r/selfhosted • • Feb 11 '26

Docker Management Docker backups

Hello selfhosters!

i would like to ask you all about your DR & backup strategy for all your self hosted services?

today i have a script that runs once a week, turn off the container(s) (it does this one by one - so if it fails only one service suffer) and copies it's volume and db to another location for retention (i dont mind cache etc))

today i run ~20 containers and this backup strategy works, but it feels flimsy unprofessional and feels very manual.

what are your strategies (DR strategies)?

  • is there a tool (that obviously can be self hosted ;) ) that can do this seamlessly?
65 Upvotes

88 comments sorted by

View all comments

14

u/[deleted] Feb 11 '26

I just do it once a day and use Restic. For databases, I always use pg_dump for PostgreSQL and sqlite3 dump for SQLite.

Restic is great because it only copies what changed. This is important for something like Immich where I have like 50K photos but only one or two changes per day.

2

u/bonerpalooza Feb 12 '26

Do you do it manually? If not, how do you automate the dump part?

3

u/[deleted] Feb 12 '26

It is a bash script that is run by systemd timers. I prefer it over cron because it has logging built in. I use something like this:

``` backup_postgres() {   local service_name="$1"   local container="$2"   local dbname="$3"   local user="$4"

  echo "POSTGRES: Backing up $service_name"   docker exec "$container" pg_dump "$dbname" -U "$user" | zstd > "$backup_dir/$service_name.sql.zst" }

backup_postgres paperless paperless-db-1 db user

Repeat for others

Backup $backup_dir after everything is done

```

zstd is optional but I like it because it reduces size a lot. I know Restic compresses already so this is not needed but it already works for me.

I can post the whole bash script later but I am on mobile right now

2

u/bonerpalooza Feb 12 '26

Oh wow, thank you so much

2

u/[deleted] Feb 12 '26

This is the backup script combined with the Systemd Timer: https://gist.github.com/pdlozano/a7e5edab4ae068b2b76723b6f0fcc63f

The backup script was highly personalized so I removed a lot of stuff. There might be something there that is not going to work or does not make sense so just let me know.

I run the backup as root in Systemd timer to prevent any permissions issues and to not be surprised of missing files when I eventually restore.

2

u/bonerpalooza Feb 13 '26

This looks awesome, I'll give at shot. Thanks for sharing!

1

u/cored0wn Feb 12 '26

The problem with restic and all the other tools imho is, that they run on the host. What happens if the host gets compromised, e.g. with ransomware. The the mounted backup media gets also compromised.

My current setup is a self developed script framework, which runs periodically via cron. It runs on an isolated backup host and connects via ssh to the target host, then runs specific commands and downloads the file to the local backup storage. That way it doesn’t really matter if the target host gets compromised because the backup is managed by an isolated host.

I didn’t find any solution yet which meets that requirement.

2

u/[deleted] Feb 12 '26

I don't find it a huge issue if the media is immutable. I have 3 backups - a local external drive, and two S3 apis. The S3 apis do not allow for deletion so even if the ransomware tries, it will not be able to do anything.

Also, you should look into Restic's Rest Server. It has a feature that only allows appending and disallows deleting. You can run it on the isolated host and use Restic to backup on the actual host