Free tools / Backup file checker

Backup file checker

Choose a dump file your own backup job wrote to see what it is, which version of which tool wrote it, whether it was cut short, and the command that restores it. The file is read in this browser and is never uploaded.

Which file to choose

The file a database's own dump tool wrote: the one your cron job, CI step or hosting provider's export leaves behind. For example:

Your backup job runsChoose
pg_dump -Fc app > app.dumpapp.dump
pg_dump app | gzip > app.sql.gzapp.sql.gz
pg_dump -Fd -f app.dir appapp.dir/toc.dat
pg_dumpall > all.sqlall.sql
mysqldump --single-transaction shop > shop.sqlshop.sql
mongodump --archive=app.archive --gzipapp.archive
sqlite3 app.db ".backup app-copy.db"app-copy.db

If the job encrypts the dump (age, gpg) or compresses it with zstd, decrypt or decompress it on your own machine first. A gzipped file can be chosen as it is.

SafeGrd snapshots are checked a different way. A snapshot holds SafeGrd's own archive of the database, and safegrd verify --snapshot ID restores it and counts every table and row against what was backed up (Restore and Fire Drills).

What it checks

FileWhat it reads
pg_dump custom or tarThe archive header: format version, the pg_dump and server versions, database, date and compression. From the format version it names the oldest pg_restore that reads the file. A tar archive must end with its end-of-archive blocks.
pg_dump plain SQLThe completion line pg_dump writes last, the versions, the extensions and owner roles the target needs, and the \restrict line that older psql versions cannot run.
mysqldump and mariadb-dumpThe Dump completed line, versions, tables, definers that need an account on the target, and MariaDB's sandbox line that the mysql client refuses.
mongodump --archiveThe archive header, its collections, and the terminator a complete archive ends on.
SQLiteThe page count in the header against the file's size, and WAL mode, where a copied file can miss recent transactions.

A gzipped file is decompressed as it is read, and a gzip stream that ends early is reported as cut short.

What it cannot tell you

A file can be complete and still fail to load: a missing extension or role, a server version that rejects its syntax, or a backup of the wrong database. The only check that catches those is a restore into an empty database, followed by counting what came back. The guide to testing a restore shows how to do that by hand.

SafeGrd does it on a schedule. It restores each backup, counts every table and row against what was backed up, and signs the result (Backup verification).

Run your first Fire Drill Build a pg_dump command