Linux

Where Does Passbolt Keep Keys and Data?

What a complete Passbolt backup needs: database dump, GPG server keys, config, and where each lives.

Last updated

A restorable Passbolt backup has three parts, and the database dump is only the first. The GPG server key pair under /etc/passbolt/gpg encrypts everything, and the compose file holds credentials as environment variables. Miss any piece and the restore fails.

Docker and package installs differ in tooling but not in parts: dump the database with the matching tool, copy keys with compose cp, and save config files. Restores need an empty database plus keyring import, finished with a healthcheck. Automate the whole set on a schedule.

Where Passbolt stores this, by platform

Linux
/etc/passbolt/gpg

Holds the server GPG key pair that encrypts all vault data; back up both asc files. Database dumps come from mariadb-dump against the db container. Compose env blocks carry credentials, so save the compose file too. Restore needs keyring import, not just file copies.

Frequently asked questions

how do I back up Passbolt on Docker

Collect a database dump, the GPG key pair from /etc/passbolt/gpg, and the compose file with its env. Tar them together and move off-site encrypted. Practice restores on a scratch instance; untested backups are wishes.

how do I restore a Passbolt backup

Copy the SQL dump into the container and run mysql_import against an empty database, then restore keys into the web user keyring with keyring_init. Files alone never suffice: keys must be imported, then verified with healthcheck. Config must match the backup state.

is the database dump enough

No. Compose files hold credentials and settings as environment variables, sometimes split into env files. Back up the compose file itself alongside data. Direct docker run commands need their full text saved the same way.

Notice an outdated path? Let us know.