6
submitted 1 year ago* (last edited 1 year ago) by grimer@lemmy.world to c/selfhosted@lemmy.world

Just curious if there is an easy way to back up my docker-compose.yaml and .env files. I have the following directory structure for my containers:

-docker
  -<name of container>
    -.env
    -docker-compose.yml

I'd like to copy those two files for each container folder but no other subfolders that may also be in the container folder (config, data, etc). I've been trying to get my restic backups to do it but I just can't figure it out.

Is there a better way? I'd like to have backups in case my entire server dies.

UPDATE: Thank you all for the advice, I'm giving git a try and so far so good!

top 13 comments
sorted by: hot top new old
[-] RegalPotoo@lemmy.world 12 points 1 year ago* (last edited 1 year ago)

Check them into Git, but be cautious about credentials that might live in the env files that you don't want to expose if you end up making the repo publicly available.

[-] grimer@lemmy.world 1 points 1 year ago

That is an option I've been thinking about but I've never used it, I'm not a dev. Maybe I'll look at it more seriously since it does sound like what would work best, I'd really apprecieate the versioning. Thanks!

[-] shadybraden@programming.dev 3 points 1 year ago

Definitely worth a shot.

One thing I do to prevent stuff from getting into a public git repo is:

  • In the git repo, make a file called .gitignore then add the line .env to it. Then git will ignore any file named .env
  • edit compose files from a computer that is separate from the one that gets secrets. I have my desktop setup to push to github. Then I make a change, then simply run `git pull on my server to download the changes.
  • make the .env only viewable by root (you'll have to use sudo nano) by running sudo chmod 600 .env && sudo chown root:root .env

Docker compose in git. Env in 1password or whatever password manager you use. Most support uploading a raw file.

Keeping backup of .env means exposing sensitive creds ?

[-] grimer@lemmy.world 3 points 1 year ago

In my particular case I only have a few .env files and they don't have any credentials in them. This is mostly for the docker-compose files.

[-] shadybraden@programming.dev 2 points 1 year ago* (last edited 1 year ago)

You can specify a folder in your files for configs, and a different one for the compose and env:

- config
   - <container_config>
- docker
  - container 
      - compose.yml

Edit: then you can map your volume not to ./config:/config but instead to /config/containerName:/config

[-] MangoPenguin@lemmy.blahaj.zone 2 points 1 year ago

Backups are encrypted so it shouldn't be an issue.

[-] HelloRoot@lemy.lol 1 points 1 year ago

what about a local, encrypted backup

It’s like you have secrets that you pull in to build your .env which should only be used by the stuff that needs it and it’s not shared.

I’m assuming this is a production backup and the idea that someone has a prod .env file gives me the Willies.

Id want to change all the cards.

[-] shadybraden@programming.dev 3 points 1 year ago

I have mine in git! I have:

-docker
  - .env
  - <thing name>
      - dockers-compose.yml

Then using docker compose --env-file ../.env -v up -d it uses the above .env file. (../ means up one folder)

For more details and a bunch of my compose files checkout my repo! https://github.com/shadybraden/homelab/tree/main/docker

[-] MangoPenguin@lemmy.blahaj.zone 2 points 1 year ago

I mean... just back them up like any other file. If you want them and nothing else, then do an exclude all and then include after for those files.

But you also need to backup the rest of the data, so I'm not sure why you'd want to exclude all the other folders.

[-] dohpaz42@lemmy.world 1 points 1 year ago

As a Mac user, I like Time Machine for backups. It’s not perfect, but it gets the job done. There is a Linux version.

Nb. I’ve not used this particular software, so YMMV.

this post was submitted on 30 Mar 2025
6 points (75.0% liked)

Selfhosted

62043 readers
1094 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS