Where Does Concourse CI Store Data and Keys?
Concourse keeps pipelines, builds, and logs in Postgres. The web and worker keys in /concourse-keys are the only files to guard.
Last updated
Concourse splits state cleanly. PostgreSQL holds nearly everything: pipeline configs, build metadata, and all build logs. The web and worker nodes themselves are stateless processes configured by flags and environment. Generated SSH keys and certificates for web-to-worker trust live in /concourse-keys, usually a mounted folder beside the compose file.
Backups therefore mean database plus keys. Lose the database and pipelines, history, and team setup vanish together. Lose the keys and nodes distrust each other until you regenerate and redistribute. Workers hold only ephemeral build containers, so they never enter the backup story. The fly CLI stores its own targets client side, not on the server.
Where Concourse stores this, by platform
/concourse-keys (Docker mount)
Generated SSH keys and certificates for web and worker trust. Mount persistently (./keys or ./data/app). Regenerate only deliberately; rotation means redistributing to every node.
Postgres data (./database)
Pipelines, builds, logs, and team data in the atc database. Dump on schedule. Build logs dominate disk usage, so set retention policies before growth forces the issue.
Frequently asked questions
how do i back up concourse
Dump the Postgres database (pipelines, build logs, team auth) and save the /concourse-keys folder with it. Workers are stateless and re-register. Restore means fresh nodes pointed at the dump plus the same keys.
why is my concourse database growing forever
Almost always disk pressure from build logs, which live in the database. Set job build_log_retention on pipelines plus a cluster default. Feed the database real CPU too; it serves near-constant queries even when idle.
Notice an outdated path? Let us know.