Backup and restore
All data lives in one directory:
| Installation | Directory |
|---|---|
| Server service | /var/lib/deaconguard/ |
| Local mode | ~/.local/share/deaconguard/ |
| Either, if set | the directory in DEACONGUARD_HOME |
It holds:
deaconguard.db: hosts, scan results, activity logs, accounts, tokens and the audit log. Passwords are stored as PBKDF2 hashes, tokens and credentials as SHA-256 hashes.tls/: the server's certificate and key. Keep them: agents trust this key.feeds/: a cache of advisory data, downloaded again if missing.
Files are readable only by their owner.
Back up
Stop the server, copy the directory, start it again:
sudo systemctl stop deaconguard-server
sudo cp -a /var/lib/deaconguard /root/deaconguard-backup-$(date +%Y%m%d)
sudo systemctl start deaconguard-server
Restore
Stop the server, put the backup back in place with its ownership, and start it:
sudo systemctl stop deaconguard-server
sudo rm -rf /var/lib/deaconguard
sudo cp -a /root/deaconguard-backup-YYYYMMDD /var/lib/deaconguard
sudo systemctl start deaconguard-server
Agents keep working as long as the restored tls/ directory holds the same key.