velaclaw backup
Create a local backup archive for Velaclaw state, config, auth profiles, channel/provider credentials, sessions, and optionally workspaces.
Notes
- The archive includes a
manifest.jsonfile with the resolved source paths and archive layout. - Default output is a timestamped
.tar.gzarchive in the current working directory. - If the current working directory is inside a backed-up source tree, Velaclaw falls back to your home directory for the default archive location.
- Existing archive files are never overwritten.
- Output paths inside the source state/workspace trees are rejected to avoid self-inclusion.
velaclaw backup verify <archive>validates that the archive contains exactly one root manifest, rejects traversal-style archive paths, and checks that every manifest-declared payload exists in the tarball.velaclaw backup create --verifyruns that validation immediately after writing the archive.velaclaw backup create --only-configbacks up just the active JSON config file.
What gets backed up
velaclaw backup create plans backup sources from your local Velaclaw install:
- The state directory returned by Velaclaw’s local state resolver, usually
~/.velaclaw - The active config file path
- The resolved
credentials/directory when it exists outside the state directory - Workspace directories discovered from the current config, unless you pass
--no-include-workspace
agents/<agentId>/agent/auth-profiles.json, so they are normally covered by the
state backup entry.
If you use --only-config, Velaclaw skips state, credentials-directory, and workspace discovery and archives only the active config file path.
Velaclaw canonicalizes paths before building the archive. If config, the
credentials directory, or a workspace already live inside the state directory,
they are not duplicated as separate top-level backup sources. Missing paths are
skipped.
The archive payload stores file contents from those source trees, and the embedded manifest.json records the resolved absolute source paths plus the archive layout used for each asset.
Invalid config behavior
velaclaw backup intentionally bypasses the normal config preflight so it can still help during recovery. Because workspace discovery depends on a valid config, velaclaw backup create now fails fast when the config file exists but is invalid and workspace backup is still enabled.
If you still want a partial backup in that situation, rerun:
--only-config also works when the config is malformed because it does not rely on parsing the config for workspace discovery.
Size and performance
Velaclaw does not enforce a built-in maximum backup size or per-file size limit. Practical limits come from the local machine and destination filesystem:- Available space for the temporary archive write plus the final archive
- Time to walk large workspace trees and compress them into a
.tar.gz - Time to rescan the archive if you use
velaclaw backup create --verifyor runvelaclaw backup verify - Filesystem behavior at the destination path. Velaclaw prefers a no-overwrite hard-link publish step and falls back to exclusive copy when hard links are unsupported
--no-include-workspace.
For the smallest archive, use --only-config.