Run mysqldump to backup your databases periodically using the cron task manager in the container. Your backups are saved in /backup. You can mount any directory of your host or a docker volume in /backup. Otherwise, a docker volume is created in the default location.
- Usage
- Environment Variables
- Uploading Backups to S3 or S3-Compatible Services
- Docker Compose Examples
- Restore from a backup
docker container run -d \
--env MYSQL_USER=root \
--env MYSQL_PASS=my_password \
--link mysql \
--volume /path/to/my/backup/folder:/backup \
fradelg/mysql-cron-backupHealthcheck is provided as a basic init control.
Container is Healthy after the database init phase, that is after INIT_BACKUP or INIT_RESTORE_LATEST happens without checking if there is an error, Starting otherwise. No other checks are actually provided.
MYSQL_HOST: The host/IP of your MySQL database.MYSQL_HOST_FILE: The file in the container where to find the host of your MySQL database (cf. Docker secrets). You should use eitherMYSQL_HOST_FILEorMYSQL_HOST.MYSQL_PORT: The port number of your MySQL database.MYSQL_USER: The username of your MySQL database.MYSQL_USER_FILE: The file in the container where to find the username of your MySQL database (cf. Docker secrets). You should use eitherMYSQL_USER_FILEorMYSQL_USER.MYSQL_PASS: The password of your MySQL database.MYSQL_PASS_FILE: The file in the container where to find the password of your MySQL database (cf. Docker secrets). You should use eitherMYSQL_PASS_FILEorMYSQL_PASS.MYSQL_DATABASE: The database name to dump. Default:--all-databases.MYSQL_DATABASE_FILE: The file in the container where to find the database name(s) in your MySQL database (cf. Docker secrets). In that file, there can be several database names: one per line. You should use eitherMYSQL_DATABASEorMYSQL_DATABASE_FILE.
CRON_TIME: The interval of cron job to run mysqldump.0 3 * * sunby default, which is every Sunday at 03:00. It uses UTC timezone.MAX_BACKUPS: The number of backups to keep. When reaching the limit, the old backup will be discarded. No limit by default.INIT_BACKUP: If set, create a backup when the container starts.INIT_RESTORE_LATEST: If set, restores latest backup.EXIT_BACKUP: If set, create a backup when the container stops.TIMEOUT: Wait a given number of seconds for the database to be ready and make the first backup,10sby default. After that time, the initial attempt for backup gives up and only the Cron job will try to make a backup.
MYSQLDUMP_OPTS: Command line arguments to pass to mysqldump (see mysqldump documentation).MYSQL_SSL_OPTS: Command line arguments to use SSL.GZIP_LEVEL: Specify the level of gzip compression from 1 (quickest, least compressed) to 9 (slowest, most compressed), default is 6.USE_PLAIN_SQL: If set, back up and restore plain SQL files without gzip.TZ: Specify timezone in the container. E.g.,"Europe/Berlin". Default is UTC.REMOVE_DUPLICATES: Use fdupes to remove duplicate database dumps.
When S3_BUCKET is set, every dump is uploaded via the aws CLI right after it's created locally, both under its timestamped name and under latest.<database>.sql[.gz]. Local retention (MAX_BACKUPS, REMOVE_DUPLICATES) is unaffected: it only manages files inside /backup, the S3 upload just mirrors what's written there.
S3_BUCKET: Name of the bucket to upload backups to. If not set, no upload is performed.S3_PATH: Optional key prefix inside the bucket, e.g.my-project/backups. Default: bucket root.S3_ENDPOINT: Custom endpoint URL, required for S3-compatible services that aren't AWS, e.g.https://<ACCOUNT_ID>.r2.cloudflarestorage.comfor Cloudflare R2.S3_REGION: Region passed to the AWS CLI. Default:us-east-1. Some providers (e.g. Cloudflare R2) acceptauto.AWS_ACCESS_KEY_ID/AWS_ACCESS_KEY_ID_FILE: Access key used to authenticate. Use_FILEfor docker secrets.AWS_SECRET_ACCESS_KEY/AWS_SECRET_ACCESS_KEY_FILE: Secret key used to authenticate. Use_FILEfor docker secrets.S3_UPLOAD_OPTS: Extra command line arguments passed toaws s3 cp(e.g.--storage-class STANDARD_IA).
If you want to make this image the perfect companion of your MySQL container, use docker-compose. You can add more services that will be able to connect to the MySQL image using the name my_mariadb, note that you only expose the port 3306 internally to the servers and not to the host.
Security Tip: For production environments, prefer using Docker Secrets (
*_FILEvariables) or external.envfiles rather than writing plain-text passwords directly in compose files.
services:
mariadb:
image: mariadb
container_name: my_mariadb
expose:
- 3306
volumes:
- data:/var/lib/mysql
# If there is no schema, restore the last created backup (if exists)
- ${VOLUME_PATH}/backup/latest.${DATABASE_NAME}.sql.gz:/docker-entrypoint-initdb.d/database.sql.gz
environment:
- MYSQL_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD}
- MYSQL_DATABASE=${DATABASE_NAME}
restart: unless-stopped
mysql-cron-backup:
image: fradelg/mysql-cron-backup
depends_on:
- mariadb
volumes:
- ${VOLUME_PATH}/backup:/backup
environment:
- MYSQL_HOST=my_mariadb
- MYSQL_USER=root
- MYSQL_PASS=${MARIADB_ROOT_PASSWORD}
- MAX_BACKUPS=15
- INIT_BACKUP=0
# Every day at 03:00
- CRON_TIME=0 3 * * *
# Make it small
- GZIP_LEVEL=9
# As of MySQL 8.0.21 this is needed
- MYSQLDUMP_OPTS=--no-tablespaces
restart: unless-stopped
volumes:
data:The database root password passed to docker container by using docker secrets.
In example below, docker is in classic 'docker engine mode' (iow. not swarm mode) and secret sources are local files on host filesystem.
Alternatively, secrets can be stored in docker secrets engine (iow. not in host filesystem).
version: "3.7"
secrets:
# Place your secret file somewhere on your host filesystem, with your password inside
mysql_root_password:
file: ./secrets/mysql_root_password
mysql_user:
file: ./secrets/mysql_user
mysql_password:
file: ./secrets/mysql_password
mysql_database:
file: ./secrets/mysql_database
services:
mariadb:
image: mariadb:10
container_name: my_mariadb
expose:
- 3306
volumes:
- data:/var/lib/mysql
- ${VOLUME_PATH}/backup:/backup
environment:
- MYSQL_ROOT_PASSWORD_FILE=/run/secrets/mysql_root_password
- MYSQL_USER_FILE=/run/secrets/mysql_user
- MYSQL_PASSWORD_FILE=/run/secrets/mysql_password
- MYSQL_DATABASE_FILE=/run/secrets/mysql_database
secrets:
- mysql_root_password
- mysql_user
- mysql_password
- mysql_database
restart: unless-stopped
backup:
build: .
image: fradelg/mysql-cron-backup
depends_on:
- mariadb
volumes:
- ${VOLUME_PATH}/backup:/backup
environment:
- MYSQL_HOST=my_mariadb
# Alternatively to MYSQL_USER_FILE, we can use MYSQL_USER=root to use root user instead
- MYSQL_USER_FILE=/run/secrets/mysql_user
# Alternatively, we can use /run/secrets/mysql_root_password when using root user
- MYSQL_PASS_FILE=/run/secrets/mysql_password
- MYSQL_DATABASE_FILE=/run/secrets/mysql_database
- MAX_BACKUPS=10
- INIT_BACKUP=1
- CRON_TIME=0 0 * * *
secrets:
- mysql_user
- mysql_password
- mysql_database
restart: unless-stopped
volumes:
data:
Example using Cloudflare R2:
mysql-cron-backup:
image: fradelg/mysql-cron-backup
depends_on:
- mariadb
volumes:
- ${VOLUME_PATH}/backup:/backup
environment:
- MYSQL_HOST=my_mariadb
- MYSQL_USER=root
- MYSQL_PASS=${MARIADB_ROOT_PASSWORD}
- S3_BUCKET=my-backups
- S3_PATH=mysql
- S3_ENDPOINT=https://${CLOUDFLARE_ACCOUNT_ID}.r2.cloudflarestorage.com
- S3_REGION=auto
- AWS_ACCESS_KEY_ID=${R2_ACCESS_KEY_ID}
- AWS_SECRET_ACCESS_KEY=${R2_SECRET_ACCESS_KEY}
restart: unless-stoppedSee the list of backups in your running docker container, just write in your favorite terminal:
docker container exec <your_mysql_backup_container_name> ls /backupTo restore a database from a certain backup you may have to specify the database name in the variable MYSQL_DATABASE:
mysql-cron-backup:
image: fradelg/mysql-cron-backup
command: "/restore.sh /backup/201708060500.${DATABASE_NAME}.sql.gz"
depends_on:
- mariadb
volumes:
- ${VOLUME_PATH}/backup:/backup
environment:
- MYSQL_HOST=my_mariadb
- MYSQL_USER=root
- MYSQL_PASS=${MARIADB_ROOT_PASSWORD}
- MYSQL_DATABASE=${DATABASE_NAME}docker container exec <your_mysql_backup_container_name> /restore.sh /backup/<your_sql_backup_gz_file>if no database name is specified, restore.sh will try to find the database name from the backup file.
Set INIT_RESTORE_LATEST to automatic restore the last backup on startup.
Set EXIT_BACKUP to automatic create a last backup on shutdown.
mysql-cron-backup:
image: fradelg/mysql-cron-backup
depends_on:
- mariadb
volumes:
- ${VOLUME_PATH}/backup:/backup
environment:
- MYSQL_HOST=my_mariadb
- MYSQL_USER=${MYSQL_USER}
- MYSQL_PASS=${MYSQL_PASSWORD}
- MAX_BACKUPS=15
- INIT_RESTORE_LATEST=1
- EXIT_BACKUP=1
# Every day at 03:00
- CRON_TIME=0 3 * * *
# Make it small
- GZIP_LEVEL=9
restart: unless-stopped
volumes:
data:Docker database image could expose a directory you could add files as init sql script.
mysql:
image: mysql
expose:
- 3306
volumes:
- data:/var/lib/mysql
# If there is not scheme, restore using the init script (if exists)
- ./init-script.sql:/docker-entrypoint-initdb.d/database.sql.gz
environment:
- MYSQL_ROOT_PASSWORD=${MYSQL_ROOT_PASSWORD}
- MYSQL_DATABASE=${DATABASE_NAME}
restart: unless-stopped mariadb:
image: mariadb
expose:
- 3306
volumes:
- data:/var/lib/mysql
# If there is not scheme, restore using the init script (if exists)
- ./init-script.sql:/docker-entrypoint-initdb.d/database.sql.gz
environment:
- MYSQL_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD}
- MYSQL_DATABASE=${DATABASE_NAME}
restart: unless-stopped