01 / 13
What is SupaCove
Self-hosted encrypted PostgreSQL backups with BYOS storage and verifiable restores
SupaCove is a self-hosted PostgreSQL backup service for Supabase, Neon,
Railway, Aiven, Prisma Postgres, TigerData, Miget, Render and any self-hosted
PostgreSQL. It streams pg_dump output through
age encryption into your own object storage (S3 / R2 / B2 / MinIO) and
keeps a downloadable ciphertext copy in local staging.
The binary, the container image, the metric names and the webhook headers
still carry the earlier name supabackup. Commands and identifiers in these
docs are shown exactly as the software expects them.
Four guarantees
Failures never look like success
Any failure in export, encryption or commit lands the job as failed — never as succeeded.
Restarts converge
Shutdown-interrupted jobs are recorded as interrupted (no false failure alerts). When the resume conditions hold (interrupted + locally committed ciphertext + recorded remote upload intent + artifact file and manifest actually readable + usable destination), startup re-uploads automatically; otherwise the job keeps an explainable terminal state and the protection chain resumes with the next scheduled run.
Backups restore standalone
Recovery needs exactly three things: the ciphertext, your offline age identity, and the recovery kit script.
Secrets never leak into errors
Passwords and credentials are redacted across logs, API errors, task history and metrics.
The pipeline
source pg_dump --format=custom
→ age stream encryption (X25519 + ChaCha20-Poly1305)
→ atomic commit in local staging (.inprogress → final name)
→ remote object-storage commit with read-back hash verification
→ optional embedded-PostgreSQL restore verification
→ notification outbox (webhooks, with retries)Console
The single-page console is embedded in the binary and ships in Chinese and
English; the UI language also drives API-side messages via Accept-Language.
Sessions use cookies plus double-submit CSRF; production deployments must sit
behind TLS.
Next
- Quickstart: first encrypted backup in ten minutes.
- Configuration: every
SB_*variable. - Restore & DR: the three key-loss scenarios.
Last updated