Each backup is encrypted (GPG, AES-256) with
BACKUP_PASSPHRASE before it leaves the runner, because the repository is public. Without the passphrase the file is useless, so keep it in the password manager as well as in GitHub.
Restore
Practice this on a scratch Supabase project first. Restoring over production replaces live data; decide it with the President and record it in the minutes.1
Download and decrypt
Download the artifact
sal-backup-YYYY-MM-DD, then:2
Restore into the target database
Use the target project’s connection string (Project Settings → Database):
3
Check
Sign in to a Nexus pointed at the target, open a member, an event and the ledger, and compare row counts with the source.