Skip to content
BotServBotServ
DockerVolumesBackupRestoreRestic

Secure Docker Volume Backups

Back up Docker volumes with tar, Duplicati, and Restic. Backup strategies and restore procedures.

S

schutzgeist

3 min read
Secure Docker Volume Backups

Backing Up Docker Volumes Safely

What This Article Covers

  • How to back up Docker volumes
  • Which tools work best
  • How to restore from backup
  • Incremental and automated backups
  • Offsite and encryption options

Introduction: Backing Up Docker Volumes Safely

Docker volumes typically store critical data: databases, configurations, models, uploads, and logs. Running containers without a backup strategy risks data loss from container failures, disk corruption, or accidental deletion. A solid backup should be regular, automated, tested, and stored in a secure location.

This article shows how to reliably back up and restore Docker volumes.

Key Concepts

  • Volume: Persistent storage in Docker.
  • Bind Mount: Host directory mounted into a container.
  • Backup: Copy of data for restoration.
  • Restore: Recovering data from a backup.
  • Snapshot: Point-in-time state of data.
  • Incremental: Backing up only changed data.
  • Offsite: Backup stored at an external location.
  • 3-2-1 Rule: Three copies, two media types, one external.

Manual Backup with tar

docker run --rm -v quell-volume:/data -v $(pwd):/backup alpine \
  tar -czf /backup/volume-backup.tar.gz -C /data .

Manual Restore

docker run --rm -v quell-volume:/data -v $(pwd):/backup alpine \
  tar -xzf /backup/volume-backup.tar.gz -C /data

The volume must exist beforehand.

Identifying a Single Volume

docker volume ls
docker inspect quell-volume

Stopping Running Containers Before Backup

For consistent database backups, stop containers or use the database’s native backup tools:

docker stop datenbank
docker run --rm -v datenbank-volume:/data -v $(pwd):/backup alpine \
  tar -czf /backup/db.tar.gz -C /data .
docker start datenbank

Backup Script

#!/bin/bash
BACKUP_DIR=/pfad/zu/backups
DATE=$(date +%Y%m%d_%H%M%S)
VOLUME=$1

docker run --rm -v "${VOLUME}:/data" -v "${BACKUP_DIR}:/backup" alpine \
  tar -czf "/backup/${VOLUME}_${DATE}.tar.gz" -C /data .

Automation with Cron

0 2 * * * /home/benutzer/backup-volume.sh datenbank-volume

Restic for Incremental Backups

Restic is excellent for incremental, deduplicated, and encrypted backups.

docker run --rm \
  -v datenbank-volume:/data:ro \
  -v /pfad/zu/repo:/repo \
  restic/restic init -r /repo

docker run --rm \
  -v datenbank-volume:/data:ro \
  -v /pfad/zu/repo:/repo \
  -e RESTIC_PASSWORD=meinpasswort \
  restic/restic -r /repo backup /data

Duplicati

Duplicati offers a web interface, incremental backups, encryption, and cloud storage support:

services:
  duplicati:
    image: duplicati/duplicati
    volumes:
      - /pfad/zu/backups:/backups
      - /var/lib/docker/volumes:/source:ro
    ports:
      - "8200:8200"

Offsite Backup

  • S3-compatible object storage
  • SFTP servers
  • rsync.net
  • B2 Backblaze
  • Nextcloud

Restic can target S3 directly:

restic -r s3:https://s3.example.com/bucket backup /data

Restoring from Restic

docker run --rm -v datenbank-volume:/data -v /pfad/zu/repo:/repo -e RESTIC_PASSWORD=meinpasswort \
  restic/restic -r /repo restore latest --target /data

Testing Backups

  • Regularly restore a backup to a temporary volume
  • Verify the application starts successfully
  • Open important files to check data integrity
  • Verify backup chains for consistency

Tips

  • Set up automated backups
  • Define retention policies for how long to keep backups
  • Store backups offsite and encrypted
  • Stop containers before backup or use application-aware backup methods
  • Monitor backup logs
  • Document emergency restore procedures

Common Pitfalls

  • Container running during backup: Results in inconsistent data.
  • Volume not found: Volume name misspelled.
  • Permission issues: Backup created as root, restored as a different user.
  • Untested backup: Emergency restore fails when needed.
  • Disk space: Backups fill up the drive.
  • Forgotten encryption: Password not recorded.

Further Reading and Resources

FAQ: Docker Volume Backups

Can I just copy Docker volumes? Running containers should be stopped first.

How often should I back up? At least daily for important data, more frequently for databases.

Are tar backups sufficient? For simple cases, yes. For larger setups, incremental solutions like Restic work better.

Where should backups be stored? At least at an external location, ideally two.

How do I restore a volume? Unpack into an existing volume or create a new one.

Sources and Further Reading

Summary: Backing Up Docker Volumes Safely

Docker volumes are the foundation of persistent data. A solid backup strategy combines regular, consistent, tested, and offsite-mirrored backups. Simple tar backups work for basic needs, while Restic or Duplicati suit professional setups. Stop containers before backup or use application-aware backup methods. Testing restores regularly means you’ll be ready when an actual failure occurs.

Back to Blog
Share:

Related Posts