Upgrades and backups

Backups

HouseGRC can back itself up on a schedule: Settings ▸ Backups sets where backups go and when, and whether they include evidence as well as the databases. The databases inside a backup stay encrypted.

The encryption keys are not in those backups, on purpose. Back up the housegrc_secret volume separately, once and after any key change, and keep it somewhere other than the backups. To restore you need both.

For a complete copy at the volume level, stop HouseGRC and copy all three volumes:

docker compose stop housegrc
docker run --rm -v housegrc_data:/v -v "$PWD":/out alpine tar czf /out/housegrc-data.tgz -C /v .
docker run --rm -v housegrc_evidence:/v -v "$PWD":/out alpine tar czf /out/housegrc-evidence.tgz -C /v .
docker run --rm -v housegrc_secret:/v -v "$PWD":/out alpine tar czf /out/housegrc-secret.tgz -C /v .
docker compose start housegrc

Upgrading

  1. Read what's new for anything to do before upgrading.
  2. Make a backup, as above.
  3. Set HOUSEGRC_VERSION in .env to the new version.
  4. Run:
docker compose pull
docker compose up -d
docker compose logs -f housegrc

HouseGRC upgrades its database on start. Try upgrades on your test installation first if you have one.

Rolling back

Set HOUSEGRC_VERSION back and restore the backup you made before upgrading: a database upgraded by a newer version is not guaranteed to work with an older one.