DBackup
Database integration

MongoDB backups, Atlas included.

DBackup runs mongodump on a schedule, against a single server, a replica set or MongoDB Atlas. It encrypts the archives with AES-256-GCM when the job has a key and restores them under any database name.

Open source under GPL-3.0 · runs on your own server
app-mongodbRunning
  1. ConnectDirect to cluster0.abcde.mongodb.net
  2. Dumpmongodump --db app --archive=app.archive --gzip
  3. EncryptAES-256-GCM
  4. UploadHetzner Object Storage
  5. Retention7 daily, 4 weekly, 12 monthly
  6. NotifyDiscord · #backups
With an encryption profile, every dump is encrypted with AES-256-GCM before it leaves your server.
Tested with 4.4 and 8.0
MongoDB 4 to 8
mongodb+srv and seed lists
Atlas and replica sets
Over SSH, mongodump runs on your server
Direct or over SSH (beta)
Each database on its own
Restore under any name

How a MongoDB backup runs

Four steps, each one a tool or a format you could use yourself. DBackup runs them on a schedule and tells you when one fails.

  1. 1Dumpmongodump --archive --gzip writes one compressed archive per database, one after the other.
  2. 2Compressmongodump compresses the archive itself, so DBackup keeps it as it is and only encrypts it.
  3. 3EncryptAES-256-GCM with the key of an encryption profile, for each dump on its own. Inside, the dump stays what the tool wrote.
  4. 4StoreUploaded to one or several of the 13 destinations, each with its own retention, from a simple count to daily, weekly, monthly and yearly.

Atlas, replica sets and single servers

Type the host the way you know it. DBackup turns it into the right connection for mongodump.

The authentication database is admin unless you name another one.

  • cluster0.abcde.mongodb.netSRVAn Atlas host is recognized and connected through mongodb+srv.
  • mongodb+srv://mongo.example.comSRVAny other SRV record works once you write the scheme.
  • db1:27017,db2:27017,db3:27017Seed listSeveral hosts become one connection to the replica set.
  • mongoSingle serverA single server, with the port in its own field.

One archive per database

Leave the pick empty and every run lists the databases again, without admin, config and local. Each one is dumped on its own into the same TAR.

  • Restore a database under a new name, and mongorestore moves its collections with --nsFrom and --nsTo.
  • A restore drops each collection before it writes it back, so the result matches the backup.
  • Users and roles live in the admin database, which is not part of the backup.
  • TARapp-mongodb_2026-10-08_03-00-00.tar301 MB
  • { }manifest.json
  • DIRdatabases/
  • DBapp.archive218 MB
  • DBanalytics.archive83 MB
  • { }index
The layout of an unencrypted archive. In an encrypted one the entries carry neutral names.
Any computer with Node.js
$ node dbackup-recover.js --extract app-mongodb_2026-10-08_03-00-00.tar ./restored databases/app$ mongorestore --gzip --archive=./restored/databases/app.archive

Get it back without DBackup

Each archive is what mongodump --gzip wrote. The Recovery Kit decrypts it, and mongorestore reads it back with the same flag.

The Recovery Kit from the Vault is a script and your key. It decrypts and unpacks a dump and checks its SHA-256 before it writes the file.

Why we built it this way

Running in five minutes

DBackup is one container. Put it next to your database, give it a login and add the first job.

docker-compose.yml
services:
  dbackup:
    image: skyfay/dbackup:latest
    restart: always
    ports:
      - "3000:3000"
    environment:
      - ENCRYPTION_KEY=${ENCRYPTION_KEY}          # openssl rand -hex 32
      - BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET}  # openssl rand -base64 32
      - BETTER_AUTH_URL=https://localhost:3000
    volumes:
      - ./data:/data

  mongo:
    image: mongo:8
    environment:
      - MONGO_INITDB_ROOT_USERNAME=root
      - MONGO_INITDB_ROOT_PASSWORD=${MONGO_PASSWORD}

MongoDB questions

Yes. Enter the host of your cluster, like cluster0.abcde.mongodb.net, and DBackup connects through mongodb+srv on its own.

No. mongodump runs without --oplog, so writes during the dump can be caught in part. For a busy database, schedule the job for a quiet hour.

MongoDB 4 to 8. The image ships the MongoDB Database Tools 100.16, and the integration tests run against 4.4 and 8.0.

No. They live in the admin database, which DBackup leaves out with config and local. Create the users on a new server before you restore.

Yes. The Recovery Kit gets the archives out, encrypted or not, with nothing but Node.js. Then run mongorestore with --gzip and --archive.

Your first MongoDB backup runs tonight.

One container, one compose file and a job. Free and open source.