MariaDB backups with MariaDB's own tools.
DBackup runs mariadb-dump, the tool MariaDB ships itself, on a schedule. It encrypts the dumps with AES-256-GCM when the job has a key, keeps them on the storage you choose and restores them with the mariadb client.
- ConnectDirect to mariadb:3306
- Dumpmariadb-dump --single-transaction --routines --events --databases nextcloud
- EncryptGzip and AES-256-GCM
- UploadHetzner Object Storage
- Retention7 daily, 4 weekly, 12 monthly
- NotifyDiscord · #backups
- Tested with 10.11 and 11.4
- MariaDB 10 and 11
- MariaDB's client ships in the image
- mariadb-dump
- Over SSH, mariadb-dump runs on your server
- Direct or over SSH (beta)
- Pick databases and give them new names
- Restore in the app
How a MariaDB backup runs
Four steps, each one a tool or a format you could use yourself. DBackup runs them on a schedule and tells you when one fails.
- 1Dump
mariadb-dump --single-transactiondumps each database from one consistent snapshot, with its routines and events by default. - 2CompressDBackup can compress each dump with Gzip or Brotli before it is encrypted.
- 3EncryptAES-256-GCM with the key of an encryption profile, for each dump on its own. Inside, the dump stays what the tool wrote.
- 4StoreUploaded to one or several of the 13 destinations, each with its own retention, from a simple count to daily, weekly, monthly and yearly.
What goes into the dump, per source
The Options of a source decide. Each switch is on unless you turn it off, and Extra options go to mariadb-dump as they are.
The password reaches mariadb-dump in a temporary file that only its owner can read, never on the command line.
- Consistent snapshot
--single-transactionReads InnoDB tables at one point in time without blocking writes. Off, the tables of each database are locked while it is dumped. - Stored procedures and functions
--routinesDumps the routines of each database with its tables. - Events
--eventsDumps the scheduled events of each database.
Before each dump DBackup checks what the login may read. Where it may not read the events or the body of a routine, that database is dumped without them, with a warning on the run.
One archive per run, one dump per database
A job takes a single database, a few, or every database of the server without the system schemas. The dumps share one TAR with a manifest and an index of checksums.
- Restore a single database without touching the others, and give it a new name, like a copy next to the live one.
- A MariaDB backup restores into MariaDB only, and never from a newer server onto an older one. The app checks both before it starts.
- Unencrypted,
tar -xfgets the SQL files out, andgunziporbrotli -dunpacks them when the job compresses.
- TARwiki-mariadb_2026-10-08_03-00-00.tar164 MB
- { }manifest.json
- DIRdatabases/
- DBnextcloud.sql.gz121 MB
- DBwiki.sql.gz43 MB
- { }index
$ node dbackup-recover.js --extract wiki-mariadb_2026-10-08_03-00-00.tar ./restored databases/nextcloud$ mariadb -u root -p < ./restored/databases/nextcloud.sql
Get it back without DBackup
The Recovery Kit decrypts and unpacks a dump and checks it before it writes the file. The mariadb client does the rest.
The Recovery Kit from the Vault is a script and your key. It decrypts and unpacks a dump and checks its SHA-256 before it writes the file.
Why we built it this wayRunning in five minutes
DBackup is one container. Put it next to your database, give it a login and add the first job.
services:
dbackup:
image: skyfay/dbackup:latest
restart: always
ports:
- "3000:3000"
environment:
- ENCRYPTION_KEY=${ENCRYPTION_KEY} # openssl rand -hex 32
- BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET} # openssl rand -base64 32
- BETTER_AUTH_URL=https://localhost:3000
volumes:
- ./data:/data
mariadb:
image: mariadb:11
environment:
- MARIADB_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD}
MariaDB questions
MariaDB 10 and 11. The integration tests run against 10.11 and 11.4.
Not from the app, which refuses restores between MariaDB and MySQL and from a newer server onto an older one. The SQL file is still yours to import by hand.
Yes. The mariadb client reads the dump without --force, so the first failing statement ends the restore, and the run shows the error.
Yes, over SSH, which is in beta. DBackup logs into the server, runs mariadb-dump there and streams the dump back. The server needs mariadb-dump, mariadb and mariadb-admin, or their mysql names.
Yes. The Recovery Kit gets the SQL file out, encrypted or not, and unpacks it, with nothing but Node.js. The mariadb client reads it back.
Other databases
All integrationsYour first MariaDB backup runs tonight.
One container, one compose file and a job. Free and open source.