DNS zone backups (Cloudflare)
Keep every record of a Cloudflare zone in your own storage, and put back what changed.
A DNS zone job backs up every record in one of your Cloudflare zones: A, AAAA, CNAME, MX, TXT, CAA, SRV and the rest, with their proxying, TTLs and comments. Each backup is one file in your own storage, holding the records and the zone as a BIND file that Cloudflare or any other DNS host can import.
Setting one up
- Connect Cloudflare under Providers, by signing in or with an API token that has Zone Read and DNS Edit on the zones.
- Create a backup job, choose DNS zone, then the connection, the zone and the storage destination. Or, on the Cloudflare connection's page, choose Back up this zone.
- Schedule and retention work as for any other job.
Restoring
Open a backup and choose Preview changes. It compares the backup with the zone as it is now and lists every record that was changed, deleted or added since, without changing anything. Restore, which owners and admins can do after typing the zone's name, first stores a safety copy of the zone, then writes back only the records that differ, and reads the zone again to confirm it matches. If Cloudflare refuses a change partway, what was written is undone from the safety copy.
Records added since the backup are kept unless you switch on "Also remove records added since this backup". With it on, the zone ends up exactly as it was backed up.
What a restore will not do
- Write a record Cloudflare manages itself (marked read-only): it is listed as skipped.
- Create a record beside a CNAME of the same name, or a CNAME beside other records, which DNS does not allow. Restore with removal switched on to replace one with the other.
- Guess which of several records at one name became which: the backup's are created and the zone's kept, or removed if you ask.
Without VPS Snaps
Download the backup from your storage and take out the BIND file, then import it in Cloudflare (DNS → Records → Import and export) or at any other DNS host. Importing adds the file's records; it does not remove others.
gunzip -c example.com-*.dns.json.gz | jq -r .bind > zone.txtWhere the data goes
A zone has no server of yours to run anything on, so our worker reads the records through Cloudflare's API and writes them straight on to your storage, in memory only, never keeping them. A restore reads the backup from your storage the same way.