.env, recreate the API container, verify a backup, and then retire the old key.AWS
Enable one runtime AWS identity for resource backups and restores.
AWS is optional. Enable it only when a resource backup policy uses AWS S3. Configure the API process and restart it:
Temporary AWS sessions are not supported because they are not maintainable as static installation configuration. Scope the identity to the required buckets, prefixes, object versions, and KMS keys. Towbar shows AWS only when all enabled values pass startup validation and never returns the credential in the UI or API.
Confirm permissions with a real resource backup and restore before relying on the configuration. Rotate the key in
Last modified on September 10, 2026


