3. Backups
In short. The app makes a backup on the server every 6 hours. A backup on the same disk is lost if the server is lost. On this page, you send an encrypted copy of each backup to your backup machine each day. Then you test a restore. At the end, you have backups in two places, and you know that a restore works.Each command block says where to type it: on the server, on your computer, or on the backup machine.
Step 1. Create the backup encryption key
Do this step on a trusted machine that hasage installed. Do not use the server or a
machine that agents use.
-
Create the key:
-
The command shows
Public key: age1.... Copy the part that starts withage1. You need it in Step 2. -
Keep the file
sesame-backup.agekeyoffline in two places: on an encrypted USB drive and in your password manager. - Keep it with the session secret from First deploy, Step 3.
sesame-backup.agekey on the server. If you lose it, you cannot
decrypt the copies on the backup machine.
Step 2. Turn on encryption on the server
-
On the server, create the file for the public key:
-
Write the public key from Step 1 into the file:
-
Turn on the backup timer:
systemctl list-timers sesame-seal-backups.timer shows the
time of the next run.
Step 3. Let the backup machine read the encrypted copies
-
On the backup machine, create a key without a passphrase. The key has no passphrase
because the copy runs without a person.
-
On the backup machine, show the public key. Copy the line that it shows:
-
On the server, open the key file of the backup account:
-
Write one line: the start below, then a space, then the public key that you copied. Save
the file and close the editor.
-
On the backup machine, get a copy of the repository:
-
Copy your list of allowed signers from your computer to the backup machine. Use the same
path:
~/.config/sesame/allowed_signers. The list is from Prepare the server, Step 8. -
On the backup machine, create the file
<repo-folder>/deploy/.deploy.envwith these three lines: -
On the backup machine, create the folder for the copies:
-
On the backup machine, connect to the server once to record its fingerprint:
-
Compare the fingerprint with the one from
Prepare the server, Step 12.
If the two are the same, type
yes. If they are different, typenoand stop. Afteryes, the server shows an error and closes the connection. This result is correct, because the backup account can only copy files. -
On the backup machine, in
<repo-folder>, get the release tags and copy the backups once:For each new file, the command showsdeploy: pulled <file name>. The first time, the list can be empty if the timer did not run yet. -
On the backup machine, find the folder of
task:The command shows a path such as/usr/local/bin/task. The folder is the part before/task. -
Open the schedule of your user on the backup machine:
-
Add these two lines. Make sure that the
PATHline contains the folder from item 12. If it does not, add the folder and a:at the start of the value. In the second line, replace<repo-folder>with your path. Save the file and close the editor.The copy runs each day at 04:15. Its messages go intosesame-backup-pull.login your home folder.
SHA256SUMS in the same folder. When you do not need an old copy, delete
it yourself.
Is it working?
-
On your computer, make a backup now:
The command shows a file name such as
sesame-20261001T040000Z.db, andsesamectl: sealedlines for the new files. -
On the backup machine, copy the backups:
-
Look in
/srv/sesame-backups. It containssesame-20261001T040000Z.db.ageandsesame-20261001T040000Z.db.mac.age, with the time of your backup in the names.
Step 4. Test a restore
Do this test once now, so that you know that a restore works. A restore stops the app for a short time and logs out each browser.-
On your computer, make a backup:
-
Write down the file name that the command shows, for example
sesame-20261001T040000Z.db. - In the app, set a price alert.
-
On your computer, restore the backup from item 1:
-
The command asks
restore <file name> over the database on <your-domain>? sesame stops meanwhile [y/N]. Typey. -
The command shows
MAC verifiedandlogin sessions cleared, then the app starts again. - Log in to the app again.
- Look at your alerts. The alert from item 3 is not there, because the backup is older than the alert.
task deploy:start on your computer. Day to day tells
you how to restore a backup later.
Previous: 2. First deploy · Next: 4. Go live