Containerized mbsync IMAP backup & restore ā multi-arch, CVE-scanned
3.3K
Containerized mbsyncā (isync) that mirrors a
list of IMAP accounts ā defined in a .env file ā into local Maildir
backups, and can restore those backups to a new IMAP server.
amd64 + arm64).SYNC_INTERVAL.<backup>/<account>/, restorable and greppable.š Full documentation & source: https://github.com/Josiah-OGT/imap-backupā
latest, vX.Y.Z (releases), isync-<version> (e.g. isync-1.5.1),
sha-<short>, and a YYYYMMDD date tag on the weekly build. Pin a vX.Y.Z or
isync-<version> tag for reproducibility; use latest for the freshest isync.
docker pull unsalted1832/imap-backup:latest
1. Create docker-compose.yml:
services:
imap-backup:
image: unsalted1832/imap-backup:latest
container_name: imap-backup
env_file: .env
restart: unless-stopped
volumes:
- ./backups:/backups
- ./logs:/logs
2. Create .env with your accounts (numbered blocks; gaps are fine):
# Global (all optional ā defaults shown)
SYNC_INTERVAL=1h
RETAIN_DELETED=false # false = exact mirror; true = keep server-deleted mail
LOG_LEVEL=normal # normal | verbose | debug
# Account 1 (minimum: HOST, USER, PASS)
ACCOUNT_1_HOST=imap.gmail.com
[email protected]
ACCOUNT_1_PASS=app-password-here
# ACCOUNT_1_PORT=993 # optional (default 993)
# ACCOUNT_1_TLS=IMAPS # IMAPS (default) or STARTTLS (+ PORT=143)
For Gmail/Outlook use an app password, not your login password. To avoid plaintext, use
ACCOUNT_N_PASSCMD(any command that prints the password).
3. Start the backup service:
mkdir -p backups logs
docker compose up -d
docker compose logs -f # live; also written to ./logs/imap-backup.log
The running backup service is left untouched:
docker compose run --rm imap-backup sync-once # a single backup cycle
docker compose run --rm imap-backup restore # restore all accounts
docker compose run --rm imap-backup restore 1 3 # restore specific indices
docker compose down # stop & remove the container
docker compose pull && docker compose up -d # update to the latest image
docker run)docker run -d --name imap-backup --env-file .env \
-v ./backups:/backups -v ./logs:/logs \
unsalted1832/imap-backup:latest
Run a single cycle instead of the loop:
docker run --rm --env-file .env \
-v ./backups:/backups -v ./logs:/logs \
unsalted1832/imap-backup:latest sync-once
Set the restore target per account in .env (omit any field to fall back to the
original source value):
ACCOUNT_1_RESTORE_HOST=imap.newserver.com
[email protected]
ACCOUNT_1_RESTORE_PASS=new-password
# optional: RESTORE_PRESYNC=true -> pull latest from source before pushing
Then run a one-off restore (restore pushes the local Maildir to the target):
docker compose run --rm imap-backup restore # all accounts
docker compose run --rm imap-backup restore 1 # specific account(s)
The service container reports healthy while backup cycles keep completing,
and unhealthy when the loop stalls (no cycle activity for SYNC_INTERVAL +
HEALTH_GRACE) or HEALTH_MAX_FAILURES consecutive cycles fail. A cycle still
in progress counts as healthy, and one-off sync-once / restore runs always
report healthy.
docker ps # STATUS shows (healthy) / (unhealthy)
docker inspect --format '{{.State.Health.Status}}' imap-backup
The failure reason (stale loop vs. failed cycles) is recorded in the
docker inspect health log.
| Variable | Default | Meaning |
|---|---|---|
SYNC_INTERVAL | 1h | Time between cycles (30, 30m, 1h, 1d). |
RETAIN_DELETED | false | false exact mirror (propagate server deletions); true archival (keep server-deleted mail). |
RESTORE_PRESYNC | false | Pull latest from source before a restore. |
HEALTH_GRACE | 5m | Slack beyond SYNC_INTERVAL before the loop counts as stale (unhealthy). |
HEALTH_MAX_FAILURES | 3 | Consecutive failed cycles before reporting unhealthy. |
LOG_LEVEL | normal | mbsync verbosity: normal (summary), verbose (-V), debug (-V -D). |
LOG_DIR | /logs | Logfile directory (mount it). |
LOG_MAX_SIZE | 10M | Rotate after this size. |
LOG_KEEP | 7 | Rotated logs retained. |
LOG_TIMESTAMPS | true | ISO timestamps on log lines. |
LOG_COMPRESS | false | gzip rotated logs. |
BACKUP_DIR | /backups | Maildir root (mount it). |
ACCOUNT_N_HOST / _USER / _PASS | ā | Required per account. |
ACCOUNT_N_PORT / _TLS / _NAME / _PASSCMD | 993 / IMAPS / address / ā | Optional. |
ACCOUNT_N_RESTORE_HOST/_PORT/_USER/_PASS/_TLS/_PASSCMD | source values | Restore target. |
root. PUID/PGID are not app settings ā to own the
files as yourself, add a user: line to the service and feed it your host IDs:
user: "${PUID:-0}:${PGID:-0}" # add under the imap-backup service
PUID/PGID (from id -u / id -g) in .env, or inline:
PUID=$(id -u) PGID=$(id -g) docker compose up -d. Pre-create backups/ and
logs/ as that user first. (With docker run, use --user "$(id -u):$(id -g)".):Z to the volume mounts, e.g.
./backups:/backups:Z.docker stop sends SIGTERM; the container finishes the
in-progress account, then exits.ACCOUNT_N_TLS=STARTTLS (+ ACCOUNT_N_PORT=143) for STARTTLS servers.Licensed under the terms in the repositoryā .
Content type
Image
Digest
sha256:d607f59d7ā¦
Size
5 MB
Last updated
4 days ago
docker pull unsalted1832/imap-backup