Where Does Self-Hosted Pangolin Store Config?
Pangolin reads config.yml from its config dir with Traefik, Postgres, and Gerbil keys beside it. Back up the folder whole.
Last updated
Pangolin centers on config.yml in the install config directory: domains, server secret, ports, mail, and component wiring. Around it sit Traefik configs, Let's Encrypt storage, Gerbil WireGuard keys, and optional Postgres/Redis data dirs. The installer generates this tree; Docker mounts it back into the containers.
Backups mean the whole tree plus database dumps. The server secret encrypts stored data, so config without the secret (or vice versa) restores nothing usable. Logs are optional file output under config/logs. Never edit the secret by hand; the rotate command re-encrypts dependent data in one pass.
Where Pangolin stores this, by platform
./config/config.yml (install dir)
Domains, secret, ports, mail, component wiring. Traefik, letsencrypt, Gerbil keys beside it. Rotate secrets with pangctl only. Postgres/Redis data dirs sit alongside when enabled.
Frequently asked questions
how do i back up pangolin
Stop the stack and copy the whole config/ folder (config.yml, traefik/, letsencrypt/, key) plus database dumps. Secrets and WireGuard keys travel in the files, so guard the copy. Restore to identical paths.
how do i change the pangolin server secret
Use pangctl rotate-server-secret, never hand edit. The secret encrypts stored credentials, and changing the file directly orphans everything encrypted with the old value.
Notice an outdated path? Let us know.