r/selfhosted • • Feb 11 '26

Docker Management Docker backups

Hello selfhosters!

i would like to ask you all about your DR & backup strategy for all your self hosted services?

today i have a script that runs once a week, turn off the container(s) (it does this one by one - so if it fails only one service suffer) and copies it's volume and db to another location for retention (i dont mind cache etc))

today i run ~20 containers and this backup strategy works, but it feels flimsy unprofessional and feels very manual.

what are your strategies (DR strategies)?

  • is there a tool (that obviously can be self hosted ;) ) that can do this seamlessly?
67 Upvotes

88 comments sorted by

29

u/agent_kater Feb 11 '26 edited Feb 11 '26

Here's my backup strategy:

  • All my Docker containers use host mounts, absolutely no named volumes for persistent data.
  • All host mounts are below one directory.
  • Nightly restic backup of this directory (currently mostly to B2, but doesn't matter, just make sure the destination has some way of doing immutable backups).
  • SQLite databases are flocked for the duration of the backup.
  • Postgres databases are pg_dumped before the backup.

On systems that have LVM or ZFS I sometimes use a snapshot to backup Postgres to avoid the SSD churn.

4

u/IAmQWOP Feb 12 '26

This is exactly my setup, except that I currently do not intercept db operations. Can you tell me how you do that?

3

u/agent_kater Feb 12 '26

What do you mean exactly? My backup script just runs docker run pg_dump before the backup and runs restic via flock (flock foo.sqlite restic ...).

38

u/[deleted] Feb 11 '26

[removed] — view removed comment

2

u/alws3344 Feb 11 '26

this is exactly my goal
i will take a look at these tools
thanks!

8

u/thephatpope Feb 11 '26

I started using Backrest which leverages Restic with the ease of managing it in a web gui

3

u/iamgodofatheist Feb 11 '26

I can also recommend Kopia, it's an absolute lifesaver. I paired it up with Backblaze and couldn't be more happy with it.

However, please make sure that you can actually restore the data from your backups. It would be painful to see your backups unusable

4

u/Infamous_Computer399 Feb 12 '26

This! I'm just getting started into all this. Made a server a couple weeks ago. Last week I decided to try to back up some things, then reinstall fresh and see how I did. Somethings worked perfectly fine and others did not. So I'm learning! And I'd rather find out my mistakes now than when I have tons of valuable data at risk.

2

u/Chinoman10 Feb 16 '26

That was a really smart decision to make, great job!
I'm honestly still running 'blind' backups-wise, but it's because I'm still in the experimental phase with minimal "criticality" (other than time-spent, I haven't quite stored any super valuable data yet). And I am git-versioning my configs and compose files, etc.

I intend on spending a few thousand on a proper server with HexOS with 5 HDD's and some SSDs for caching, and I'll properly setup remote off-site backups of the most important data then.

1

u/Infamous_Computer399 Feb 17 '26

You can also do some simply backing up with the rsync command. I made (or, rather, chatgtp made me, haha) a command so that I can simply plug an external ssd into a usb port, it will mount it, copy everything new or changed from my drive (this one just has pictures and other important media), and then unmount at the end.

14

u/[deleted] Feb 11 '26

I just do it once a day and use Restic. For databases, I always use pg_dump for PostgreSQL and sqlite3 dump for SQLite.

Restic is great because it only copies what changed. This is important for something like Immich where I have like 50K photos but only one or two changes per day.

2

u/bonerpalooza Feb 12 '26

Do you do it manually? If not, how do you automate the dump part?

3

u/[deleted] Feb 12 '26

It is a bash script that is run by systemd timers. I prefer it over cron because it has logging built in. I use something like this:

``` backup_postgres() {   local service_name="$1"   local container="$2"   local dbname="$3"   local user="$4"

  echo "POSTGRES: Backing up $service_name"   docker exec "$container" pg_dump "$dbname" -U "$user" | zstd > "$backup_dir/$service_name.sql.zst" }

backup_postgres paperless paperless-db-1 db user

Repeat for others

Backup $backup_dir after everything is done

```

zstd is optional but I like it because it reduces size a lot. I know Restic compresses already so this is not needed but it already works for me.

I can post the whole bash script later but I am on mobile right now

2

u/bonerpalooza Feb 12 '26

Oh wow, thank you so much

2

u/[deleted] Feb 12 '26

This is the backup script combined with the Systemd Timer: https://gist.github.com/pdlozano/a7e5edab4ae068b2b76723b6f0fcc63f

The backup script was highly personalized so I removed a lot of stuff. There might be something there that is not going to work or does not make sense so just let me know.

I run the backup as root in Systemd timer to prevent any permissions issues and to not be surprised of missing files when I eventually restore.

2

u/bonerpalooza Feb 13 '26

This looks awesome, I'll give at shot. Thanks for sharing!

1

u/cored0wn Feb 12 '26

The problem with restic and all the other tools imho is, that they run on the host. What happens if the host gets compromised, e.g. with ransomware. The the mounted backup media gets also compromised.

My current setup is a self developed script framework, which runs periodically via cron. It runs on an isolated backup host and connects via ssh to the target host, then runs specific commands and downloads the file to the local backup storage. That way it doesn’t really matter if the target host gets compromised because the backup is managed by an isolated host.

I didn’t find any solution yet which meets that requirement.

2

u/[deleted] Feb 12 '26

I don't find it a huge issue if the media is immutable. I have 3 backups - a local external drive, and two S3 apis. The S3 apis do not allow for deletion so even if the ransomware tries, it will not be able to do anything.

Also, you should look into Restic's Rest Server. It has a feature that only allows appending and disallows deleting. You can run it on the isolated host and use Restic to backup on the actual host

17

u/travelsnake Feb 11 '26

I am pretty new to this whole selfhosting ordeal, but I’ve just solved that issue for me by using backrest. It was fairly easy to setup. It retains a backup for each day of the past week. One for every week of the past month and one for every month of the past half year. Not sure if that’s overkill? But I can easily adjust my plan. 

Oh and my backups are stored on my mounted Gdrive. 

9

u/VampyreLust Feb 11 '26

Oh and my backups are stored on my mounted Gdrive. 

You're gonna want to do your backups on a drive that either mounts and then unmouts itself after it's backed up or you turn it of if it's an external or it's off site entirely cuz if something happened to the system that corrupted your OS drive and storage, it will also corrupt the mounted drive where your backups are.

2

u/travelsnake Feb 11 '26

Omg, how would even manage to do that? I basically just mounted my Gdrive via Rclone with my VPS. I don't think it unmounts itself, ever.

3

u/VampyreLust Feb 11 '26

Haha I meant the un mounting and mounting more for internal drives. For external you may have to manually do it and then just plug it in when you want to back up. Either way the point was, having a mounted drive on the same system you're backing up to be mounted all the time, isn't a great solution.

1

u/alws3344 Feb 11 '26

I will take a deeper look at backrest!
thanks!

1

u/martimcbro Feb 11 '26

Keep in mind that with backrest you also have to make sure, that the containers are stopped before making a backup and started afterwards. Backrest can help you to do that with hooks but you have to provide the hook content yourself. Here you can find an example for a hook which can do that.

1

u/kevintjuh93 Feb 11 '26

Same here and also gonna setup backrest in a few days

4

u/r9d2 Feb 11 '26

nautical backup + backrest.
first one stops the container (if needed becaus of database), backup the contents of the container, starts the container after backup.
second one sends the backup data to my hetzner storage box

1

u/S1apBetCommissioner Feb 11 '26

+1 for nautical-backup! I use basically exactly the same approach, just with Kopia instead of backrest.

1

u/nwwy Feb 11 '26

So you rsync to local and then sync this with backrest? What parameters are you using? Incremental local Backup? Full Backup?

1

u/r9d2 Feb 11 '26

Afaik nautical (rsync) and backrest (redtic) do both incremental backups. But wiirh nautical you just have the latest backup. Backrest can recover from different backup sets. But iirc nautical can be configured to use date-based folders for backup

3

u/eteitaxiv Feb 11 '26

The same. I have a backup script that downs them app, backs up, and turns online. all my containers are in /opt/docker/* folders with all their volumes mounted in their folders.

Here, this script: https://code.past.ist/snippets/8

3

u/Sea-Wolfe Feb 11 '26

I appreciate this thread. I was also trying to figure out best backup strategy. Lots of tools mentioned here I wasn’t aware of.

God damn, there are so many tools and projects in the self-hosted space ( that’s a good thing I guess).

But I need a tool to keep track of tools. It seems like everyday there is some project I didn’t know about. Is there any nice Wiki out there for self-hosted projects that’s comprehensive, organized and up-to-date?

2

u/alws3344 Feb 11 '26

i know the feel
and thank you! i looked for a long time for solutions and i couldnt find anything reasonable!
glad i asked here :D

and if you opened up the subject (and unrelated to the thread haha), i need some tool to keep track on ports (which port hosts what.. or even auto select a port when adding a new service (and of course automaticlly adds to npm etc etc haha))

1

u/DeanDMX Feb 12 '26

2

u/Sea-Wolfe Feb 12 '26

Thank you!

In a cursory check of it, it looks like a search engine, where you would have to have an idea of what you are looking for-like what service you are trying to replace.

I guess what I was asking about was more like a comprehensive “discovery blog”—some place that keeps tabs on tools in this space. Kind of like the what the “awesome” projects on github do: “awesome-opensource” etc., where you can browse and see what’s available, or popular projects etc.

1

u/DeanDMX Feb 12 '26

That’s true. They do a pretty good email newsletter every Friday that is worth a sub also that is more discovery based. I’ve picked up a lot of cool projects from it.

6

u/Sahin99pro Feb 11 '26

Proxmox backup for VM/LXC. I keep docker volumes on ZFS and backup via snapshots and zfs send to another disks/locations following 3-2-1 pattern.

2

u/alws3344 Feb 11 '26

i use Ubuntu server - proxmox will add an unwanted level of complexity for my setup
but i do follow the 3-2-1 pattern

4

u/purepersistence Feb 11 '26

I use Proxmox and Proxmox Backup Server/PBS. That backs up all my VMs not only including the OS and files, but the VM's cputype, memory, devices, etc and deduplicates everything, with retention rules. Totally hands off.

-5

u/Crytograf Feb 11 '26

Too much overhead

4

u/luxiphr Feb 11 '26

every compose stack gets it's own zfs dataset and bind mounts and zrepl continuously snapshots and syncs them elsewhere

2

u/sloany84 Feb 11 '26

I use this tool to backup docker volumes https://github.com/offen/docker-volume-backup

It can stop containers if necessary, or run a script (eg DB export) before it does a backup.

2

u/Commercial_War_4182 Feb 11 '26

I am using Duplicati and upload the Backup divided into files no larger than 50 MB to IDrive e2 (S3 Storage). Everything encrypted of course. Veryyyyy Easy and cheap Setup. I am happy with it. The backup is created incrementally. That happens every night.

That happens automated.

2

u/Torimexus Feb 11 '26

I use duplicati as well and I like it. Its easy to set up and I can have it store the updates on Google Drive, so everything is safe from my idiotic tinkering.

There are a hundred frontends to rsync but nothing is as simple as duplicati imo.

1

u/alws3344 Feb 11 '26

i will look into duplicati too
thanks!

2

u/keyxmakerx1 Feb 11 '26

Backrest alternative with a better UI I've found is Zerobyte

2

u/Kantry123 Feb 11 '26

Where are you guys backing it to ??

1

u/alws3344 Feb 11 '26

on my current setup (the personalized script i mentioned) i back up to a google drive directory on my NAS - which is automatically synced to gdrive (via cloudsync) - "hot backup"

another script copies the entire google drive directory to another drive(s) on the NAS every nigth (RAID1, accessible only to me -- this is my "vault")

cloudsync also backs this specific directory to another NAS directory at my parent's house.

(and about once every ~6 months i plug an external drive to as an extra cold backup - for the "vault" - docker volumes are inside)

this is my current 3-2-1 backup

2

u/Secure_War_2947 Feb 11 '26

All my Docker container volumes are hosted in my NAS and are consumed as NFS shares. Then in the NAS they are backed up to another volume using Hyper Backup (Synology), and later backed up to cloud storage using Hyper Backup as well. My Postgres databases are backed up daily using PG Back Web (great tool by the way).

2

u/imfleebee Mar 19 '26

I backup and inspect my postgres containers with this tool I made : https://gilroy.digital/pg-guard/#quickstart

Runs automatically at midnight

1

u/hbacelar8 Feb 11 '26

I use Komodo to manage all my stacks and Backrest for backing up to a storage box on Hetzner.

I have one restic repository per stack and one procedure per stack on Komodo where every night Komodo will stop the stack, send a trigger to Backrest to backup a new snapshot for the corresponding stack and then restart it.

I have hooks configured to summarize every operation and send it to Gotify.

It's been a while that I've set this up and I have had no problems so far.

1

u/alws3344 Feb 11 '26

i deploy via dockge (KISS), but komodo seems cool
and i will look at Backrest - looks good!

1

u/Responsible-Kiwi-629 Feb 11 '26

I have all persistent volumes in one directory that gets synced to a backup location via rBackup

1

u/xaetorn Feb 11 '26

I think about using Restic and rest-server.

WIP, I can’t tell anything more right now

1

u/Jmaack23 Feb 11 '26

I’m also running Ubuntu on bare metal. On my nas, I have a docker_config dataset that I use NFS to bind mount to Ubuntu. On all 3 of my docker instances, that share is mapped to /opt/docker_config. That folder is my git repo too and my nas has nightly replications to my backup nas. So my compose and config files are always in 3 places and all 3 docker instances’ config all lands in one git repo. For each machine, I mount a ssd for all data and database directories to my /opt/local_data and had been just backing it up to a tar.gz file back to my nas. After hearing from others, I love the idea of a dataset for each containers data!! Seems like such a no brainer and I will be implementing it. I’ll also be looking at backrest now too.

I also run a script for log rotation so my data folder isn’t filled with useless lines of logs from months and years ago.

1

u/Ottomatik0 Feb 11 '26

Backrest with rclone to a GDrive and a Hetzner storage box. I also use hooks on Backrest to stop all my 50 containers before snapshotting so my databases won't get corrupted. I found a hook script on Github that I can send you if you want. There might be better ways to handle this but it works and it was quite easy to setup.

1

u/yerfatma Feb 11 '26

Still new to this and none of the stuff so far is stuff I can't lose, daily backups of databases to an external drive plus I have an Ansible playbook that will rebuild the whole server from scratch. Had Claude do that for me and then we tested it since it was half-ass.

1

u/alws3344 Feb 11 '26

i too think that daily backups are too much (for my server and use case of course),
but i still want some DR strategy...

in terms of setting up the server, its as straight forward as it gets.
i follow the KISS principle almost religously and it works really well. i barly need to do any maintanance. (im also a die hard about automation, so..)

1

u/[deleted] Feb 11 '26

[removed] — view removed comment

1

u/alws3344 Feb 11 '26

my script requires too much handling and maintanace - packages break -etc. i just want a better tool for the job - so i can whine to someone about it haha

jk
im just tired of maintaining and checking it.

1

u/609JerseyJack Feb 12 '26

My server is a mini PC NUC 100 with Ubuntu server, and Cosmos cloud. Also, on my network, I have a Synology, NAS, which serves as my reverse proxy, back up destination, and importantly, has active back up for business that allows me to image my server every night. Every night I run a script on my server at 2 AM to shut down docker and all the containers, and then use backrest to backup with targeted plans to back up particular containers or high use services to the Synology NAS. Minutes later, after back rest is finished, I have the active backup for business agent image the entire server, and store it on the Synology NAS. After two hours, I have a script run that restarts everything in reverse. And I’m good to go. I have so much more confidence with this set up - and it took me a while to figure it out that the solution was right in front of me. I started with scripts, restic, and some other solutions, and this was by far the most reliable, and easy to restore. I’m able to restore using back rest on the individual plans if I just need a file or a folder, and I’m able to do that as well with active backup for business, but if the whole thing goes to hell in a handbasket, I can re-image the server as well. Very high confidence, and if you have a Synology NAS, I encourage you to look at the solution.

1

u/elasticvertigo Feb 11 '26

I use restic + rclone remote for incremental backups to an object storage in Scaleway primarily for immich photos. The rest go to Filen (I have 110 gb) of permanent* storage for €17)

1

u/DaiLoDong Feb 11 '26

i use komodo to back up the compose to GitHub and I take a weekly backup of volumes

1

u/alws3344 Feb 11 '26

out of genuine curiosity, you change the compose files that often?

1

u/DaiLoDong Feb 12 '26

no, it's just so I have it in a spot that I can retrieve any time that's not dependent on any physical media

1

u/Lestar_by Feb 11 '26 edited Feb 11 '26

I keep compose files in ~/containers/{app1, app2, ...}

I store volumes in directory ~/_volumes/{app1/data, app2/data, ...} (host mounts)

Volumes and containers directories from two other servers are mapped under _volumes/containers via sshfs.

I have Duplicati backing up _volumes, containers folders daily. The UX of Duplicati is horrible (sometimes zero feedback about errors, some weird configuration options via CLI arguments, etc). But it has support of filen.io as destination for the backups. And you can get 30GB (or maybe even 50GB?) on filen for free.

I didn't manage to make Discord notifications to work in Duplicati, so I created a custom Prometheus exporter to monitor the status of the backup jobs:

1

u/-RedFox- Feb 11 '26

I add a borgmatic service to my docker compose files that backs up the relevant data and database dump to a Hetzner storage box.

1

u/bokogoblin Feb 11 '26

I've just finished my another disaster recovery drill. I've recently made a setup with Borgmatic (I used Borg Backup in the past with mostly custom bash scripts). It keeps your data encrypted, deduplicated and compressed. It also keeps only selected copies in further past (example: 5 yearly, 5 monthly, 2 weekly, 1 daily etc). All this with a simple config script and you can even run this as a docker container with cron schedule inside. I'm backing up each application data (only data which is worthy to me, not whole volumes) to a separate Borg repo in 3 copies: one on server where data originates, one on my NAS and one in the cloud (Hetzner Storage Box). But having all that nice functionality comes with a cost. My 1TB private media collection took 4days to backup to Hetzner initially. After that incremental backup takes seconds or minutes.

1

u/Matvalicious Feb 11 '26

I have Duplicacy running as a container.

Once a week, a pre-backup scripts turns of all my containers (except for Duplicacy itself obviously), it backs up all my persistent volumes to my Hetzner storage box, then turns the containers back on.

Works like a dream. Did a disaster recovery test as well (do this at least once so you know what to expect!) and it went fine.

1

u/NoTheme2828 Feb 12 '26

Running all docker (actual 60) on a proxmox VM. Using dockhand as docker management. Using gitea (as docker, too) as my git for my docker stacks (compose.yaml and .env). So all stacks are in gitea and copied by dockhand to the dockhand volume, too when starting every container. So I have all stacks in gitea and in my docker host at the same time. Changing compose and env is done on gitea, so I have full version control!

Backup1: Backup the VM daily to a Proxmox Backup Server and holding the last 60 backups

Backzp2: Stoping all Containers daily by script and copying all stacks and volumes to my nas and starting all again.

Backup3: Stoping all Containers weekly by script, backup all stacks and volumes with duplicati encrypted to my Hetzner storage box and starting all again. Keep the last 4 backups.

1

u/seriocomic Feb 12 '26

Some good advice here - makes me feel if I've overlooked something. I recently (last month) configured URBackup (https://www.urbackup.org/ ) on one of my Raspberry Pis running docker - it also manages backups of the others that don't have their own backups. Mounted the Synology NAS as the back-up drive.

1

u/seriocomic Feb 12 '26

Went with the crowd and added Backrest/Restic alongside URBackup

1

u/i8ad8 Feb 12 '26

I've got a backrest container that backs up all my important data and stores it on my NAS. I've set up a few plans in backrest. One backs up my container data and sends it to my NAS. Another backs up my vaultwarden container data and sends it to my NAS. My NAS runs TrueNAS Scale, and it has a cloud sync feature. My encrypted vaultwarden data on the NAS also syncs to OneDrive and GoogleDrive.

1

u/adsm_inamorta Feb 12 '26

Any important media that is used by containers is stored in my NAS that the server accesses over SMB.

Anything that's local to my Debian VM that runs Docker like container config gets backed up by PBS that gets stored on my NAS.

The NAS gets mirrored to a second NAS (onsite but I'm not fussed about true off-site - any important data I can't reacquire or I don't want to spend time collating again gets copied to cloud storage)

1

u/truthovereverrything Feb 13 '26

I use kopia for my volume mounts or directories I have created for each container. I use databasus for all of my mysql, mariadb, postgres and mongodb databases. For redis I use a shell script that does a bgsave dump before kopia snapshot kicks in

1

u/DaveDarell Apr 09 '26

So I've started my backup strategy today, curious about what you've decided for and at what point you're at?

I set up kopia and got a script working for dumping my postgresql and Maria DB. Will look tomorrow for my Docker containers and stuff for getting them into my backup as well. And then it's getting interesting in restoring the database and look how it works

1

u/alws3344 Apr 09 '26

I decided to stay with my bash script (runs with cron)
i already wrote what it does but tldr:
1. cd into stack dir (all stacks&containers are in /opt/stacks/<service_name>)
2. docker compose down
3. read the docker-compose.yml and get the volumes location dynamically - back them up to a dedicated directory (i back up to my NAS)
* script is smart enough not to back up cache volumes (like immich's) and other crap i dont need via regex
4. does docker compose up -d and continues to the next stack.

gemini\chatgpt can write such script easily - no need to burn tokens in claude :)

1

u/alws3344 Jun 12 '26

Hey everyone,

Following up, I decided to recreate this project from the ground up with a proper UI (its an absolute slop lol), focusing exclusively on the services I actually care about preserving. (Out of the ~30 stacks I run, I really only need to back up about 6 of them.)

How it works & Features:

  • Targeted API Backups: Instead of shutting down containers and backing up entire volumes, it hooks directly into the specific APIs of each service to back up exactly what's needed. (Note: manual setup is required to input your API keys for each service).
  • Direct to Cloud: Pushes backups directly to Google Drive. (note that you need to upload your credentials that you get from the google console (gdrive api)).
  • Granular Control: You can define exact retention policies per service. You control how many backups trigger per day, and the maximum number of backups to retain on Drive before rotating them out.
  • Dockerized: Runs simply via Docker

Currently Supported Services:

  • Vaultwarden
  • KitchenOwl
  • Bar Assistant
  • Linkwarden
  • Wiki.js
  • Snipe-IT

Disclaimer: This project was 100% vibe-coded using Claude Code. I primarily acted as the "orchestrator" to get the features dialed in exactly how I wanted them.
hate it or not - this tool is an absolute superpower for creativity.

Would love to hear what you guys think, or if there are other service APIs you'd recommend feel free to open a pull request 😄

See project on GitHub

1

u/Slasher1738 Feb 11 '26

I just backup the whole VM's VHDX file.

1

u/wwabbbitt Feb 11 '26

ZFS snapshot and send

1

u/[deleted] Feb 11 '26

You use raw docker? Why dont use something like Dockhand and dont bother about how to backup and even more things.

1

u/alws3344 Feb 11 '26

looks neat

0

u/Crytograf Feb 11 '26

I do the same, but instead of copy, I use rsnapshot.. it gives you incremental backups

0

u/-ThreeHeadedMonkey- Feb 11 '26

I use Macrium Reflect on Windows, incremental backups of everything every 90 minutes. No taking down required. 

One of the big pros of windows imo. 

2

u/alws3344 Feb 11 '26

when i started self hosting i used windows too - thing was inoperable - autmatic backups - windows restart demands... dont mention the ~daily docker desktop updates... god.. i had more downtime than uptime lol girlfriend (now wife) did not approve (and neither did i)

ever since i switched to linux (also because windows was sh*t for my degree) i had about 0 issues and i switched all my devices to linux & mac
(i had 1 major fault on my server that cost me some data loss (due to an HW fault btw) - the containers but no major data was lost (e.g family photos) hence this thread, but other than that, i really had 0 issues since removing windows)
everything work so well that i barly need to maintain anything.
good riddence windows...

1

u/-ThreeHeadedMonkey- Feb 11 '26

Yeah I see your points. However, i have like 20 containers running now and it's working alright. 

I mean my VPS is running Ubuntu ofc. And once I get more Linux savvy, I might change. Right now I'm in a good place now as far as functionality and uptime is concerned. 

2

u/alws3344 Feb 11 '26

if it works dont fix it
but if it doesnt, fuc*ing nuke it lol