Backup and upgrade
All data of an installation lives in two places: the core-data Docker volume (database, uploads, certificates) and the root key in .env (or the root_encryption_key file, if you keep it there). A backup needs both.
Back up
Run this in the directory with docker-compose.yml. Core stops for the copy, so nothing changes while it runs:
docker compose stop core
docker run --rm \
-v openmeshtak_core-data:/data:ro \
-v "$PWD":/backup \
alpine tar czf /backup/openmeshtak-$(date +%F).tar.gz -C /data .
docker compose start coreThis creates openmeshtak-<date>.tar.gz next to the Compose file. Copy it, together with .env or the key file, to another machine. Store the key apart from the archive: anyone with both can read every stored secret.
Restore
Restore onto the same OpenMeshTak version that made the backup:
docker compose down
docker volume rm openmeshtak_core-data
docker volume create openmeshtak_core-data
docker run --rm \
-v openmeshtak_core-data:/data \
-v "$PWD":/backup \
alpine tar xzf /backup/openmeshtak-2026-10-08.tar.gz -C /data
docker compose up -dPut the matching .env or key file next to docker-compose.yml before starting. Test a restore on a spare machine once, before you need it.
Upgrade
Read the release notes.
Make a backup as above.
If you use a fixed version, set
OPENMESHTAK_VERSIONin.envto the new one. Withlatest, skip this step.Start the new version:
shdocker compose pull docker compose up -d docker compose logs core
Core updates the database on its first start. To go back, restore the backup and set the old version again. Do not start an older version on a database that a newer one has already updated.