Account and running it · Chapter 21
Backups, moving and updating
Only a backup helps against a broken disk. With nexdiary it takes two things: the backup itself, which nexdiary makes every night out of the box, and the master key, which you download once and keep apart. Without the master key a backup cannot be read, not even by you.
What a backup holds
A backup is a ZIP file with the database, every photo and the server's own secret (secret.key, which opens the mail server's password and the AI service's key, for example). nexdiary copies the database while it runs, so nobody has to wait. The master key is never part of it.
What the family writes is encrypted inside, just as in the database. The ZIP file itself is not: account names, mail addresses, dates and who shares which day with whom can be read in it, and so can the server's secret. So keep a backup as carefully as a password.
Setting up the backup
Under “Settings”, tab “Backup”, card “Backup”:
| Setting | Means |
|---|---|
| Automatically | “off”, “every night” or “every week”; every night out of the box, between 3 and 6 am |
| Keep | how many automatic backups stay, 1 to 365; 7 out of the box |
| Back up now | makes a backup by hand straight away |
| Upload a backup | puts a downloaded backup back into the list, on a new server for example |
The list says for each backup how it came about (“by hand”, “scheduled”, “before a change” or “uploaded”), with four buttons: “Check”, “Download”, “Restore” and “Delete”. Downloading, uploading, restoring and deleting ask for your password once more. Only automatic backups are thinned out.
The backups lie in the data folder under backups/, so on the same disk as nexdiary. Download one now and then and put it somewhere else.
Saving the master key
Each person has a key of their own for their diary, and all those keys are wrapped with the master key. It is made at the first start and lies on the server at keys/master.key.
- “Save master key”
In the same tab, card “Encryption”.
- Confirm
With your password and your second factor, that is the code from the app or “Confirm with a passkey”. Without a second factor of your own, nexdiary does not hand the key out.
- “Download”
You get the file
nexdiary-master.key. - Keep it apart
Not next to the backups, but in your password manager, say, or on a stick in a drawer. Whoever has both can read every diary.
Afterwards the card shows “Last saved on …”, and the point “Master key saved” in “Ready for the internet?” turns green. Older backups also hold the keys of accounts deleted since; with the master key, their diaries in there can still be read.
Restoring
“Check” tells you whether a backup is complete and what restoring it would add and remove. “Restore” first backs up the current state, then restarts nexdiary with the backup, and everybody signs in again. nexdiary turns down a backup from a newer version of nexdiary, and one from a server with a different master key.
Moving to a new server
- On the old server
“Back up now”, “Download” the backup, and save the master key if you do not have it yet.
- Put the key in place before nexdiary starts
On the new server, make the folder
keysin the data folder and put the file in askeys/master.key(that is,nexdiary-master.keyrenamed). - Start and set up
As in the chapter Setting up, with the setup code and an operator account.
- Upload, check, restore
Under “Backup” with “Upload a backup”, then “Check” and “Restore”. After the restart everything is back, and you sign in with your old account.
Putting the key in only after the setup goes wrong: it then does not fit the keys that have come about on the new server in the meantime, and nexdiary does not start. If that has happened, begin again there with an empty data folder and the key in its place. Keep the data folder on a disk in the machine itself, not on a network share (SMB or NFS).
Updating
nexdiary does not update itself. When a new version is out, the page “About nexdiary” says so, as long as “Check once a day” is on there (on out of the box; nexdiary asks GitHub for it). With Docker Compose you fetch it like this:
docker compose pull && docker compose up -dAt the start nexdiary adds what the database lacks and makes a backup of its own first (“before a change”). That backup is the way back. An older version cannot open a database from a newer one, and says so when it starts.
Forgot your password, as the operator
The first account has no mail address, so “Forgot your password?” does not help you. If there is a second operator, they can send you a link under “Accounts”. Otherwise you make the link yourself on the server:
docker exec -it -u nexdiary nexdiary python -m app.reset_link julePut your user name in place of jule; without a name the command lists the accounts. On Unraid, open the container's console and type gosu nexdiary python -m app.reset_link jule. The command prints a link, or a path when no public address is set; open that at the address you reach nexdiary under. The link works once and for 24 hours, and also ends the wait after too many tries. Your second factor stays, and so does your diary.
Good to knowTry a move once with a second instance on another machine, with the backup and the master key. Then you know the two fit together before you really need them.