How to set up off-machine backups¶
Send a copy of InteLIS to another machine or drive, automatically, every 8 hours and after every restart. The copy survives if the InteLIS machine fails.
Storage needed
Use a backup machine or drive with at least 1 TB of space. That covers one STS and up to about 30 LIS machines, with 5 weeks of database history. For a larger network, allow 50 GB for each STS and 20 GB for each LIS machine, plus 30 GB for the operating system, and keep a quarter of the disk free.
Another Linux machine is the recommended place for backups. One backup machine takes the backups of every lab: prepare it once, then run the setup on each lab's InteLIS machine. Use a USB drive only when there is no other machine.
Choose where the backups go, then follow its steps from top to bottom.
Use this when there is a second Linux machine on the same network. This is the recommended choice.
Prepare the backup machine¶
Do this once. Every lab then sends its backups to the same machine.
-
On the backup machine, open a terminal and install the SSH server:
sudo apt install openssh-server -
Find the backup machine's IP address:
hostname -IWrite down the first address, for example
192.168.1.60. -
Write down the username and password used to manage the backup machine. Each lab's setup logs in with them once, and creates the backup account itself. Nothing else needs to be created on the backup machine.
This is the account used to log in to the backup machine's desktop, created when Ubuntu was installed. To see its username, run this in the same terminal:
whoamiCheck the account can manage the machine
Run:
groupsThe list must include
sudo. If it does not, log in with the account created when Ubuntu was installed and use that one.How to add a user on Ubuntu
Do this only once, on the backup machine. Every lab then uses the same
lisbackupaccount, so it is never repeated for later labs.Setup creates
lisbackupby itself when it logs in as the administrator. Add it by hand only when the administrator's password cannot be typed during setup.-
On the backup machine, open a terminal and run:
sudo adduser lisbackup -
If asked for a password first, type the password used to log in to the backup machine. This one is for
sudo. - At
New password, type a strong password forlisbackupand press Enter. Type it again atRetype new password. Nothing appears on screen while typing. Write the password down. - At
Full Name,Room Numberand the other questions, press Enter to leave them blank. - At
Is the information correct?, typeYand press Enter.
During setup on each lab's InteLIS machine, choose Type the lisbackup password at How should it be given? and type this password.
-
Set up the backup on the InteLIS machine¶
-
On the InteLIS machine, open a terminal and run:
intelis backup setupThe command checks for the current backup setup script before it runs. If the machine is offline, it uses the installed script.
-
Answer the questions:
Question Answer Lab name or lab code A short name for this lab, such as kigali-central.Where should the backup be sent? Another Linux machine on the network (recommended). Address of the backup machine The address from step 2. This machine needs access to … How should it be given? Log in as the backup machine's administrator (recommended). Administrator account on the backup machine The username from step 3. If it says
Cannot reach …Check the backup machine is switched on and on the same network. Check the address with
ping 192.168.1.60, using the address from step 2. Check the SSH server from step 1 is installed. Then choose Yes at Try again?.If the backup machine uses another SSH port or account
Write them into the address:
192.168.1.60:2222for port 2222, orbackup@192.168.1.60for the accountbackup. Without them, setup uses port 22 and the accountlisbackup. -
When asked for a password, type the password from step 3 and press Enter. It can be asked twice: once to log in, and once more for
sudo. The first lab creates thelisbackupaccount on the backup machine. Every later lab adds its own access to that account. Later backups need no password.If it says
Could not log in as … eitherThe username or password is wrong, or the backup machine refuses that account's password. Check both on the backup machine. Setup asks How should it be given? again.
If it says
adding the key failedThe account logged in but is not allowed to use
sudo. Check the account as in step 3:groupson the backup machine must listsudo. Choose Log in as the backup machine's administrator again and type the account created when Ubuntu was installed.Without the administrator's password
At How should it be given?, choose one:
Choice Use it when Type the lisbackup password lisbackupalready exists on the backup machine with a password. To create it, see How to add a user on Ubuntu in step 3.Add it by hand on the backup machine Someone else manages the backup machine. The script prints four commands. The first creates the lisbackupaccount if it does not exist yet. Send them to that person. When they have run them, choose Yes at Has it been added? Check now?.Logging in to the backup machine by hand
Setup adds the backup machine to
/root/.ssh/config, sosudo ssh lisbackup@192.168.1.60from the InteLIS machine uses the backup key. Use the address from step 2. -
Wait for the first backup to finish. It can take an hour or more. The script ends with
Backups are set up and the first one completed.If it ends with
Setup finished, but the first backup failedThe settings are saved. Read the error above the message, fix the cause, then run the backup again:
intelis backup
Confirm it works¶
-
Run:
intelis backup statusA working backup looks like this:
Lab : kigali-central (kigali-central-3f9a2b1c) Backing up to : lisbackup@192.168.1.60:/home/lisbackup/backups/kigali-central-3f9a2b1c Last good backup: 2026-08-07T09:14:22Z (12 minutes ago) Size on backup : 4.2G History : 2026-08-01 to 2026-08-07 (7 days) Last attempt : succeeded in 47s Schedule : every 8 hours and after every restartCheck these lines:
Line Must show Last good backup A time less than 8 hours ago. Last attempt succeeded.Schedule every 8 hours and after every restart.If
Last attemptshowsFAILEDThe
Reasonline below it gives the cause. Fix it, then runintelis backup. The full record is in/var/log/intelis-backup.log.If
ScheduleshowsOFFStart the scheduled backups again:
intelis backup enable
Once a week, check the status the same way, then run:
intelis health
The backup line must not show a warning. If it mentions newest DB dump,
the database backups have stopped. See the warning under
Where the backup lands. Once
every three months, restore the newest backup onto a spare or test machine
by following Restoring from a Backup. A backup
that has never been restored is not yet proven to work.
Where the backup lands¶
The backup is on the backup machine, in a folder named after the lab and a code unique to this InteLIS machine:
/home/lisbackup/backups/kigali-central-3f9a2b1c/
It holds the whole InteLIS folder. The database backups are in backups/db
and the settings backups in backups/config. It leaves out files rebuilt on
install: vendor/, node_modules/, caches, logs, temporary files and
version-control folders.
The folder is a mirror of this machine, so it holds the newest database
backups only, about the last 2 days. Files deleted on this machine are
deleted from the mirror at the next run. Older database backups are kept
next to it, in .history/:
Kept in .history/ |
How many |
|---|---|
| One database backup per day | The newest 7 days |
| One database backup per week, after that | 4 more weeks |
| The settings backup | One per week, for the same period |
That is about 5 weeks in all. A wipe or reinstall of this machine does not
touch .history/. To keep more, change HISTORY_DAYS and HISTORY_WEEKS
in /etc/intelis/backup.conf.
The backup also holds the settings, which include the database password. Keep the backup folder readable only by the people who manage InteLIS.
Two labs with the same name still get separate folders. One lab never overwrites another lab's backup.
If a backup says that the newest database dump is old
The InteLIS scheduler has stopped, so no new database backups are being
made. The backup stops before changing the destination. Check the
scheduler by following Check the scheduled tasks are running.
Then run intelis backup.
Other commands¶
| Task | Command |
|---|---|
| Back up now | intelis backup |
| Check the connection without copying | intelis backup test |
| Watch a backup as it runs | tail -f /var/log/intelis-backup.log |
| Stop the scheduled backups | intelis backup disable |
| Start them again | intelis backup enable |
| Change where backups go | Run intelis backup setup, then choose Change where backups go. The saved answers are offered. Press Enter to keep one. |
To get the data back, see Restoring from a Backup.
Use this when there is a Windows computer on the same network. Nothing is installed on Windows.
Prepare the Windows computer¶
-
On the Windows computer, create this folder:
C:\InteLIS-Backups -
Press Win+R, type
lusrmgr.msc, and press Enter.If Windows says it cannot find
lusrmgr.mscWindows Home editions do not have it. Open Settings → Accounts → Other users and select Add account. Select I don't have this person's sign-in information, then Add a user without a Microsoft account. Create the user from step 3 there, then carry on at step 5.
-
Right-click Users and select New User. Set the user name to
lisbackupand set a strong password. Write the password down. - Untick User must change password at next logon. Tick Password never expires. Select Create.
- Right-click the
C:\InteLIS-Backupsfolder and select Properties. Open the Sharing tab and select Advanced Sharing. - Tick Share this folder. Set Share name to
InteLIS-Backups. The name must not contain spaces. - Select Permissions. Add
lisbackup, then tick Change and Read under Allow. Select OK on each window. - Give the Windows computer a fixed IP address. Either set a static
address on it, or reserve its address in the router. Write the address
down, for example
192.168.1.50. - Open Control Panel → Windows Defender Firewall → Allow an app or feature through Windows Defender Firewall. Check that File and Printer Sharing is ticked under Private.
Set up the backup on the InteLIS machine¶
-
On the InteLIS machine, open a terminal and run:
intelis backup setupThe command checks for the current backup setup script before it runs. If the machine is offline, it uses the installed script.
-
Answer the questions:
Question Answer Lab name or lab code A short name for this lab, such as centrallab.Where should the backup be sent? A shared folder on a Windows machine. Windows hostname or IP The address from step 8. Name of the shared folder InteLIS-BackupsWindows username lisbackupWindows password for lisbackup The password from step 3. If it says
Could not connect to //…Check the Windows computer is switched on and not asleep. Check the address from step 8, the share name, the username and the password. Check step 9. Then choose Yes at Try again?.
If it says
Connected, but the folder is read-onlyOn the Windows computer, repeat step 7 and make sure Change is ticked. Then choose Yes at Try again?.
If it says
The share name contains a spaceOn the Windows computer, repeat steps 5 and 6 with a share name without spaces, such as
InteLIS-Backups. The script asks the questions again. -
Wait for the first backup to finish. It can take an hour or more. The script ends with
Backups are set up and the first one completed.If it ends with
Setup finished, but the first backup failedThe settings are saved. Read the error above the message, fix the cause, then run the backup again:
intelis backup
Confirm it works¶
-
Run:
intelis backup statusA working backup looks like this:
Lab : centrallab (centrallab-3f9a2b1c) Backing up to : //192.168.1.50/InteLIS-Backups -> /mnt/intelis-backup/backups/centrallab-3f9a2b1c Last good backup: 2026-08-07T09:14:22Z (12 minutes ago) Size on backup : not measured History : 2026-08-01 to 2026-08-07 (7 days) Last attempt : succeeded in 96s Schedule : every 8 hours and after every restartCheck these lines:
Line Must show Last good backup A time less than 8 hours ago. Last attempt succeeded.Schedule every 8 hours and after every restart.If
Last attemptshowsFAILEDThe
Reasonline below it gives the cause. A Windows computer that is switched off or asleep is the usual one. Fix it, then runintelis backup. The full record is in/var/log/intelis-backup.log.If
ScheduleshowsOFFStart the scheduled backups again:
intelis backup enable
Once a week, check the status the same way, then run:
intelis health
The backup line must not show a warning. If it mentions newest DB dump,
the database backups have stopped. See the warning under
Where the backup lands. Once
every three months, restore the newest backup onto a spare or test machine
by following Restoring from a Backup. A backup
that has never been restored is not yet proven to work.
Where the backup lands¶
The backup is on the Windows computer, in a folder named after the lab and a code unique to this InteLIS machine:
C:\InteLIS-Backups\backups\centrallab-3f9a2b1c\
It holds the whole InteLIS folder. The database backups are in backups\db
and the settings backups in backups\config. It leaves out files rebuilt on
install: vendor/, node_modules/, caches, logs, temporary files and
version-control folders.
The folder is a mirror of this machine, so it holds the newest database
backups only, about the last 2 days. Files deleted on this machine are
deleted from the mirror at the next run. Older database backups are kept
next to it, in .history/:
Kept in .history/ |
How many |
|---|---|
| One database backup per day | The newest 7 days |
| One database backup per week, after that | 4 more weeks |
| The settings backup | One per week, for the same period |
That is about 5 weeks in all. A wipe or reinstall of this machine does not
touch .history/. To keep more, change HISTORY_DAYS and HISTORY_WEEKS
in /etc/intelis/backup.conf.
The backup also holds the settings, which include the database password. Keep the backup folder readable only by the people who manage InteLIS.
Two labs with the same name still get separate folders. One lab never overwrites another lab's backup.
If a backup says that the newest database dump is old
The InteLIS scheduler has stopped, so no new database backups are being
made. The backup stops before changing the destination. Check the
scheduler by following Check the scheduled tasks are running.
Then run intelis backup.
Other commands¶
| Task | Command |
|---|---|
| Back up now | intelis backup |
| Check the connection without copying | intelis backup test |
| Watch a backup as it runs | tail -f /var/log/intelis-backup.log |
| Stop the scheduled backups | intelis backup disable |
| Start them again | intelis backup enable |
| Change where backups go | Run intelis backup setup, then choose Change where backups go. The saved answers are offered. Press Enter to keep one. |
To get the data back, see Restoring from a Backup.
Use this when there is no other machine to send backups to. The drive must stay plugged into the InteLIS machine.
Set up the backup¶
- Plug the drive into the InteLIS machine.
-
Open a terminal and run:
intelis backup setupThe command checks for the current backup setup script before it runs. If the machine is offline, it uses the installed script.
-
Answer the first questions:
Question Answer Lab name or lab code A short name for this lab, such as centrallab.Where should the backup be sent? A USB or external drive plugged into this machine. -
At Which drive should the backups go to?, choose the USB drive. Each row shows the drive's name and size. The script connects the drive, and connects it again by itself after every restart.
If it says
No drive was found apart from this machine's own diskThe drive is not plugged in, or is not recognised. Plug it in, wait a few seconds, then choose Look again.
If it says
This drive is formatted as FAT32FAT32 cannot hold a file of 4 GB or more, and database backups grow past that. Reformat the drive as exFAT or ext4. This erases everything on it. Open the Disks app, select the drive, then select Format Partition. Then choose Look again.
If it says
The drive is open at …A window is showing the drive's files. Close it, then choose Yes at Choose again? and choose the drive again.
-
Wait for the first backup to finish. It can take an hour or more. The script ends with
Backups are set up and the first one completed.If it ends with
Setup finished, but the first backup failedThe settings are saved. Read the error above the message, fix the cause, then run the backup again:
intelis backup
Confirm it works¶
-
Run:
intelis backup statusA working backup looks like this:
Lab : centrallab (centrallab-3f9a2b1c) Backing up to : /mnt/intelis-usb/backups/centrallab-3f9a2b1c Last good backup: 2026-08-07T09:14:22Z (12 minutes ago) Size on backup : 4.2G History : 2026-08-01 to 2026-08-07 (7 days) Last attempt : succeeded in 52s Schedule : every 8 hours and after every restartCheck these lines:
Line Must show Last good backup A time less than 8 hours ago. Last attempt succeeded.Schedule every 8 hours and after every restart.If the reason is
The backup drive is not plugged inPlug the drive in, then run
intelis backup. The backup connects the drive by itself.If the reason is
The backup drive at … is not thereThe drive was set up by an older version, which relied on it being opened in the Files app. Run
intelis backup setup, choose Change where backups go, and choose the drive from the list.If
Last attemptshowsFAILEDfor another reasonThe
Reasonline below it gives the cause. Fix it, then runintelis backup. The full record is in/var/log/intelis-backup.log.If
ScheduleshowsOFFStart the scheduled backups again:
intelis backup enable
Once a week, check the status the same way, then run:
intelis health
The backup line must not show a warning. If it mentions newest DB dump,
the database backups have stopped. See the warning under
Where the backup lands. Once
every three months, restore the newest backup onto a spare or test machine
by following Restoring from a Backup. A backup
that has never been restored is not yet proven to work.
Where the backup lands¶
The backup is on the drive, in a folder named after the lab and a code unique to this InteLIS machine:
/mnt/intelis-usb/backups/centrallab-3f9a2b1c/
It holds the whole InteLIS folder. The database backups are in backups/db
and the settings backups in backups/config. It leaves out files rebuilt on
install: vendor/, node_modules/, caches, logs, temporary files and
version-control folders.
The folder is a mirror of this machine, so it holds the newest database
backups only, about the last 2 days. Files deleted on this machine are
deleted from the mirror at the next run. Older database backups are kept
next to it, in .history/:
Kept in .history/ |
How many |
|---|---|
| One database backup per day | The newest 7 days |
| One database backup per week, after that | 4 more weeks |
| The settings backup | One per week, for the same period |
That is about 5 weeks in all. A wipe or reinstall of this machine does not
touch .history/. To keep more, change HISTORY_DAYS and HISTORY_WEEKS
in /etc/intelis/backup.conf.
The backup also holds the settings, which include the database password. Keep the backup folder readable only by the people who manage InteLIS.
Two labs with the same name still get separate folders. One lab never overwrites another lab's backup.
If a backup says that the newest database dump is old
The InteLIS scheduler has stopped, so no new database backups are being
made. The backup stops before changing the destination. Check the
scheduler by following Check the scheduled tasks are running.
Then run intelis backup.
Other commands¶
| Task | Command |
|---|---|
| Back up now | intelis backup |
| Check the drive without copying | intelis backup test |
| Watch a backup as it runs | tail -f /var/log/intelis-backup.log |
| Stop the scheduled backups | intelis backup disable |
| Start them again | intelis backup enable |
| Change where backups go | Run intelis backup setup, then choose Change where backups go. The saved answers are offered. Press Enter to keep one. |
To get the data back, see Restoring from a Backup.
A backup in the same room as the InteLIS machine does not survive a fire or a theft. To keep a second copy elsewhere, see Backing up to Google Drive with Rclone.