Where Does the Psono Server Store Data?
Psono reads settings.yaml for secrets and database wiring. Vault contents live in Postgres; the file plus a dump is the backup.
Last updated
Psono splits config from content. The settings.yaml file holds the secret key, activation tokens, database credentials, mail, YubiKey, and time server options. The Postgres database holds every encrypted vault: users, groups, secrets, and file shard maps. Client config.json files for the web portal sit beside settings.yaml in compose layouts.
Docker mounts settings.yaml at /root/.psono_server/settings.yaml (commonly from ./data/psono/), with Postgres data in ./data/postgres/. Bare installs use ~/.psono_server/settings.yaml instead. Fileserver shards add their own storage, but the chunk map in Postgres still needs the dump. Guard settings.yaml: it contains every key that decrypts the deployment.
Where Psono stores this, by platform
settings.yaml (/root/.psono_server/)
Secrets, DB credentials, mail, and service toggles. Mounted from the host data folder. Client portal config.json files sit beside it. Never commit this file; it decrypts the whole deployment.
Postgres data (./data/postgres)
Encrypted vaults, users, groups, and shard maps. Dump on schedule. Fileserver chunks without this dump are undecryptable noise, so back both halves together.
Frequently asked questions
how do i back up psono
Copy settings.yaml and take a Postgres dump with the server stopped. Keys, mail, and DB credentials travel in the file; encrypted vaults travel in the dump. One without the other restores nothing usable.
how do i generate psono server keys
Run the generateserverkeys command from the server image and paste the output into settings.yaml. Store the printed admin recovery private key offline and never in the file; losing it locks you out of recovery with no reset path.
Notice an outdated path? Let us know.