Linux

Where Does Self-Hosted Infisical Store Data?

Infisical compose keeps secrets in .env and data in pg_data plus redis_data volumes. Dump Postgres, never copy raw volumes.

Last updated

A compose Infisical install has three persistent pieces: the .env file with every secret, the pg_data volume with all encrypted data, and the redis_data volume with regenerable cache. The docs call out pg_data explicitly as the never delete volume.

Backups mean pg_dump plus the .env file, ideally on a cron schedule. Upgrades follow the same pair: dump first, pull the new image, watch migration logs. SMTP and TLS settings also live in .env. Metrics and external database URLs extend the same file as deployments mature.

Where Infisical stores this, by platform

Linux
/opt/infisical/.env

Every secret for the stack: DB creds, encryption key, SMTP, site URL. Chmod 600 and never commit.

Linux
/var/lib/docker/volumes/infisical_pg_data/_data

Postgres data with all secrets and config. Back up with pg_dump into timestamped sql files, not raw volume copies.

Linux
/var/lib/docker/volumes/infisical_redis_data/_data

Cache and queue data. Safe to rebuild. Externalize to managed Redis for bigger installs.

Frequently asked questions

How do I back up Infisical?

Dump Postgres with pg_dump and store the .env beside the dump. The encryption key inside .env is mandatory: restores without it cannot decrypt.

How do I protect the .env file?

Chmod 600 the file and keep it out of git. It carries DB passwords, encryption keys, and SMTP credentials for the whole stack.

Notice an outdated path? Let us know.