Backups
deploy/scripts/backup.sh writes a database dump and the files to a
restic repository:
RESTIC_REPOSITORY=<repository> RESTIC_PASSWORD_FILE=<file> deploy/scripts/backup.sh- The database is dumped with
pg_dumpinto/srv/skillpouch/backups; local dumps older than two days are deleted. - The dump and the files folder go to restic. Files never change once stored, so later backups are small.
- restic keeps 14 daily, 8 weekly and 12 monthly snapshots.
Run it every night with a systemd timer or cron job.
What isn’t backed up
Section titled “What isn’t backed up”pepper_keyandjwt_signing_key. Keep them offline, apart from the backups (Configuration). A backup without them can’t restore a working server.- Files in a bucket (
BLOB_DRIVER=s3). Back the bucket up with the provider’s tools orrclone.
Restoring or moving by hand
Section titled “Restoring or moving by hand”On the new machine:
- Set it up as usual (Cloudflare Tunnel or VPS).
- Copy
deploy/secrets/anddeploy/env/from the old machine or your offline copy. - Attach the old data volume, or restore the files folder and the database dump from restic.
- Deploy, then point your hostname at the new machine.
For a move without downtime, see Moving to a new server.