Skip to main content

Backup and restore

All data lives in one directory:

InstallationDirectory
Server service/var/lib/deaconguard/
Local mode~/.local/share/deaconguard/
Either, if setthe directory in DEACONGUARD_HOME

It holds:

  • deaconguard.db: hosts, scan results, activity logs, accounts, tokens and the audit log. Passwords are stored as PBKDF2 hashes, tokens and credentials as SHA-256 hashes.
  • tls/: the server's certificate and key. Keep them: agents trust this key.
  • feeds/: a cache of advisory data, downloaded again if missing.

Files are readable only by their owner.

Back up​

Stop the server, copy the directory, start it again:

sudo systemctl stop deaconguard-server
sudo cp -a /var/lib/deaconguard /root/deaconguard-backup-$(date +%Y%m%d)
sudo systemctl start deaconguard-server

Restore​

Stop the server, put the backup back in place with its ownership, and start it:

sudo systemctl stop deaconguard-server
sudo rm -rf /var/lib/deaconguard
sudo cp -a /root/deaconguard-backup-YYYYMMDD /var/lib/deaconguard
sudo systemctl start deaconguard-server

Agents keep working as long as the restored tls/ directory holds the same key.