Keep an encrypted copy away from the server. A backup on the same disk will not help if you lose that disk.
The commands below apply to the Docker Compose setup. Run them from its directory. With a managed database or storage service, use the provider’s backup tools as well.
Make a consistent backup
Schedule a maintenance window and stop every Kaneo API instance that can write to this database. For the single-container setup:S3_PRESIGN_TTL_SECONDS if it differs.
Create a private backup directory and dump PostgreSQL:
silo.env, proxy files, Compose override files, and secret references needed to recreate your setup. Preserve AUTH_SECRET and, when used, NOTIFICATION_SECRET_ENCRYPTION_KEY; the latter is needed to decrypt personal notification credentials. Use your actual Compose filename if it differs.
The custom archive is created by pg_dump. Listing its contents checks the archive structure; a successful restore is the stronger check.
Save uploaded files
Keep Kaneo stopped while saving storage, so the database records and files stay aligned. For the single-node Silo service in this guide, copy its complete data directory while it is stopped.docker compose cp can copy from a stopped container. Include the hidden metadata files:
Test the database restore in isolation
Use a separate directory and Compose project with a new volume. Do not point this test at the live database. Save this ascompose.restore.yml:
Recover the whole instance
- Restore PostgreSQL into an empty recovery database.
- Restore the matching storage backup, preserving bucket names, object keys, and required key material. For a fresh single-node Silo recovery volume, create the stopped container with
docker compose create silo, copy the savedsilo-data/.intosilo:/data/withdocker compose cp, check ownership matches the container’s runtime user, then start it. Do not overlay a recovery copy onto a live storage volume. - Deploy the Kaneo image recorded with the backup. Restore its
AUTH_SECRETand other required settings. - Set the recovery instance’s URLs, database connection, and storage endpoint to the recovery services.
- Before starting it, isolate outbound email, webhooks, and repository integrations at the network level. Integration credentials can be present in the restored database, not only in
.env. - Sign in, compare several projects and tasks with the expected backup state, and open existing attachments. Try a new task and file upload.
- Only after those checks, plan the cutover and restore the intended URLs and delivery channels.