Backups on your own server
This page is for organizations that run PatchPilot on their own server. On the hosted service, backups are ours to run.
Turn them on
In the server's .env file:
PP_BACKUP_DIR=/var/backups/patchpilot # folder on this server
PP_BACKUP_ENABLED=true
PP_BACKUP_TIME=02:00 # every day, UTC
PP_BACKUP_KEEP_DAYS=14 # older files are deletedThen, in the PatchPilot folder on the server:
docker compose up -d backupEach night writes one file, patchpilot-<date and time>.sql.gz, readable
only by root. docker compose logs backup shows when the next one runs.
A backup right now:
docker compose exec backup sh /backup.sh nowCopy the folder to another machine (a file share, another server,
cloud storage). A backup on the same disk is lost with that disk. Keep a
private copy of .env too: the database needs its passwords.
See them in the portal
Organization admins find Database backups under Data retention: whether backups are on, when they run (in UTC and your own time), how many days are kept, the folder on the server, the latest backup and the files kept. Copy puts the folder's path on the clipboard.
If a backup fails
The administrators see a warning bar in the portal and get one email. It clears itself after the next good backup.
Restore
Restore onto the same server or a new one installed the same way:
# 1. Stop everything that uses the database; leave Postgres running.
docker compose stop api retention notifier vuln scheduler analytics web backup
# 2. Load the backup. It replaces the PatchPilot database with its copy.
gunzip -c /var/backups/patchpilot/patchpilot-<date and time>.sql.gz \
| docker compose exec -T postgres psql -U patchpilot -d postgres
# 3. Start again.
docker compose --profile appliance up -dpsql prints a few errors such as current user cannot be dropped and
role "patchpilot" already exists: those concern the database account
itself and are expected. Anything about a table is not.
Use the .env from the old server, so passwords and sign-in keys match.