Where Does Ory Kratos Store Config and Identities?
Kratos reads kratos.yml via --config with identities in SQL. Docker mounts the file at /etc/config/kratos; SQLite persists in a volume.
Last updated
Kratos centers on kratos.yml (JSON/YAML/TOML all parse): DSN, self-service flow URLs, hashing, courier, and session settings, passed with --config (Docker bind-mounts it, commonly at /etc/config/kratos). Env vars override any key with underscore nesting. Secrets belong in env, never the file.
Identities live in SQL chosen by DSN. Quickstart uses a SQLite volume for local trials; production wants Postgres/MySQL/Cockroach. Referenced files (identity schemas, OIDC mappers, courier templates, JWKS) must travel with the config or startup sandboxing denies them. Some keys hot-reload; DSN changes need restarts.
Where Ory Kratos stores this, by platform
kratos.yml (config mount)
DSN, flow URLs, hashing, courier, sessions. Pass via --config; Docker bind-mounts commonly at /etc/config/kratos. Env overrides any key. Ship referenced schemas and templates with it.
Frequently asked questions
how do i back up ory kratos
Copy kratos.yml (plus identity schemas and hooks it references) and dump the SQL database with the service stopped. Identities, sessions, and flows travel in the db; URLs and secrets in the file. Restore both halves together.
can kratos use sqlite in production
Never SQLite outside local dev. Kratos supports SQLite, Postgres, MySQL, and CockroachDB, but production guides require a server database. Quickstart mounts a SQLite volume purely for trying flows locally.
Notice an outdated path? Let us know.