Documentation
Everything you need to go from zero to the first restorable backup.
How Arkame works
Arkame is a BYOS (bring your own storage) backup panel: data flows from your server straight to your bucket (AWS S3, Backblaze B2, Wasabi, OCI, GCS, MinIO, or any S3-compatible storage with versioning). Bucket credentials live only on your server — the panel never sees them.
- Agent: a lightweight binary (or container) installed on the server you want to protect. It runs backups, measures bucket usage, and performs restores.
- Storage: your S3-compatible bucket, registered in the panel (no credentials).
- Plan: connects a source (agent folders) to a destination (storage), with scheduling, exclusions, and bandwidth limits.
- Restore: search by name, browse folders, or go back to a point in time, and restore to any active agent.
1. Register your storage
In the panel, go to Storages → Add storage, pick the provider, and enter the bucket, region, and (for S3-compatible providers) the endpoint. Recommendations:
Never set up cloud storage before? The storage guide goes from a new account at Backblaze, Wasabi or AWS to a key ready for Arkame.
- Enable versioning on the bucket: it's what lets you restore old versions and protects against overwrites/ransomware.
- Turn on Object Lock and set a default retention in Compliance mode (for example, 30 days). Retention is what prevents deleting or overwriting older versions — even with the server’s credential in someone else’s hands — until the period ends. Object Lock turned on without a default retention protects nothing, and versioning alone does not protect you from whoever holds the key. Pick a period longer than it would take you to notice an attack.
- Create a credential (access key) dedicated to the agent, with access to that bucket only.
Object Lock through the S3 API exists on AWS S3, Backblaze B2, Wasabi and MinIO. Google Cloud Storage and OCI have their own retention, outside the S3 API. Cloudflare R2 isn't accepted for new storage: it has no versioning or Object Lock through the S3 API, and without versions you can't go back in time or protect against ransomware. R2 buckets already registered keep working.
Arkame's smart-retention cleanup deletes old versions with the agent's key, so the key needs permission to delete versions (s3:DeleteObjectVersion or equivalent). In a bucket with Object Lock, Arkame deletes nothing: the lock is your decision that nothing leaves before its deadline, and the cleanup respects it. In that case, old versions expire through a lifecycle rule on the bucket itself, which the provider applies only after each version's retention ends. Without Object Lock, a key without permission to delete versions also works: Arkame's cleanup is logged as a failure and the lifecycle rule does the job.
2. Install the agent
In Servers → New server you name the server, pick the bucket and the panel shows one command for its system. On Linux, Docker is the default; there are also native installers for Linux, macOS and Windows. The command carries an install code, valid for 24 hours and single-use. The flow:
- The installer downloads the Arkame agent, verifies the file’s integrity and asks for the bucket’s access key and secret key. They stay on the server — the panel never receives them.
- Before going on, the installer tests the key against the bucket. If the bucket refuses it, it says why and asks again.
- With the key accepted, the agent registers with the panel and creates an Ed25519 key pair on the server. The panel shows the key fingerprint; you check it and approve.
Once approved, the server shows as active, the panel checks the bucket connection and the agent starts running the plans.
Docker (default on Linux) — in the server’s terminal:
sudo docker run --rm -it --user 0 --security-opt label=disable --hostname "$(hostname)" -v /etc/arkame:/etc/arkame \
ghcr.io/arkame-app/arkame-agent:latest install --token=<code> --panel-url=https://save.arkame.app --install-service=false \
&& { sudo docker rm -f arkame-agent >/dev/null 2>&1; \
sudo docker run -d --name arkame-agent --restart always --user 0 --security-opt label=disable --hostname "$(hostname)" \
-v /:/host -v /etc/arkame:/etc/arkame ghcr.io/arkame-app/arkame-agent:latest; }The first container asks for and tests the bucket key and waits for approval; only if it succeeds does the agent start as a service that comes back with the server. On Docker, a plan’s before/after backup commands do not run: schedule database dumps on the host itself (cron), into a folder the plan includes.
Linux and macOS without Docker — in the server’s terminal:
curl -fsSL https://get.arkame.app/install.sh | sudo sh -s -- --token=<code>
Windows — press Windows + R, paste and Enter. Windows asks for administrator permission; click Yes and continue in the window that opens:
cmd /c "curl -fsSLo "%TEMP%\arkame-agent.exe" https://get.arkame.app/agente.exe && "%TEMP%\arkame-agent.exe" setup --token=<code> || pause"
Heads-up: on Windows 11 with Smart App Control turned on, Windows blocks the agent, which is not code-signed yet. Windows 10 and Windows Server work normally.
To change the bucket key later (new key, revoked key), run this on the server — it asks, tests and restarts the agent. On Windows, the panel shows the command for Windows + R.
sudo /usr/local/bin/arkame-agent set-storage-keys --restart
On Docker:
sudo docker run --rm -it --user 0 --security-opt label=disable -v /etc/arkame:/etc/arkame ghcr.io/arkame-app/arkame-agent:latest set-storage-keys && sudo docker restart arkame-agent
3. Create a backup plan
In Plans → New plan, choose the source agent, the folders to protect, exclusions (globs like *.tmp), the destination storage, and the schedule — daily, every X hours, cron, or on demand. You can cap the bandwidth used by backups.
The first backup is full; the following ones are incremental (changed files only), with SHA-256 integrity verification on every file.
4. Restore whenever you need
Under Restore you have three modes: Search (by file name), Browse (navigating the folder tree), and Timeline (going back to a point in time). Select files or folders, choose the target agent, the destination folder, and the conflict strategy — then track progress under History.
Files in cold storage. If your bucket archives on its own — a lifecycle rule sending objects to Glacier or Deep Archive after a few days — the object does not come back instantly. Arkame handles it: on restore, it asks the provider to rehydrate, marks the file with a snowflake, shows when it is expected to be ready, and resumes the transfer by itself once it is. You do not have to come back and try again. What nobody can shorten is the provider’s wait: 3 to 5 hours on Glacier and up to 12 on Deep Archive. The storage screen warns you when your bucket has such a rule, before you need it.
Security
- Bucket credentials exist only on your server (BYOS): the panel never receives them.
- Each agent has its own identity (Ed25519), manually approved by you.
- The Arkame agent talks to the panel and to the bucket over HTTPS, and every file’s integrity is checked with SHA-256. On an S3 service you host yourself you set the endpoint — use HTTPS there too.
- Sensitive actions are recorded in the organization's history. The screen for you to read that record does not exist yet: for now, Arkame support looks it up on request.
Removing the agent from a server
The command removes the service, the configuration file with the bucket key, the agent’s identity and the program itself from the server. The backups stay in the bucket.
Windows
In Settings → Apps → Installed apps, find "Arkame — agente de backup" and click Uninstall. Or press Windows + R, paste and Enter (an agent older than 0.3.1 isn’t listed in Apps: use this path after reinstalling):
powershell -Command "Start-Process -Verb RunAs 'C:\Program Files\Arkame\arkame-agent.exe' 'uninstall --pause'"
Linux and macOS
sudo /usr/local/bin/arkame-agent uninstall
Docker
sudo docker rm -f arkame-agent && sudo rm -rf /etc/arkame
Then, in the panel, archive the server (Servers → ⋯ → Archive) so it stops being billed. Its history and backups remain restorable, and the name is free for another machine.
Agent offline — how to recover
If the panel shows an agent as offline (no heartbeat for over 5 minutes), the agent service has likely stopped on the server. Backups, restores and the connection test only run while the agent is active. Use the commands below for your operating system.
Simplest way (any OS): run `arkame-agent status` on the server — it shows whether the agent is enrolled and its last heartbeat, without needing the service name.
Docker
If you installed with Docker, the agent is the arkame-agent container. Check that it is running, read the last lines of its log and restart it:
sudo docker ps -a --filter name=arkame-agent sudo docker logs --tail 50 arkame-agent sudo docker restart arkame-agent
Linux — default install (system service, with sudo)
sudo systemctl status arkame-agent sudo systemctl restart arkame-agent sudo journalctl -u arkame-agent -n 50
Linux — per-user install
Here the commands are without sudo — sudo systemctl --user queries the root user’s services, not yours. Use list-unit-files (not list-units, which hides stopped services) to find the name:
systemctl --user list-unit-files 'arkame-agent*' # finds the name (shows stopped ones) systemctl --user restart <service-name> journalctl --user -u <service-name> -n 50
macOS (launchd)
sudo launchctl print system/app.arkame.agent sudo launchctl kickstart -k system/app.arkame.agent
macOS — install without sudo (user agent)
launchctl list | grep app.arkame # finds the name (shows stopped ones) launchctl kickstart -k gui/$(id -u)/<label>
Windows
The agent runs as a Windows service (arkame-agent). To restart it, press Windows + R, paste and Enter; click Yes when Windows asks for permission:
powershell -Command "Start-Process -Verb RunAs powershell '-Command Restart-Service arkame-agent'"
If the service no longer exists (for example, the machine was reinstalled), generate a new command under Servers → ⋯ menu → "Reinstall" and run it again.
Still have questions? The help center inside the panel has the full walkthrough.
Open the panel