Backups¶
A backup is two things: the database and the data volume (attachments, uploaded files, the licence). One without the other is not a backup of your company.
Nightly backup¶
Run from the folder holding docker-compose.yml, for example from cron at 02:15:
#!/usr/bin/env bash
set -euo pipefail
cd /srv/consoletium
stamp=$(date +%Y%m%d-%H%M)
mkdir -p backups
docker compose exec -T db pg_dump -U erp -Fc consoletium > "backups/db-$stamp.dump"
docker compose run --rm --no-deps -u 0 -v "$PWD/backups:/backup" --entrypoint sh backend \
-c "tar -czf /backup/data-$stamp.tar.gz -C /data ."
# encrypt, then copy off this server
for f in backups/*-"$stamp".*; do
openssl enc -aes-256-cbc -pbkdf2 -salt -pass file:/root/consoletium-backup.key \
-in "$f" -out "$f.enc" && rm "$f"
done
# rclone / aws s3 cp / scp the .enc files to another provider here
find backups -name '*.enc' -mtime +14 -delete
Create the key once with openssl rand -hex 32 > /root/consoletium-backup.key && chmod 600 /root/consoletium-backup.key, and keep a copy in your password manager, not on the server. Keep PAYROLL_ENCRYPTION_KEY from .env with it: employee bank details in a restored database can only be read with that key.
Restoring¶
Try this once before you need it, and then every few months, on a spare machine.
openssl enc -d -aes-256-cbc -pbkdf2 -pass file:/root/consoletium-backup.key \
-in db-<stamp>.dump.enc -out db.dump
docker compose stop backend jobs
docker compose up -d db
docker compose exec -T db dropdb -U erp --if-exists consoletium
docker compose exec -T db createdb -U erp consoletium
docker compose exec -T db pg_restore -U erp -d consoletium --no-owner < db.dump
openssl enc -d -aes-256-cbc -pbkdf2 -pass file:/root/consoletium-backup.key \
-in data-<stamp>.tar.gz.enc -out data.tar.gz
docker compose run --rm --no-deps -u 0 -v "$PWD:/restore" --entrypoint sh backend \
-c "tar -xzf /restore/data.tar.gz -C /data"
docker compose up -d
Then sign in and run Reports › Trial Balance: it should balance and match the figures from before the backup.