How to back up a DigitalOcean Managed PostgreSQL cluster, past its 7 days
DigitalOcean backs up a managed PostgreSQL cluster once a day and keeps seven days, with a restore to a point in time that makes a new cluster. It keeps no backup longer than that and gives you no file. This page is the dump you keep: the host to connect to, the role, the command, where the file goes, the restore and the check, plus the one thing to know about Spaces as the destination. The last section is how SafeGrd runs it from a droplet in the VPC.
What DigitalOcean's backups cover
From DigitalOcean's documentation, read on 2026-10-08:
- Daily, kept 7 days. "PostgreSQL cluster backups run automatically once per day and are retained for seven days." A restore goes to the latest transaction or a point in time, and "creates a new copy of the cluster's primary node."
- No download. The docs say to "download any important data before you destroy a cluster," and give no way to take a backup out, so the dump is it.
- Not a superuser. "To maintain cluster stability, users cannot access the superuser role," and only listed extensions can be installed. A dump works without either; a restore into a new cluster needs the extensions on the list.
1. Reach the cluster
The cluster's Connection Details show a public hostname and, for anything
in the same VPC, a private one. Both use the port the panel shows, and the string ends in
sslmode=require:
- Trusted sources. A cluster with none configured accepts connections from anywhere; DigitalOcean's migration guide describes removing them as leaving the cluster "open to all incoming connections." Add the droplet, Kubernetes cluster, app, tag or IP address the backup runs from, and nothing else. IPv6 rules are not supported.
- The private hostname works only from the same VPC, and keeps the dump off the public internet. A droplet in the VPC is the natural place for a scheduled backup.
- Connect to the database, not a pool. The panel offers connection pools in transaction, session and statement mode. A dump needs its own server connection for the whole run; the direct cluster connection, or a pool in session mode, gives it one. A transaction-mode pool does not.
sslmode=requireis the default in the panel's strings; it encrypts without checking the server's identity. The panel's verify-full toggle gives a string with the CA certificate for a check.
Make a role for the backup that can read and cannot write. doadmin can create
it:
2. Dump it
The client has to be at least the cluster's major version, shown on the cluster's overview.
--no-owner --no-privileges keeps doadmin and DigitalOcean's grants
out of the dump, so it restores anywhere. A cluster with several databases is one dump
each.
3. Off the account, encrypted, on a schedule
Where the bucket is matters. DigitalOcean Spaces is S3-compatible and the obvious choice from a droplet, and it has no Object Lock: anyone with the Spaces key can delete every backup in it. For a copy nobody can delete early, use a bucket with Object Lock at another provider, in an account that is not the one the droplet's keys reach: which providers have it, and how to set one up. If Spaces is where it has to go, give the droplet a key that can write and not delete, and keep a second copy elsewhere. The S3 guide has the full script and the policy.
4. Restore, and check it
Into a new DigitalOcean cluster, or any PostgreSQL of the same or a newer major version: create an empty database and restore into it, stopping at the first error. A new cluster needs any extension the dump names to be on DigitalOcean's supported list.
Then compare row counts per table with the source, as How to test that a backup restores shows.
How SafeGrd does it
SafeGrd's daemon runs on a droplet in the VPC, from the install script or the
ghcr.io/safegrd/cli image, and reads the cluster over the private hostname.
A sandbox drill loads the backup into a PostgreSQL server on the droplet: the image carries
one, and a droplet set up by the install script needs one installed. SafeGrd does the same job on every platform; the PostgreSQL page has what it dumps, how it encrypts, and what a drill checks.
Run your first Fire Drill Read the install guide
curl -fsSL https://safegrd.dev/install.sh | sh
safegrd enroll
safegrd backup --database-url "$DATABASE_URL" --retention-days 14
Spaces works as a sink with the lock turned off in the config, stated as
worm_mode: "NONE", and the console says so on every backup written there
(Spaces, and any bucket without Object Lock).
With no droplet, Back up on SafeGrd under Surfaces in the console takes the public
connection string; a machine SafeGrd starts for each backup dumps and encrypts it, then is
destroyed, and the string is sealed and given only to that machine
(how). Where SafeGrd's machines connect from fixed
addresses, the console shows them, for the cluster's trusted sources.
Questions
Does this replace DigitalOcean's backups?
No. The daily backup and the point-in-time restore are the quick undo for the last week, and they come with the cluster. The dump is for anything older, and for after the cluster or the account is gone.
Can I back up from a standby node?
Yes, where the plan offers read-only connections to a standby. Point the connection string at it to keep the read off the primary; the dump is the same.
Related
- How to back up a PostgreSQL database: pg_dump's formats and flags, restore and the check
- Immutable backups with S3 Object Lock: which providers have it
- Hetzner backup: the same job with Hetzner Object Storage, which has Object Lock