Self-hosting

Server maintenance

Update the sync server, back up its database, and know what is kept apart from your other services.

On this page

Update the server

Copy the new files to your home folder on the server as in step 2. Then, on the server as root:

bash
cp /home/USER/burrow-sync/* /home/USER/burrow-sync/.dockerignore /opt/burrow-sync/
rm -r /home/USER/burrow-sync
cd /opt/burrow-sync
docker compose up -d --build

This only replaces the server’s code. Your .env and the database stay as they are.

Back up the database

On the server as root:

bash
cd /opt/burrow-sync
docker compose exec burrow-sync node backup.js
docker cp burrow-sync:/data/backup-$(date +%F).db /home/USER/
chown USER /home/USER/backup-*.db

Then fetch it from your computer:

bash
scp USER@SERVER_IP:~/backup-*.db .

The data in the backup is encrypted and useless without the account passwords.

To follow the logs, run docker compose logs -f in /opt/burrow-sync.

What is isolated and what isn’t

Separate from your other services:

  • Network: other containers can’t reach the sync server.
  • Data: its own volume and SQLite database.
  • Configuration: its own folder and .env.
  • Resources: at most 128 MB of RAM and half a CPU, so it can’t slow down anything else.
  • Container: runs as a non-root user with a read-only file system, no Linux capabilities, no privilege escalation and (except with 5E) no internet access.

Shared with everything else: the reverse proxy, the Docker daemon and the Linux kernel. Containers are not virtual machines. Anyone who gets root on the server can reach everything, but from the sync server they only get encrypted data.

If you want the proxy and kernel separated too, run the sync server on its own machine.

Made with love by zukotuutori