Backup, recovery, and state persistence

Chapter 66 established that broker state is ground truth and local state must reconcile against it. This chapter covers what "local state" needs to actually survive — disk failure, VPS loss, accidental deletion — independent of the broker relationship entirely.

What actually needs backing up

DataWhy it mattersRecovery source if lost
Trade journal (ch 89)Tax records, performance historyIrrecoverable if lost — this is the one thing with no broker-side backup
Strategy state machine state (ch 88)Resume mid-position correctlyReconcilable from broker positions/orders, but loses your *reasoning* context
Historical price data (ch 30)BacktestingRe-fetchable from broker API (slow, rate-limited)
Config, credentialsBot operationShould already exist elsewhere (password manager, chapter 6)
Instrument master cache (ch 21)Symbol resolutionTrivially re-fetchable, don't bother backing up

The trade journal is the one genuinely irreplaceable asset — treat its backup with the seriousness of financial records, because for tax purposes (chapter 97) it effectively is one.

Simple, effective backup pattern

#!/bin/bash
# backup.sh — run daily via cron/systemd timer, after market close
DATE=$(date +%Y%m%d)
tar -czf "backups/algo-bot-backup-$DATE.tar.gz" \
    data/journal.db data/market.db .env config.py

# Upload offsite — never rely solely on the same VPS disk that could fail
aws s3 cp "backups/algo-bot-backup-$DATE.tar.gz" s3://your-backup-bucket/ 2>/dev/null || \
    rclone copy "backups/algo-bot-backup-$DATE.tar.gz" remote:algo-bot-backups/
# systemd timer, daily after market close
[Timer]
OnCalendar=*-*-* 16:00:00 Asia/Kolkata

Recovery drill — test this before you need it, not during a crisis

def recovery_checklist():
    """Run manually after restoring from backup, before resuming trading."""
    steps = [
        "1. Verify journal.db integrity: sqlite3 data/journal.db 'PRAGMA integrity_check;'",
        "2. Re-authenticate with broker (chapter 10)",
        "3. Reconcile positions against broker (chapter 66) — trust broker, not restored local state",
        "4. Reconcile pending orders against broker order book",
        "5. Verify kill switch and heartbeat are functioning before resuming live trading",
    ]
    for step in steps:
        print(step)

An untested backup is not a backup — actually restore from one of your backup files periodically (e.g. monthly, to a separate throwaway directory) and confirm the recovery steps work, rather than discovering a corrupted or incomplete backup during an actual emergency.

Encrypt backups containing credentials or PII

If your backup includes .env or anything with account details, encrypt the archive before uploading offsite:

gpg --symmetric --cipher-algo AES256 "backups/algo-bot-backup-$DATE.tar.gz"

Next: 096 — Taxation basics for algo traders in India