Plan space for the board you run
A small text board and a large file library need different backup budgets. SPITFIRE NG keeps the critical board state protected while letting you choose how managed file content is retained.
What needs protecting?
| Kind of data | What it includes | Your backup responsibility |
|---|---|---|
| Critical board state | Configuration, users, messages, conferences, network records, SYSTEM and DISPLAY resources. | Always included in managed snapshots; never silently omitted to make an update fit. |
| SPITFIRE-managed payloads | File bytes stored and tracked by SPITFIRE. | Copied by default. Metadata-only policy instead requires matching bytes retained separately. |
| External libraries | Files on operator-managed disks, NAS or removable media. | Metadata and expected paths/hashes are recorded, but external bytes are neither read nor copied automatically. Back these up separately. |
| Regenerable state | Eligible caches, temporary work and runtime endpoints. | Reconstructed where supported; not a substitute for critical state. SYSTEM and DISPLAY are copied conservatively in full. |
Runtime executables are kept separately under the installation's releases. Preserve the installation as well as backups for loss of the host; D1 is not a new-host recovery installer.
Warnings and stopping points
- Minimum free space: maintenance refuses to begin below this floor.
- Reserve: space that must remain after the planned work, so recovery has room.
- Hard stop: an absolute floor checked before and after budgeting. The larger of reserve and hard stop must remain.
- Warning: projected free space is getting low, even though the refusal checks passed.
- Backup size limit: the proposed copied snapshot and manifest allowance must fit.
- Retention budget: existing backup files plus the new backup must fit. No old backup is removed automatically.
Managed-file, area and single-file limits can also refuse an update. These are maintenance eligibility checks, not live upload quotas. Retention budgets do not cap the entire installation: retained runtimes and staging also consume disk space.
Try the plan before the maintenance window
Run spitfire update --dry-run with the intended release and policy. It estimates backup and temporary workspace, reports warnings, and refuses unsafe plans. It does not reserve disk space or promise later success.
Metadata-only reduces copying, not validation reads of managed content. Very large or slow libraries can hit validation time limits and cause refusal. External references do not prove those disks are present or their bytes are intact.
Keep a recovery copy
Nothing automatically prunes backups, recovery checkpoints or old releases. Expand space or archive the complete stopped installation to your own storage before a reviewed retention change. Keep the only known-good checkpoint and any pending transaction intact.
Backups contain private board data and may include private host keys. D1 does not encrypt, replicate or upload them. Keep external media and referenced managed payloads covered by a separate backup plan.
Advanced: exact storage settings and budgeting rules.