application Access Policy can restrict it to one sender mailbox.

Send a test message to the admin account before continuing. It shows right away whether the transport works, and a failed test does not block finishing the setup (fix the transport afterward in Settings if needed).

Check every entry (operating mode, public URL, admin account, mail transport, test result), then finish. Restow signs you in automatically; if that step fails, the setup itself is still saved and you sign in manually.

Next: First steps to connect a source and take your first backup.