Linux

Where Does Authentik Store Data and Secrets?

Authentik keeps everything in Postgres and Redis, wired by .env secrets. Dump the DB and copy .env for migration.

Last updated

Authentik stores nothing in its app containers. Postgres holds users, flows, and policies. Redis holds cache and sessions. A media volume holds uploads. The .env file ties them together.

Migration means database plus secrets plus media. The compose directory usually holds the .env beside the YAML, so archiving that folder plus a DB dump covers everything worth keeping.

Where Authentik stores this, by platform

Linux
/var/lib/postgresql/data (postgres container)

Container-side Postgres data. Named volume in official compose. Dump on a schedule, not just volume snapshots.

Linux
.env (compose directory)

Secrets and connection strings beside docker-compose. Copy with the DB dump. Without matching salts, sessions break.

Frequently asked questions

How do I back up Authentik?

Dump Postgres and copy the .env file with secrets and DB credentials. The server and worker containers hold no state. Media uploads live in the media volume.

What moves besides the database?

Copy POSTGRES_*, AUTHENTIK_SECRET_KEY, and related values into the new .env. Same salts keep sessions and tokens validating after the move.

Where are Authentik customizations?

Custom icons and branding uploads sit in the media volume. Back it up with the DB dump or the new instance looks stock.

Notice an outdated path? Let us know.