Docs › Operations
Backup and restore
What is backed up
The backup service dumps the whole database every night to ./backups
(next to docker-compose.yml) as depmap-<date>.dump, and deletes dumps
older than BACKUP_KEEP_DAYS (14 by default). The database holds
everything: accounts, workspaces, resources, relationships, history and
encrypted integration credentials.
Two things are not in the dump and must be kept separately:
.env— the passwords and keys. WithoutCREDENTIALS_ENCRYPTION_KEYthe integration credentials in a backup cannot be decrypted, and withoutBETTER_AUTH_SECRETtwo-factor authentication stops working.- The age private key, if you encrypt backups.
Encrypt the backups
Create a key pair on another machine
Install age on your workstation (not on the server) and run:
age-keygen -o inframole-backup-key.txt
It prints the public key (age1…). Keep inframole-backup-key.txt in your
password manager or offline.
Configure the server
In .env:
BACKUP_AGE_RECIPIENT=age1...
Then docker compose up -d. From the next night on, dumps are written as
depmap-<date>.dump.age, encrypted before they touch the disk.
Copy backups off the server
A backup on the same disk does not survive the loss of the server. Copy
./backups elsewhere every day, for example with rsync to another
machine, restic or rclone to object storage, or your NAS. Encrypted
dumps (.age) are safe to store with third parties.
Take a backup now
docker compose exec backup sh -c 'pg_dump -h db -U depmap -d depmap -Fc > /backups/manual-$(date -u +%Y%m%dT%H%M%SZ).dump'
Do this before an upgrade.
Restore
Restoring replaces the data
A restore replaces the whole database with the contents of the dump. Stop and think about which dump you need; everything after it is lost.
Put the dump in ./backups
Copy the file into the backups folder next to docker-compose.yml.
Run the restore
./scripts/restore.sh depmap-20261001T020000Z.dump
# encrypted:
./scripts/restore.sh depmap-20261001T020000Z.dump.age /secure/path/inframole-backup-key.txt
cd /mnt/c/InfraMole # Git Bash: cd /c/InfraMole
./scripts/restore.sh depmap-20261001T020000Z.dump
The script stops the app, restores the dump and starts the app again. The private key is copied into the backup container only for the duration of the restore.
Check
Open InfraMole and verify the data. If you restored onto a new server, use
the same .env as the old one.
