Advanced
How backups work
A helper container on the host that owns the data pushes straight to your destination. MangoDock only ever sees the exit code.
The data never crosses the control plane
A helper container runs on whichever daemon owns the volume, mounts it read-only, and pushes straight to the destination. A 200 GB volume moves at that host's bandwidth rather than being pulled through an SSH channel to MangoDock and back out again. MangoDock sees the exit code and the log, and nothing else.
It also keeps the “nothing installed on the host” property intact. The helper is a container that host's own daemon runs for the duration — exactly as a compose deploy already is — not an agent anybody has to install.
restic does the work
Deduplication, encryption, the destination back-ends and snapshot browsing are all restic's. That is the fourth time MangoDock shells out to a mature tool rather than owning the problem, after docker compose, git and the vulnerability scanners.
Its repository format is documented and stable, and that is the property worth protecting: a MangoDock backup can be restored with plain restic by somebody who no longer has MangoDock. The repository password is all that is needed — which is also why keeping that password somewhere else matters. Without it the backups cannot be read by anything.
Nothing sensitive reaches docker inspect
The repository password and the destination's keys are written into the helper container as a file before it starts — never as environment variables and never as the command, both of which anyone with access to that daemon can read back off a running container. The helper deletes the file as soon as it has read it, and hands the password to restic through a file reference so it is not in the process environment either.
A restore never overwrites
It lands in a new volume, always. Putting it back over the live one is a separate, deliberate step, because a restore that overwrites is a restore that can destroy the only copy of the data when the snapshot turns out to be the wrong one. Nothing running is touched by the restore itself.
What a snapshot carries
- The volume contents, and a manifest of what was running alongside them — a restore that cannot say what the data belonged to is most of a restore.
- Enough to restore a single service rather than everything, and to restore onto a different host than the one it came from.
- Bind mounts and named volumes both, which look similar and restore differently.
Air-gapped
- A local or self-hosted destination keeps the whole path inside your network. The helper image must be reachable on each host that backs up — load it once by hand, or point MANGODOCK_BACKUP_IMAGE at your internal mirror.