Recover work
Inspect retained worktrees and transfers before restoring or cleaning them up.
What Outpost keeps
Section titled “What Outpost keeps”When a run stops before its changes can be integrated, inspect the work Outpost retained. Use the recovery inventory to locate worktrees, downloaded transfers and backups before restoring or removing anything.
| What | Where | Kept when |
|---|---|---|
| Worktree | .outpost/workspaces/ | The run failed, integration conflicted, or the worktree is dirty, detached or holds ignored files (node_modules, copies). |
| Remote transfer | .outpost/recovery/ | Changes from a cloud sandbox could not be applied to your checkout. |
| Conversation | .outpost/conversations/ or the agent’s own store | After each turn and on failure. See Conversations. |
| Workflow progress | .outpost/storage/ or your transport | After each finished task. See Durable runs. |
A retained worktree is an ordinary Git worktree on its branch: open it, commit what you keep and merge the branch.
Read the error
Section titled “Read the error”recoveryDetails() returns what Outpost attached to the error: branch, directory, commits, transcript and logReference when available.
Two failures also name their location in error.details. Errors lists every code.
API reference: recoveryDetails.
When the run itself also failed, the synchronization error arrives inside an AggregateError.
Restore a remote transfer
Section titled “Restore a remote transfer”A transfer holds two sides: previous, your checkout before the sandbox’s changes, and incoming, the sandbox’s changes. Restore one side into a new directory, never over your checkout.
Inspect
Section titled “Inspect”API reference: RecoveryInspectionOptions.
The command exits with status 1 when the inventory is incomplete.
Verify
Section titled “Verify”$TRANSFER is the directory from details.recovery. --checksums compares each file with the transfer’s manifest; --max-bytes bounds the bytes hashed. --restorability rebuilds the commits and patches in a temporary clone of --repository. The command exits with status 1 when a check fails.
Restore
Section titled “Restore”This prints the plan. Run it again with --apply to create the checkout: a clone of your repository detached at the restored commit, with the side’s patches and files applied and no origin remote.
API reference: RecoveryRestoreOptions.
The destination must not exist and must be outside the repository, its Git metadata and the transfer. The transfer stays in place.
Compare and integrate
Section titled “Compare and integrate”The work is now the outpost/recovered branch of your repository. Review it and merge it like any other branch.
Recover from code
Section titled “Recover from code”Each command has a function. planRecoveryRestore() returns the plan; restoreRecoveryTransfer() checks that nothing changed since and applies it.
inspectRecovery({ transporter }) lists the objects of a transport instead of a local repository.
Archive a transfer remotely
Section titled “Archive a transfer remotely”archiveRecovery() verifies a transfer and uploads it through a transport. materializeRecoveryArchive() downloads it on any machine and checks its checksums again.
Keep reference (a key and a revision) to find the archive. Pass staging as --directory to outpost recovery restore, with a clone of the source repository.
Release a stopped run or race
Section titled “Release a stopped run or race”A crashed workflow or candidate race keeps ownership of its checkpoint. After stopping the old process, release it with recoverWorkflowCheckpoint() (Durable runs) or recoverSpeculation() (Competing candidates).
Clean up afterwards
Section titled “Clean up afterwards”Limits
Section titled “Limits”- Checksums detect damage against an unsigned manifest; they do not prove who produced the transfer.
- Restorability covers commits, the bundle and patches, not submodules or external dependencies.
- A transfer is restorable only once the host backup ran: a synchronization that failed during download or validation leaves no
state.json, and the restore plan rejects it. - A lock PID or recorded activity is an observation. It does not prove that a remote process has stopped.
- A worktree reported
cleancan still hold ignored files, such as copies ornode_modules. - An archive holds recovery files, not the repository: restoring still needs the source repository.
API: recoveryDetails · inspectRecovery · verifyRecoveryTransfer · planRecoveryRestore · restoreRecoveryTransfer · archiveRecovery · materializeRecoveryArchive.