Skip to content

Step 10 — Backups

Step 10 · Honesty

Everything the agent knows lives on one computer in your house. Losing that machine should be an inconvenience, not the end of the project.

The trap is that the things worth backing up are not the things that take up the most space.

Recovery backupConvenience backup
PurposeSurvive losing the machineUndo a mistake from earlier today
ContainsOnly irreplaceable stateEverything
SizeSmallLarge
WhereOff the machineOn the machine
FrequencyDaily, automaticManual, when you want one

You need both, and confusing them causes trouble. A large convenient backup is not disaster recovery, and a small recovery backup will not roll back an hour.

  1. List what cannot be rebuilt. That list is your backup.
  2. Back it up daily, automatically, off the machine.
  3. Add a size check so a broken run cannot overwrite a good copy.
  4. Restore it once, on purpose, before you need it.
  5. Write down what is not covered.

The principle: back up what cannot be rebuilt. Everything else makes the backup slow and the restore fragile.

Back upWhy
Working memory and conversation historyNot reproducible, and it is the whole point
The wikiYour household’s knowledge, written by hand
Configuration and schedulesRebuilding by hand is error-prone
Credentials, encryptedPainful to re-issue
The job definitionsReproducible, but tedious
Leave outWhy
Downloaded programs and dependenciesReinstallable in minutes
Caches and temporary filesRegenerate themselves
Log filesUseful for a day, then noise
Large media attachmentsThe conversation survives without them

That second table is what takes a backup from gigabytes to something you can email. Mine went from roughly two gigabytes to tens of megabytes, which is what makes keeping an off-site copy practical.

The most dangerous backup is one that silently writes a broken copy over the last good one. Two habits prevent it:

  1. Write to a temporary file, check it, then move it into place. If the job dies halfway, the last good copy is untouched.
  2. Refuse to publish a suspiciously small archive. A size check catches the common failures: a disk filling up, a half-finished run, a folder that went missing.

A backup you have never restored is a hypothesis. Restore it once, deliberately, onto a spare machine, before you need to.

Roughly an hour, once the downloads finish.

  1. Install the operating system and the agent platform.
  2. Create the agent’s own account again — a clean machine will not have it.
  3. Restore the recovery backup.
  4. Re-authenticate every external service. Credentials rarely survive a machine move, and the failures are confusing if you do not expect them.
  5. Re-pair every channel the household talks through.
  6. Confirm the schedules are back, and send yourself a test message.

Step 4 is the one that catches people. Access to external services is usually tied to the machine in a way that does not transfer, and no amount of restoring fixes it. Budget for it.

A daily recovery backup has one honest weakness: if the state is corrupted today, tonight’s backup faithfully overwrites the good copy with the corrupted one.

You are protected against losing the machine. You are not protected against realising at 4pm that you needed yesterday’s version.

My mitigations, cheapest first:

  • A second, local snapshot that keeps hourly history for a day or so. The cheapest real fix.
  • Rotate a small number of daily copies — a week, not a year — if storage allows.
  • Accept it, and write it down. An acknowledged gap is survivable.

It is on The Gaps I Have Not Solved deliberately. I would rather tell you than have you find out.

  • A daily backup runs and you have seen today’s file
  • It lives somewhere other than the agent’s machine
  • A size check would stop a broken copy replacing a good one
  • You have restored it once, on purpose
  • You have written down what it does not cover

Watchdogs — because a backup that stopped running three weeks ago is the most common silent failure there is.