Skip to content
junkerderprovinzPublic

About

Backup and disaster recovery for Docker containers, VMs and folders on your own server. Restored containers and VMs come back in place, with their settings. Encrypted, off-site, built on restic.

Topics

Resources

Stars

42 stars

Watchers

0 watching

Forks

Repository files navigation

BombVault

Build  Lint  Docker Pulls  Image Size  Arch  restic  Unraid  License: AGPL-3.0  Documentation


Your Unraid server, sealed in a vault. Drop a backup. Detonate a restore.

Containers, VMs, appdata, the flash drive and any folder you point it at. BombVault also backs up itself, because a backup tool that cannot save its own skin is a hobby project. One click puts it all back: containers reappear in the Docker tab, VMs in the VM tab, already configured. No reinstall, no rebuild, no evening lost.

Built on restic, so every snapshot is deduplicated, incremental and encrypted before it leaves the box. Off-site copies can be append-only, which is a polite way of saying ransomware is welcome to knock.


Android testers wanted: join the Google Play closed test

Important

Android testers wanted. Google Play only lists an app from a new developer account after at least 12 testers have kept it installed for 14 days. If you have an Android phone:

  1. Join the tester group.
  2. Open the test page and tap Become a tester.
  3. Install BombVault from Google Play and keep it for 14 days. Using it for real helps most, and anything that goes wrong is welcome as an issue.

Install from Unraid's Community Applications   Run it with Docker   Read the documentation


On Google Play soon   On F-Droid soon   Download the Android app
Always downloads the latest build


Get ParleyPort, the relay for KnightLoader and BombVault   Get the BombVault Widget for the Unraid dashboard


A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.

If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.


Buy me a coffee   PayPal   Donate with crypto


Table of Contents

  1. Screenshots
  2. What it does
  3. How it compares
  4. Getting started
  5. Documentation
  6. How AI is used here
  7. Support this project

1. Screenshots

BombVault dashboard: recovery point, next backup, last result and the live activity log
Dashboard: the recovery point, the next backup and the last result sit above a live activity log. The log also shows the off-site copy and the tamper test that proves the far side refuses a delete.


BombVault Recovery: the guided disaster-recovery flow onto a fresh install
Recovery: a guided flow for a fresh install. Check that BombVault can read your backups, restore its own settings, then attach your container, VM and flash backups and restore them.


BombVault Containers: each container with its schedule switch, placement and restore check
Containers: each container has its own schedule switch, a choice of local, off-site or both, a one-click backup and a restore check. Filters and bulk include or exclude sit above the list.


BombVault Settings: configuration organised into pages for domains, paths, schedules, off-site, notifications and integrity
Settings, organised into pages (General · Look · Storage · Retention · Schedules · Containers · Off-site · Cloud access · Notifications · Integrity · Security · Pairing · Integrations · System). General turns each backup domain on or off and holds the language and quiet toasts; Look holds the theme, colours, corners and animation. Nothing here has a Save button; every change is written as you make it.


BombVault Receiver: a received off-site copy with its snapshots by source and an independent check
Receiver: the other end of an off-site copy, read-only. It lists what arrived from each source and when, and runs its own integrity check on this hardware instead of trusting the sender.


The Android app with its list of servers, the activity log of all of them and the pairing screen
The Android app: every server of your group on one list, their activity in one log, paired by twelve words.


2. What it does

  • Backs up the whole server. Containers with their appdata and definition, VMs with their disks, XML and NVRAM, the Unraid flash, any folder, ZFS datasets with their children, and BombVault's own settings. PostgreSQL, MySQL and MariaDB containers are dumped first. Features
  • Restores to a running state. A restored container comes back in the Docker tab with its image, settings and data, a VM in the VM tab with its disks and NVRAM. Every restore shows what it will change before it starts. Features
  • Copies off site, item by item. Encrypted, to one or more targets that can be append-only. A destination is set up once, with a wizard that knows S3 storage services, your own servers and every cloud drive rclone supports. Each container, VM and folder set then lights the places that get its backups, and its card says how many sites hold it and whether 3-2-1 is met. Off-site & recovery
  • Proves that restores work. A restore check after each item's first backup, scheduled drills, and a start test that runs a restored container in an isolated network. Features
  • Notices when a backup looks wrong. Much more new data than usual, a source that shrank, a run that took far longer. When a source shrinks sharply, its old backups are kept until you acknowledge the finding. Features
  • Fits into the rest of your setup. Several servers pair by twelve words, an Android app shows them all, and AI assistants, scripts and Home Assistant read the status over MCP, an HTTP API and MQTT. Android app, MCP server, API and integrations

It runs as one Docker container on Unraid, TrueNAS Scale or a plain Docker host and stores everything with restic. The idea of one-click backup with automatic reinstall comes from VolumeVault by @Darkdragon14; BombVault is a separate implementation (see Credits).


3. How it compares

On Unraid, backups usually run through Appdata.Backup, a CA plugin that archives appdata folders, or through a general engine such as Duplicati, Kopia or BorgBackup. They save files well, but a restore gives you files back, not a running container or VM.

The closest counterpart is Vault by @ruaan-deysel, a native Unraid plugin built on the same idea: it recreates containers and re-defines VMs on restore, and it has a good deal of what BombVault has, down to changed-block VM backups and Home Assistant. BombVault is ahead on getting data back: restic reads its backups without BombVault, the off-site copy can be append-only, and restores are tested for real, up to starting a restored container in isolation. Worth a look.

BombVault Vault (plugin) Appdata.Backup (CA) Duplicati Kopia BorgBackup
Restore brings a container back whole (image, env, ports, labels) ✅ ✅ ⚠️ files and XML ❌ ❌ ❌
Restore re-defines a VM, not only its disks ✅ ✅ ⚠️ XML only ❌ ❌ ❌
VM backups read only changed blocks ✅ qcow2 ✅ qcow2 ❌ ❌ ❌ ❌
Database dumps for recognised database containers ✅ ✅ ❌ ❌ ❌ ⚠️ via Borgmatic
Installed Unraid plugins ✅ one by one from the flash backup ✅ ⚠️ in flash backup ❌ ❌ ❌
ZFS datasets as a source ✅ ✅ ❌ ❌ ⚠️ via action scripts ⚠️ via Borgmatic
Deduplication ✅ ✅ opt-in ❌ ✅ fixed blocks ✅ ✅
Client-side encryption ✅ on by default ✅ opt-in ❌ ✅ ✅ ✅
Backups readable with a standard open-source CLI ✅ restic ⚠️ not with dedup ✅ tar ⚠️ Python script ✅ kopia ✅ borg
Append-only or immutable off-site copy ✅ ❌ ❌ ✅ ✅ ✅
Scheduled backup waits until the app is idle ✅ ✅ ❌ ❌ ❌ ❌
Scheduled test restores, not only a checksum read ✅ ❌ ❌ ❌ ❌ ⚠️ via Borgmatic
Start test: a restored container is started in isolation and checked ✅ ❌ ❌ ❌ ❌ ❌
Off-site upload slows down while a media server streams ✅ ✅ any outside traffic ❌ ❌ ❌ ❌
Several off-site targets, each with its own credentials ✅ ⚠️ one per job ❌ ✅ ⚠️ CLI sync ⚠️ via Borgmatic
Each item chooses which off-site targets get a copy ✅ ⚠️ a second job per target ❌ ⚠️ a job per destination ❌ ⚠️ via Borgmatic
Each item chooses local only, local and off-site, or off-site only ✅ ⚠️ by the jobs it is in ❌ ⚠️ a job per destination ❌ ⚠️ via Borgmatic
Shows how many sites hold each item and whether 3-2-1 is met ✅ ⚠️ for the whole server, not per item ❌ ❌ ❌ ❌
Pre/post-backup hooks ✅ ✅ ✅ ✅ ✅ ⚠️ via Borgmatic
Live progress and cancel, backup and restore ✅ ⚠️ no restore cancel ⚠️ log, no percentage ✅ ⚠️ no restore percentage ⚠️ CLI or Vorta
Notifications ✅ SMTP, Matrix, Apprise, more ✅ Discord, Unraid ✅ Unraid's agents ✅ email, Telegram, HTTP ✅ email, Pushover, webhook ⚠️ via Borgmatic
Anomaly detection (size, duration, shrink) ✅ ✅ ❌ ⚠️ paid Console ❌ ❌
AI assistant access (MCP) ✅ ✅ ❌ ⚠️ third party ❌ ❌
Documented HTTP API for scripts, with its own tokens ✅ ✅ ❌ ⚠️ undocumented ⚠️ undocumented ❌
Home Assistant integration ✅ over MQTT ✅ ❌ ⚠️ third party ⚠️ third party ⚠️ third party
Announces itself on the network (mDNS) ✅ ✅ ❌ ❌ ❌ ❌
Backs up desktops and laptops ❌ ❌ ❌ ✅ ✅ ⚠️ Windows experimental
Runs outside Unraid ✅ ⚠️ replica only ❌ ✅ ✅ ✅
In Unraid Community Applications ✅ ✅ ✅ ✅ community template ✅ community template ✅ community template
Android app ✅ APK, Google Play in closed test ❌ ❌ ❌ ❌ ❌
Track record ⚠️ since 2026, one maintainer ⚠️ since 2026, one maintainer ⚠️ since 2023, feature-frozen ✅ since 2008 ✅ since 2019 ✅ since 2015

✅ yes · ⚠️ partly · ❌ no. The BombVault column is v9.8.0. The other tools were checked against their code and docs on 25 September 2026, the start-test row and Vault's cells for idle waiting, mDNS, Home Assistant and changed-block VM backups again on 28 September 2026 against Vault v2026.09.01, and the rows for placement, 3-2-1 and the Android app on 4 October 2026.


4. Getting started

On Unraid, install BombVault from Community Applications. The one setting it needs is APP_KEY, a secret you make with openssl rand -hex 32. Keep a copy somewhere other than the server, because without it nobody can read the encrypted backups. Then open https://<server-ip>:3443, switch on the kinds of backup you want under Settings, and press Back up now on a container.

On any other Docker host or on TrueNAS Scale, take deploy/docker-compose.generic.yml, set APP_KEY and the Host Data volume, and run docker compose up -d. VM and ZFS backups reach the host over SSH, so BombVault's public key has to be added there once. Getting started and Configuration cover the template, the mounts, every variable and the SSH setup.

Android app

On Google Play soon   On F-Droid soon   Download the Android app
Always downloads the latest build

Every release has the app as bombvault-android.apk. On any server, open Settings, Pairing, Show phrase and scan the QR code with the app: it adds every server of your group, shows what runs on all of them, also away from home over the relay, and opens each one already signed in. Google Play has it in a closed test for now, and F-Droid follows. The Android app page has the details, and the privacy policy lists what the app stores and sends.


5. Documentation

The documentation, in 26 languages, has what this page leaves out:

  • Getting started: requirements, the Unraid template, other Docker hosts and TrueNAS Scale, the first backup and building from source
  • Android app: pairing by QR code, servers outside a group, settings and downloads
  • Features: everything BombVault backs up, restores, checks and reports, and the companion apps
  • Configuration: environment variables, mounts, the security model, VM backup over SSH and the off-site setup
  • Off-site & recovery: destinations, placement per item, append-only copies, tamper tests, pairing, the recovery kit and guided recovery
  • ZFS datasets: items and child datasets, restores and the safety snapshot
  • MCP server: connecting AI assistants, keys and limits
  • API and integrations: the HTTP API, Home Assistant and mDNS
  • Troubleshooting: failed backups, locks, VM connections and a container that restarts
  • VM backup over SSH: the full SSH and networking guide, including TrueNAS Scale

6. How AI is used here

One knight builds this, and AI is one of the tools I work with, the same way I work with an editor or a compiler. It helps me write code and documentation and it checks my work, and that saves me a good many evenings. It does not make the decisions, though. I read and understand everything before it ships, and if something here breaks, that is on me and not on the tool.

You do not have to take my word for it. The code is open and every release note is written by hand. The issue tracker shows how problems actually get handled, including the ones I got wrong the first time. If you find something that is not right, open an issue and I will look at it.


7. Support this project

Questions? Ask in Discussions or check the support thread. Bugs, ideas or feature requests? Please open a GitHub issue.

A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.

If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.

Buy me a coffee   PayPal   Donate with crypto

About

Backup and disaster recovery for Docker containers, VMs and folders on your own server. Restored containers and VMs come back in place, with their settings. Encrypted, off-site, built on restic.

Topics

Resources

Stars

42 stars

Watchers

0 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages