Incus Backup is a comprehensive web based backup utility for all of your Incus servers.
769
Current release: v1.1.2
ScottiBYTE Incus Backup is a centralized backup, restore, and scheduled backup platform for Incus containers and Incus virtual machines across every remote available to an Incus client.
The application is designed to run as a lightweight client-only control node using Docker Compose. It leverages the native Incus client and existing trust relationships already configured on the Docker host.
Unlike traditional backup systems, ScottiBYTE Incus Backup does not require an Incus server locally. The container securely mounts the host Incus client configuration read-only and communicates directly with remote Incus servers using the official Incus CLI.
The result is a clean, lightweight, multi-remote backup solution with no database dependencies and no complicated infrastructure requirements.
The ScottiBYTE Incus Backup dashboard provides:
.tar.gz.tar.gz backup filesThis application intentionally operates as an Incus client only.
The Docker container does not store or generate Incus trust credentials internally.
Instead, the existing Incus client configuration from the Docker host is mounted read-only into the container:
${HOME}/.config/incus:/incus-client:ro
This ensures:
The Docker host must have the Incus client installed before trust relationships can be configured.
Ubuntu example:
sudo apt update
sudo apt install -y incus-client
Verify:
incus version
Run this on every Incus server you want ScottiBYTE Incus Backup to manage:
incus config set core.https_address :8443
Verify:
ss -ltnp | grep 8443
On the remote Incus server:
incus config trust add IncusBackup
Copy the generated trust token.
Run these commands on the Docker host.
Example remote:
incus remote add vmsmist https://vmsmist:8443 --accept-certificate
Paste the trust token when prompted.
Verify connectivity:
incus remote list
Verify instances are visible:
incus list vmsmist:
Repeat for every Incus server you want ScottiBYTE Incus Backup to manage.
Examples:
incus remote add vmsstorm https://vmsstorm:8443 --accept-certificate
incus remote add vmsrain https://vmsrain:8443 --accept-certificate
incus remote add mondo-2 https://mondo-2:8443 --accept-certificate
mkdir -p ~/incusbackup
cd ~/incusbackup
mkdir -p backups
mkdir -p uploads
Create:
nano docker-compose.yml
Paste:
services:
incusbackup:
image: scottibyte/incusbackup:latest
container_name: incusbackup
restart: unless-stopped
ports:
- "3030:3030"
environment:
PORT: "3030"
INCUS_CONF: /incus-client
INCUS_BACKUP_DIR: /app/backups
INCUS_COMPLETED_JOB_TTL_MS: "180000"
volumes:
- ./backups:/app/backups
- ./uploads:/app/uploads
# Read-only host Incus trust mount
- ${HOME}/.config/incus:/incus-client:ro
security_opt:
- no-new-privileges:true
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:3030"]
interval: 30s
timeout: 10s
retries: 3
labels:
- "com.centurylinklabs.watchtower.enable=true"
docker compose up -d
View logs:
docker logs -f incusbackup
You should see:
ScottiBYTE Incus Backup running at http://0.0.0.0:3030
Backup directory: /app/backups
Completed jobs auto-hide after 180 seconds.
Scheduled backup engine active. Interval 60 seconds. Concurrency 1.
Verify the Incus CLI exists:
docker exec -it incusbackup which incus
Verify remotes:
docker exec -it incusbackup incus remote list
Verify instances:
docker exec -it incusbackup incus list vmsmist:
Replace vmsmist with one of your configured remotes.
Open a browser and go to:
http://YOUR-SERVER-IP:3030
Example:
http://172.16.2.247:3030
Version 1.1.0 adds a built-in scheduled backup engine.
Schedules are stored persistently in:
~/incusbackup/backups/settings.json
The scheduler runs inside the Incus Backup application container and uses the same backup engine as manual exports.
Supported schedule types:
The dashboard supports:
Bulk scheduling is especially useful when filtering by remote, instance type, protection state, or backup age.
When the Incus Backup application backs up its own IncusBackup container, it is automatically protected.
The app forces its own backup mode to:
Live - self protected
This prevents the backup process from stopping the container that is running the backup application.
Other containers and virtual machines can still use either Live or Stop + Restart mode.
Exports the instance while it remains running.
Recommended for:
Gracefully stops the instance before backup and restarts it afterward.
Recommended for:
During Stop + Restart mode the dashboard temporarily displays:
Backing Up
instead of Running or Stopped so the UI accurately reflects backup activity.
Protection status is color coded:
| Color | Meaning |
|---|---|
| 🟢 Green | Backed up today |
| 🟡 Yellow | 1–7 days old |
| 🟠 Orange | Backup stale |
| 🔴 Red | No backups |
Expand a container or VM row to view backups.
Restores using the original instance name.
Disabled automatically if the original instance already exists.
Restores using a generated safe clone name such as:
container-restored
or:
container-restored-2
The dashboard supports uploading external .tar.gz Incus exports.
Workflow:
Uploaded files are staged in:
~/incusbackup/uploads
Docker host paths:
~/incusbackup/backups
~/incusbackup/uploads
Container paths:
/app/backups
/app/uploads
Incus trust mount:
/incus-client
From the ~/incusbackup directory:
docker compose pull
docker compose up -d
View logs:
docker logs -f incusbackup
The compose file includes:
labels:
- "com.centurylinklabs.watchtower.enable=true"
This allows automated updates using Watchtower if desired.
Verify remotes on the Docker host:
incus remote list
Verify remotes inside the container:
docker exec -it incusbackup incus remote list
Verify:
docker exec -it incusbackup which incus
Verify mount:
docker exec -it incusbackup ls -la /incus-client
Verify connectivity:
incus list vmsmist:
Check remote server API:
ss -ltnp | grep 8443
Verify container:
docker ps
Check logs:
docker logs -f incusbackup
Verify port:
ss -ltnp | grep 3030
Edit:
ports:
- "3030:3030"
Example alternative:
ports:
- "3031:3030"
Restart:
docker compose up -d
Access:
http://YOUR-SERVER-IP:3031
IncusBackup application container is self-protected and forced to Live modescottibyte/incusbackup:latest
scottibyte/incusbackup:1.1.0
Need help with Incus Backup, Docker deployment, Incus profile management, container creation, or ScottiBYTE utilities?
Join the ScottiBYTE Rocket.Chat community:
New users can start in #general. From there, you can find other ScottiBYTE project channels and community discussions.
For bugs and feature requests, please continue to use GitHub Issues. For quick questions and community discussion, use Rocket.Chat.
Content type
Image
Digest
sha256:b1fc3b9c7…
Size
103.1 MB
Last updated
4 months ago
docker pull scottibyte/incusbackup