Sign inSign up

arconixforge/mongodb-secure-backup

By arconixforge

•Updated over 1 year ago

Production-ready MongoDB backup with AES-256-GCM encryption, compression.

Image
Security
Databases & storage
0

778

arconixforge/mongodb-secure-backup repository overview

⁠MongoDB Secure Backup

License Python Docker

A secure, production-ready MongoDB backup solution with encryption, compression, and air-gapped deployment capabilities.

šŸ“– MEDIUM : https://medium.com/@arconixforge⁠ šŸ’» Git → https://github.com/ArconixForge⁠ 🐳 Docker → https://hub.docker.com/u/arconixforge⁠ šŸ“¦ Artifact → https://artifacthub.io/packages/search?user=ArconixForge⁠ 🐳 X → https://x.com/ArconixForge⁠

⁠Features

  • Comprehensive Backup: Export databases and collections to JSON with detailed metadata
  • Strong Security: AES-256-GCM encryption and HMAC integrity verification
  • Flexible Filtering: Include or exclude specific databases and collections
  • Performance Optimization: Parallel processing with configurable concurrency
  • Robust Error Handling: Automatic retries and detailed error reporting
  • Progress Tracking: Real-time progress monitoring for long-running backups
  • Multiple Compression Options: zlib, gzip, and LZMA with configurable levels
  • Air-Gap Support: Built for secure, isolated environments
  • Docker Ready: Hardened container with non-root execution

⁠Quick Start

Pull the Docker image:

docker pull arconixforge/mongodb-secure-backup:latest

Run a backup (basic):

docker run -v /path/to/backups:/backups \
  -e MONGO_HOST=your-mongodb-host \
  -e MONGO_PORT=27017 \
  -e MONGO_USERNAME=your-username \
  -e MONGO_PASSWORD=your-password \
  arconixforge/mongodb-secure-backup:latest auto-backup

Run a backup with encryption:

docker run -v /path/to/backups:/backups \
  -e MONGO_HOST=your-mongodb-host \
  -e MONGO_USERNAME=your-username \
  -e MONGO_PASSWORD=your-password \
  -e ENCRYPTION_ENABLED=true \
  -e ENCRYPTION_PASSWORD=your-secure-encryption-key \
  arconixforge/mongodb-secure-backup:latest auto-backup

⁠Configuration Options

⁠Environment Variables
VariableDescriptionDefault
MONGO_HOSTMongoDB host127.0.0.1
MONGO_PORTMongoDB port27018
MONGO_USERNAMEMongoDB username-
MONGO_PASSWORDMongoDB password-
MONGO_AUTH_DBAuthentication databaseadmin
USE_SSLEnable SSL connectionfalse
SSL_CA_FILEPath to SSL CA file-
CONNECTION_TIMEOUT_MSConnection timeout in ms30000
BACKUP_OUTPUT_DIROutput directory for backups/backups
PRETTY_JSONFormat JSON outputtrue
MAX_CONCURRENT_EXPORTSNumber of parallel exports3
RETRY_ATTEMPTSNumber of retry attempts3
RETRY_DELAY_SECONDSDelay between retries2
CHUNK_SIZEBatch size for large collections1000
EXCLUDE_DBSComma-separated list of DBs to exclude-
EXCLUDE_COLLECTIONSCollection exclusion patterns-
ENCRYPTION_ENABLEDEnable encryption for backupsfalse
ENCRYPTION_PASSWORDPassword for encryption-
COMPRESSION_METHODCompression (none, zlib, gzip, lzma)zlib
COMPRESSION_LEVELCompression level (1-9)6
⁠Configuration File

The tool can also use a configuration file. A default file is generated on first run, or you can mount your own:

docker run -v /path/to/config.ini:/app/mongodb_backup.ini \
  -v /path/to/backups:/backups \
  arconixforge/mongodb-secure-backup:latest auto-backup

⁠Detailed Usage

⁠List Databases
docker run arconixforge/mongodb-secure-backup:latest --list-dbs
⁠Export Specific Databases
docker run -v /path/to/backups:/backups \
  -e MONGO_HOST=your-mongodb-host \
  arconixforge/mongodb-secure-backup:latest --export --databases database1,database2
⁠Create Encrypted Archive
docker run -v /path/to/backups:/backups \
  -e MONGO_HOST=your-mongodb-host \
  -e ENCRYPTION_ENABLED=true \
  -e ENCRYPTION_PASSWORD=your-secure-key \
  arconixforge/mongodb-secure-backup:latest --export --create-archive
⁠Test Connection
docker run -e MONGO_HOST=your-mongodb-host \
  arconixforge/mongodb-secure-backup:latest --test-connection

⁠Security Considerations

  • No Root Access: Container runs as a non-root user (UID 10001)
  • No Sensitive Information in Config: Credentials should be passed via environment variables
  • Encryption Key Management: For production, consider using a secrets manager
  • Regular Security Updates: Keep the image updated with the latest security patches
  • Data Validation: All inputs are validated and sanitized to prevent injection attacks

⁠Architecture

This solution comprises:

  • Python Backup Engine: Core backup functionality with encryption and compression
  • MongoDB Tools Integration: Leverages official MongoDB tools for compatibility
  • Docker Container: Secure, minimal container with proper isolation
  • Configuration System: Flexible configuration via environment variables or config file

⁠Development

⁠Prerequisites
  • Python 3.12+
  • Docker
  • MongoDB Tools (mongosh, mongoexport)

⁠Test Docker image

docker run --rm arconixforge/mongodb-secure-backup:latest --test-connection


Please ensure your code adheres to the existing style and includes appropriate tests.

## License

This project is licensed under the Apache License 2.0 - see the [LICENSE](LICENSE) file for details.

## Acknowledgements

- MongoDB Team for their excellent database and tools
- Python Cryptography library for secure encryption
- Docker for containerization
- All open-source contributors who make projects like this possible

Tag summary

Content type

Image

Digest

sha256:c08d7c438…

Size

123.5 MB

Last updated

over 1 year ago

docker pull arconixforge/mongodb-secure-backup:v1.1