Home / Alt manpages / vault-migrate(1)

  • vault-migrate(1)
  • User command
  • linux

Move Files into a Vault and Delete the Originals with vault migrate

vault migrate stores files like add does, then removes each original and any directories left empty. This guide shows the safe way to run it, including the confirmation prompt and what --yes changes.

Allow about ten minutes. You need a key and an initialised vault. Read the whole page before your first run, because the originals really are deleted.

1. Understand what differs from add

It works like vault-add(1) but deletes each original once it is stored, then any directories left empty. Directories still holding skipped files stay. A URL cannot be migrated.

2. Run it and read the prompt

$ vault migrate ./old-projects archive

Before storing anything it lists the vault names that would be overwritten and asks for confirmation on the terminal. Read that list. It is your only warning that existing vault files are about to be replaced.

3. Know the no-terminal behaviour

With no terminal, such as in cron or a pipe, the answer is no and nothing changes. That is the safe default, and it means a script fails loudly instead of quietly destroying data.

4. Skip the prompt on purpose

$ vault migrate --yes ./old-projects archive

Warning

--yes overwrites without asking and the originals are deleted afterwards. Try the command with add first, list the result, and only then migrate.

5. Verify before you trust it

$ vault list archive
$ vault get archive/old-projects/notes.txt -o /tmp/check.txt

A retrieved copy that matches what you expect is your proof. Keep a separate backup of the key file too, since the originals are gone. Overview: vault(1).

Done means

  • The confirmation list was read, not skimmed.
  • A test file was retrieved from the vault and checked.
  • --yes was used only in a scripted run you have already tested.
  • The key file is backed up somewhere other than the machine that held the originals.