02 / 13
Quickstart
Build the image, initialize the instance, register a database, take the first encrypted backup
1. Build the image
docker build --target runtime -t supabackup:local .The image runs as non-root (UID 10001) and ships PostgreSQL clients 14–18; encryption uses the built-in age Go library (no external age CLI).
2. Run it
docker run -d --name supabackup \
-p 127.0.0.1:8080:8080 \
-v supabackup-data:/app/data \
supabackup:localThe data volume holds the master secret, the SQLite metadata database and staged ciphertext — it is your most important asset besides the bucket.
3. Initialize the admin account
A fresh instance can only be claimed with a local one-time token:
docker exec supabackup /app/supabackup bootstrapOpen http://127.0.0.1:8080 (plain-HTTP loopback works locally; production
requires TLS or the browser drops the Secure cookie). Choose "Initialize a
fresh instance with a CLI
token", paste the token and pick a username plus a password of at least 12
characters. Tokens live 15 minutes and are single-use.
4. Create the age identity
docker exec supabackup /app/supabackup age init > identity.txtThe private key is printed exactly once
identity.txt is the only key that can decrypt your backups. Store it
offline, encrypted. The instance keeps the public recipient only. Losing the
identity means losing recoverability of existing backups.
5. Register a database and back it up
Use "Register your first database", pick a platform (or self-hosted) and paste the connection string or fill the fields. The string is connection-tested before saving, stored encrypted, and never shown again.
Back in the overview, press "Back up now". The task appears under Recent backups; on success you can download the recovery kit and the ciphertext.
6. Prove the restore (strongly recommended once)
AGE_IDENTITY_FILE=$PWD/identity.txt \
PGPASSWORD='<target db password>' \
sh restore.sh 'postgresql://user@host:5432/restored?sslmode=require' backup-job2.dump.ageThe kit verifies the ciphertext SHA-256 first, then decrypts, pg_restores
into the fresh database and prints the restored table count.
On Supabase? Back up a Supabase database covers the connection string to use and what the backup contains.
Last updated