Linux

Where Does Self-Hosted Firezone Store Data?

Self-hosted Firezone keeps portal settings in Postgres and secrets in .env. Gateways hold no state worth backing up.

Last updated

Firezone splits state between the portal and everything else. The portal (admin UI plus control plane) persists users, policies, devices, and audit logs in PostgreSQL, typically a db_data volume beside compose.yaml. Secrets like SECRET_KEY_BASE, DATABASE_URL, and the admin account live in .env in the project folder.

Gateways, relays, and clients hold no durable state. They authenticate to the portal and rebuild tunnels on demand, so losing one costs ten minutes of re-enrollment, not data. That makes the backup story simple: protect the database volume and the env file, and the mesh rebuilds itself around them. Note the legacy 0.7 image is end of life; current docs describe the 1.x portal layout.

Where Firezone stores this, by platform

Linux
~/firezone/.env + compose.yaml

DATABASE_URL, SECRET_KEY_BASE, admin email, ports. Lives beside compose.yaml (often ~/firezone). Guard this file; SECRET_KEY_BASE rotation invalidates existing sessions and tokens.

Linux
db_data (Postgres volume)

Users, policies, devices, audit logs. Usually a db_data named volume on /var/lib/postgresql/data. Dump on schedule; gateways and relays re-register and need no backup.

Frequently asked questions

how do i back up self-hosted firezone

Back up the Postgres db_data volume plus .env (DATABASE_URL, SECRET_KEY_BASE, admin credentials). Gateways and relays re-register from the portal, so they need no backup. Test restores before rotating secrets.

do firezone gateways need backups

No. Gateways are stateless data plane nodes that pull config from the portal. Reinstall the gateway package, re-enroll its token, and policies flow back. Only the portal machine holds state.

Notice an outdated path? Let us know.