Skip to content

Keeper

Keeper backs up Postgres and MySQL databases running in Kubernetes to any S3 bucket, streams every change, and restores any second of the retention window into a throwaway sandbox, a new database, or in place. Everything is a Kubernetes resource, every object is encrypted before it leaves the pod, and data moves only in short-lived Jobs.

  • Quickstart


    Install the chart, point Keeper at a bucket, declare your first database and restore it, in about ten minutes.

    Get started

  • Restore


    Pick a time or a backup and a destination: a sandbox, a new database, a download, or in place.

    Restore guide

  • Custom resources


    Every field of BackupStore, BackupPolicy, BackupTarget, Backup, Restore and Sandbox.

    CRD reference

  • REST API


    The JSON API behind the console and the CLI, generated from its OpenAPI document.

    API reference

  • CLI


    keeper targets, diff, restore, sandbox connect, query and the rest.

    CLI reference

  • On call


    What each alert means and what to do about it, including restoring when Keeper itself is down.

    Runbook

At a glance

Area Details
Engines Postgres 15, 16, 17 (incl. PostGIS): physical or logical backups plus WAL streaming. MySQL 8.4: logical backups plus binlog streaming.
Storage Any S3-compatible bucket. zstd compression (on by default) and age encryption on the client, parallel multipart uploads, manifest written last.
Restore Any second inside the point-in-time window, or any retained backup, into a sandbox, a new database, a download or in place.
Safety Scheduled verification restores with your SQL checks, Prometheus alerts, a Grafana dashboard, and a chaos suite that kills Keeper mid-backup.
Footprint One static binary for the controller, the API and console, the data movers and the CLI. Nothing heavy runs between backups.
Access Console and CLI on one JSON API (OpenAPI), with roles from Cloudflare Access. Every write and query is audited.