Linux

Where Does Kanidm Store Config and Database?

Kanidm reads server.toml from the data volume and keeps kanidm.db plus backups beside it. Env vars override file keys.

Last updated

Kanidm centers on one data volume holding config, database, TLS material, and backups. The server.toml file sets domain, origin, bind addresses, and database path, with KANIDM prefixed env vars overriding any key. The container defaults to the data path config.

The database file path itself is a config value defaulting inside the same volume. Online backups drop into a backups subfolder on a cron schedule. Domain and origin must stay consistent or WebAuthn breaks. TLS chain and key paths in the same volume reload on signal without restarts.

Where Kanidm stores this, by platform

Linux
/var/lib/docker/volumes/kanidm/_data/server.toml

Main config with domain, TLS paths, and db path. Validate with the configtest subcommand before restarting.

Linux
/var/lib/docker/volumes/kanidm/_data/kanidm.db

Identity database. Tune page size only for known filesystems, then vacuum. Never edit by hand.

Linux
/var/lib/docker/volumes/kanidm/_data/kanidm/backups

Scheduled online backups. Keep version counts sane. Restore by stopping the server and swapping the db file.

Frequently asked questions

How do I back up Kanidm?

Back up the whole data volume: server.toml, kanidm.db, TLS files, and the backups subfolder. The scheduled online backups already land inside it.

How do I validate server.toml?

Run the configtest subcommand against the volume first. It defaults to the data path config and catches bad domain or TLS values before restart.

Notice an outdated path? Let us know.