Linux

Where Does Zitadel Store Config and Data?

Zitadel is stateless: config comes from yaml files or env, state lives in Postgres events. Back up .env plus the database.

Last updated

Zitadel splits config from state cleanly. Configuration arrives as yaml files passed to the binary or as ZITADEL prefixed env vars, with the compose setup keeping secrets in a plain .env file. The binary itself holds nothing between restarts.

All state sits in Postgres, event sourced through the events table. That table defines the restorable point in time, so database dumps are the backup. The masterkey in .env encrypts data at rest and can never change afterward. Redis caching and init setup split files join the deploy folder as installs grow.

Where Zitadel stores this, by platform

Linux
/opt/zitadel/.env

Secrets, domain, passwords, and masterkey for compose installs. Generate the masterkey before first start and guard this file.

Linux
/opt/zitadel/docker-compose.yml

Compose file plus overlays for TLS, cache, and prodlike init splits. Lives beside .env in your deploy folder.

Linux
/var/lib/docker/volumes/zitadel_postgres/_data

Postgres data backing the event store. Dump the events table for point in time restores rather than copying raw volumes across versions.

Frequently asked questions

How do I back up Zitadel?

Dump Postgres, focusing on the events table that rebuilds all state. Keep .env with the masterkey beside it, since encrypted data dies without that key.

Yaml or env vars for config?

Prefer yaml files over env vars. Files restrict access more easily, and some options exist only as file keys. The configure docs list both forms.

Notice an outdated path? Let us know.