Skip to content
SupaCovedocs

02 / 13

Quickstart

Pull the image, initialize the instance, register a database, take the first encrypted backup

1. Run it

Use the published GHCR image (linux/amd64 + linux/arm64; see Installation for release binaries or a local build):

# Fresh-install example — upgrading from a pre-rename supabackup deployment
# must keep the ORIGINAL supabackup-data volume: see the installation page.
docker run -d --name supacove \
  -p 127.0.0.1:8080:8080 \
  -v supacove-data:/app/data \
  ghcr.io/web-casa/supacove:latest

The image runs as non-root (UID 10001) and ships PostgreSQL clients 14–18 (standalone binaries need a host pg_dump); encryption uses the built-in age Go library (no external age CLI).

The data volume holds the master secret, the SQLite metadata database and staged ciphertext — it is your most important asset besides the bucket.

2. Initialize the admin account

A fresh instance can only be claimed with a local one-time token:

docker exec supacove /app/supacove bootstrap

Open http://127.0.0.1:8080 (plain-HTTP loopback works locally; production requires TLS or the browser drops the Secure cookie). Choose "Initialize a fresh instance with a CLI token", paste the token and pick a username plus a password of at least 12 characters. Tokens live 15 minutes and are single-use.

3. Create the age identity

docker exec supacove /app/supacove age init > identity.txt

The private key is printed exactly once

identity.txt is the only key that can decrypt your backups. Store it offline, encrypted. The instance keeps the public recipient only. Losing the identity means losing recoverability of existing backups.

4. Register a database and back it up

Use "Register your first database", pick a platform (or self-hosted) and paste the connection string or fill the fields. The string is connection-tested before saving, stored encrypted, and never shown again.

Back in the overview, press "Back up now". The task appears under Recent backups; on success you can download the recovery kit and the ciphertext.

AGE_IDENTITY_FILE=$PWD/identity.txt \
PGPASSWORD='<target db password>' \
sh restore.sh 'postgresql://user@host:5432/restored?sslmode=require' backup-job2.dump.age

The kit verifies the ciphertext SHA-256 first, then decrypts, pg_restores into the fresh database and prints the restored table count.

On Supabase? Back up a Supabase database covers the connection string to use and what the backup contains.

Last updated

On this page