File migration image with dry-run, path validation, rsync, and encrypted archive support.
2.5K
migrate is a small Debian-based Docker image for moving files or directory
contents between paths or mounted volumes. It is designed for scriptable
one-shot migration jobs, with path validation, dry-run support, optional
encrypted archive handling, and readable logs.
Image built by this module:
svcops/migrate:latest
rsync for directory migration, with a cp fallback.compress.sh.| Command | Purpose |
|---|---|
migrate.sh | Main migration entrypoint. |
compress.sh | Creates an AES-encrypted .7z archive for a source path. |
commons.sh | Shared logging, validation, and archive helper functions. |
The Docker image copies these commands to /usr/local/bin.
When SRC is a directory, migrate.sh copies the contents of SRC into
TARGET.
Before copying directory contents, the script cleans TARGET and preserves only
TARGET/.gitignore when that file exists. Existing files in TARGET should be
treated as replaceable migration output.
When SRC is a file, the script copies that file into TARGET.
| Variable | Required | Default | Description |
|---|---|---|---|
SRC | Yes, unless using CLI args | Absolute source path. Can be a file or directory. | |
TARGET | Yes, unless using CLI args | Absolute target directory path. | |
ARCHIVE_PASSWORD | No | Password used to decrypt a matching encrypted archive before migration. | |
DRY_RUN | No | false | Set to true to print intended actions without changing data. |
LOG_LEVEL | No | INFO | Supported values: INFO, DEBUG. |
VERBOSE | No | false | Set to true to enable verbose rsync output. |
PRESERVE_PERMISSIONS | No | true | Set to false to skip owner, group, and permission preservation in rsync. |
PARALLEL_MODE | No | Reserved flag; currently not used by the migration logic. |
Basic directory migration:
docker run --rm \
-v /host/src:/data/src \
-v /host/dst:/data/dst \
-e SRC=/data/src \
-e TARGET=/data/dst \
svcops/migrate:latest
Dry run:
docker run --rm \
-v /host/src:/data/src \
-v /host/dst:/data/dst \
-e SRC=/data/src \
-e TARGET=/data/dst \
-e DRY_RUN=true \
svcops/migrate:latest
Use CLI arguments instead of environment variables:
docker run --rm \
-v /host/src:/data/src \
-v /host/dst:/data/dst \
svcops/migrate:latest \
migrate.sh /data/src /data/dst
Docker Compose example:
services:
migrate:
image: svcops/migrate:latest
volumes:
- ./src:/data/src
- ./dst:/data/dst
environment:
SRC: /data/src
TARGET: /data/dst
Run with environment variables:
SRC=/path/to/source TARGET=/path/to/target migrate.sh
Run with CLI arguments:
migrate.sh /path/to/source /path/to/target
Run a dry run:
DRY_RUN=true SRC=/path/to/source TARGET=/path/to/target migrate.sh
Show help:
migrate.sh --help
compress.sh creates a password-protected 7-Zip archive for SRC, stores a
marker file, and then removes the original source contents.
Create an archive with SRC from the environment:
SRC=/opt/src/some_dir compress.sh your-password
Or pass both source and password as arguments:
compress.sh /opt/src/some_dir your-password
Generated files:
| File | Description |
|---|---|
/.encrypted_data.<normalized_src_path>.7z | Encrypted archive. |
/.encrypted_marker.<normalized_src_path> | Marker containing the original source parent path. |
To decrypt and migrate, run migrate.sh with the same SRC and
ARCHIVE_PASSWORD. If the archive and marker exist, the script extracts the
archive back into the recorded parent directory, then performs the normal
migration into TARGET.
docker run --rm \
-v /host/src:/data/src \
-v /host/dst:/data/dst \
-e SRC=/data/src \
-e TARGET=/data/dst \
-e ARCHIVE_PASSWORD=your-password \
svcops/migrate:latest
Build the image with the provided script:
./build.sh
The Dockerfile accepts BUILD_ORIGIN. When BUILD_ORIGIN=LOCAL, Debian APT sources are
rewritten to Aliyun mirrors during image build.
docker build \
--build-arg BUILD_ORIGIN=LOCAL \
-t svcops/migrate:latest \
.
SRC and TARGET.TARGET must be a directory path, not a file.TARGET cannot be the same path as SRC.TARGET cannot be a system directory such as /, /usr, /var, or /etc.SRC is a directory, TARGET cannot be inside SRC.TARGET as a parent of the source file directory;
this can hide source data through volume overlay behavior.compress.sh as destructive: after a successful archive is created, the
source file is deleted or the source directory contents are cleared.debian:bookworm-slimbash, rsync, p7zip-fullmigrate.shContent type
Image
Digest
sha256:6d17e3052…
Size
32.5 MB
Last updated
3 months ago
docker pull svcops/migrate