DBackup
Database integration

MariaDB backups with MariaDB's own tools.

DBackup runs mariadb-dump, the tool MariaDB ships itself, on a schedule. It encrypts the dumps with AES-256-GCM when the job has a key, keeps them on the storage you choose and restores them with the mariadb client.

Open source under GPL-3.0 · runs on your own server
wiki-mariadbRunning
  1. ConnectDirect to mariadb:3306
  2. Dumpmariadb-dump --single-transaction --routines --events --databases nextcloud
  3. EncryptGzip and AES-256-GCM
  4. UploadHetzner Object Storage
  5. Retention7 daily, 4 weekly, 12 monthly
  6. NotifyDiscord · #backups
With an encryption profile, every dump is encrypted with AES-256-GCM before it leaves your server.
Tested with 10.11 and 11.4
MariaDB 10 and 11
MariaDB's client ships in the image
mariadb-dump
Over SSH, mariadb-dump runs on your server
Direct or over SSH (beta)
Pick databases and give them new names
Restore in the app

How a MariaDB backup runs

Four steps, each one a tool or a format you could use yourself. DBackup runs them on a schedule and tells you when one fails.

  1. 1Dumpmariadb-dump --single-transaction dumps each database from one consistent snapshot, with its routines and events by default.
  2. 2CompressDBackup can compress each dump with Gzip or Brotli before it is encrypted.
  3. 3EncryptAES-256-GCM with the key of an encryption profile, for each dump on its own. Inside, the dump stays what the tool wrote.
  4. 4StoreUploaded to one or several of the 13 destinations, each with its own retention, from a simple count to daily, weekly, monthly and yearly.

What goes into the dump, per source

The Options of a source decide. Each switch is on unless you turn it off, and Extra options go to mariadb-dump as they are.

The password reaches mariadb-dump in a temporary file that only its owner can read, never on the command line.

  • Consistent snapshot--single-transactionReads InnoDB tables at one point in time without blocking writes. Off, the tables of each database are locked while it is dumped.
  • Stored procedures and functions--routinesDumps the routines of each database with its tables.
  • Events--eventsDumps the scheduled events of each database.

Before each dump DBackup checks what the login may read. Where it may not read the events or the body of a routine, that database is dumped without them, with a warning on the run.

One archive per run, one dump per database

A job takes a single database, a few, or every database of the server without the system schemas. The dumps share one TAR with a manifest and an index of checksums.

  • Restore a single database without touching the others, and give it a new name, like a copy next to the live one.
  • A MariaDB backup restores into MariaDB only, and never from a newer server onto an older one. The app checks both before it starts.
  • Unencrypted, tar -xf gets the SQL files out, and gunzip or brotli -d unpacks them when the job compresses.
  • TARwiki-mariadb_2026-10-08_03-00-00.tar164 MB
  • { }manifest.json
  • DIRdatabases/
  • DBnextcloud.sql.gz121 MB
  • DBwiki.sql.gz43 MB
  • { }index
The layout of an unencrypted archive. In an encrypted one the entries carry neutral names.
Any computer with Node.js
$ node dbackup-recover.js --extract wiki-mariadb_2026-10-08_03-00-00.tar ./restored databases/nextcloud$ mariadb -u root -p < ./restored/databases/nextcloud.sql

Get it back without DBackup

The Recovery Kit decrypts and unpacks a dump and checks it before it writes the file. The mariadb client does the rest.

The Recovery Kit from the Vault is a script and your key. It decrypts and unpacks a dump and checks its SHA-256 before it writes the file.

Why we built it this way

Running in five minutes

DBackup is one container. Put it next to your database, give it a login and add the first job.

docker-compose.yml
services:
  dbackup:
    image: skyfay/dbackup:latest
    restart: always
    ports:
      - "3000:3000"
    environment:
      - ENCRYPTION_KEY=${ENCRYPTION_KEY}          # openssl rand -hex 32
      - BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET}  # openssl rand -base64 32
      - BETTER_AUTH_URL=https://localhost:3000
    volumes:
      - ./data:/data

  mariadb:
    image: mariadb:11
    environment:
      - MARIADB_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD}

MariaDB questions

MariaDB 10 and 11. The integration tests run against 10.11 and 11.4.

Not from the app, which refuses restores between MariaDB and MySQL and from a newer server onto an older one. The SQL file is still yours to import by hand.

Yes. The mariadb client reads the dump without --force, so the first failing statement ends the restore, and the run shows the error.

Yes, over SSH, which is in beta. DBackup logs into the server, runs mariadb-dump there and streams the dump back. The server needs mariadb-dump, mariadb and mariadb-admin, or their mysql names.

Yes. The Recovery Kit gets the SQL file out, encrypted or not, and unpacks it, with nothing but Node.js. The mariadb client reads it back.

Your first MariaDB backup runs tonight.

One container, one compose file and a job. Free and open source.