DBackup
Database integration

Redis backups, with a restore that guides you.

DBackup takes an RDB snapshot with redis-cli --rdb on a schedule, encrypts it with AES-256-GCM when the job has a key and keeps it on the storage you choose. The restore page writes the script that puts it back.

Open source under GPL-3.0 · runs on your own server
cache-redisRunning
  1. ConnectDirect to redis:6379
  2. Dumpredis-cli --rdb dump.rdb
  3. EncryptGzip and AES-256-GCM
  4. UploadHetzner Object Storage
  5. Retention7 daily, 4 weekly, 12 monthly
  6. NotifyDiscord · #backups
With an encryption profile, every dump is encrypted with AES-256-GCM before it leaves your server.
Tested with 6 and 8
Redis 2.8 and newer
Every logical database in one file
One RDB snapshot
With TLS and ACL users
Direct or over SSH (beta)
A script for Docker, Linux or Windows
Guided restore

How a Redis backup runs

Four steps, each one a tool or a format you could use yourself. DBackup runs them on a schedule and tells you when one fails.

  1. 1Dumpredis-cli --rdb asks the server for a snapshot, the same file a replica receives. It holds every logical database.
  2. 2CompressDBackup can compress the snapshot with Gzip or Brotli before it encrypts it.
  3. 3EncryptAES-256-GCM with the key of an encryption profile, for each dump on its own. Inside, the dump stays what the tool wrote.
  4. 4StoreUploaded to one or several of the 13 destinations, each with its own retention, from a simple count to daily, weekly, monthly and yearly.

A restore that writes its own script

Redis loads its snapshot when it starts, so a restore means stopping it and putting the file in place. The restore page writes a script for that, for the way your Redis runs.

Rather do it by hand? The Manual tab lists the same steps as commands.

DockerDocker ComposeLinux serviceWindows service
  1. 1Checks PING, appendonly, dir and dbfilename before it changes anything
  2. 2Stops Redis and keeps the old snapshot as dump.rdb.before-restore
  3. 3Puts the backup in place and starts Redis again
  4. 4Waits until Redis answers and shows INFO keyspace

A bash script, or PowerShell for Windows, to download or copy.

One snapshot, every database

An RDB file holds all logical databases of the server, so a backup is always one snapshot, whatever the job picked.

  • A login is a Vault profile with a user and a password. For a server with only requirepass the user is default, from Redis 6 on. An ACL user needs SYNC, PSYNC, PING and INFO.
  • Turn on TLS for a server that asks for it.
  • Sentinel and Cluster are not supported yet. DBackup takes the snapshot of the one server you name.
  • TARcache-redis_2026-10-08_03-00-00.tar21 MB
  • { }manifest.json
  • DIRdatabases/
  • DBdump.rdb.gz21 MB
  • { }index
The layout of an unencrypted archive. In an encrypted one the entries carry neutral names.
Any computer with Node.js
$ node dbackup-recover.js --extract cache-redis_2026-10-08_03-00-00.tar ./restored databases/dump$ sudo systemctl stop redis-server$ sudo install -o redis -g redis -m 640 ./restored/databases/dump.rdb /var/lib/redis/dump.rdb$ sudo systemctl start redis-server

Get it back without DBackup

The snapshot is the RDB file Redis writes itself. The Recovery Kit decrypts and unpacks it, and Redis loads it on the next start.

The Recovery Kit from the Vault is a script and your key. It decrypts and unpacks a dump and checks its SHA-256 before it writes the file.

Why we built it this way

Running in five minutes

DBackup is one container. Put it next to your database, give it a login and add the first job.

docker-compose.yml
services:
  dbackup:
    image: skyfay/dbackup:latest
    restart: always
    ports:
      - "3000:3000"
    environment:
      - ENCRYPTION_KEY=${ENCRYPTION_KEY}          # openssl rand -hex 32
      - BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET}  # openssl rand -base64 32
      - BETTER_AUTH_URL=https://localhost:3000
    volumes:
      - ./data:/data

  redis:
    image: redis:8
    command: redis-server --requirepass ${REDIS_PASSWORD}

Redis questions

Yes. An RDB file holds all logical databases of the server, and DBackup stores it as one entry.

With appendonly on, Redis loads the AOF at start and ignores the RDB. The restore guide has a part for that case, and its script stops before it changes anything while appendonly is on.

Not yet. DBackup connects to the one server you name and takes its snapshot.

Redis 2.8 and newer, and Valkey 7.2 and newer through its own source type. The integration tests run against Redis 6 and 8.

Yes. The Recovery Kit gets dump.rdb out, encrypted or not, and unpacks it, with nothing but Node.js. Stop Redis, put the file in its data folder and start it again.

Your first Redis backup runs tonight.

One container, one compose file and a job. Free and open source.