Skip to content

Backing Up Your Server

Approximate Time: 30 minutes


What to Back Up

It isn't important to back up the entire operating system.

If the server needs to be rebuilt, such as when changing providers or in the case of a hardware failure, you'd follow the steps in this guide again and reinstall things like fail2ban and docker as you did.

Presumably your code is checked into git, so backing the code up (if you were deploying your own app and not miniflux) isn't important either.

The only things that you do need to back up are files created on the server (such as user uploads) and your databases.

Where to Store Backups

A commonly cited rule for backups is the 3-2-1 rule: 3 copies of your data, 2 different kinds of storage, 1 offsite.

This means we want the following for things like our Postgres data:

  • Our live data in the database. Our first onsite copy.
  • A second copy of the data locally, useful for local restores, our second onsite copy.
  • A third copy stored on a different service, useful if we lose access to our server or even Hetzner account.

Backblaze B2

restic

We are going to use a program called restic to store backups on Hetzner's block storage:

sudo apt install restic

Then we will create a random password:

openssl rand -base64 32 > ~/.restic-password
chmod 600 ~/.restic-password
cat ~/.restic-password

Save this Password!

This password will be used to encrypt our backups, without it our backups are useless!

Save this file in your password manager right now.

TODO: block service

Simple Backup Script

Create a directory named ~/backups and place this script at ~/compose/backup.sh

#!/bin/sh
set -e
export RESTIC_REPOSITORY=sftp:user@backup-host:/restic
export RESTIC_PASSWORD_FILE=$HOME/.restic-password

# back up our Miniflux database to a local file
sudo docker compose exec -T db pg_dump -U miniflux -Fc miniflux > ~/backups/miniflux-$(date +%F).dump

# CHANGE: anything that you want to back up should wind up in this ~/backups directory. More databases? Locally created files?

# back up everything in ~/backups to our restic repository
restic backup ~/backups

# optional: don't keep backups forever
restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --prune

# clean up old backups from disk
find ~/backups -name '*.dump' -mtime +7 -delete

Verifying Backups

It is important to verify the backups work as intended.

On the server: run ~/backup.sh On your laptop: run

Scheduling Regular Backups

crontab

confirming cron is running