Self-hosting
Server maintenance
Update the sync server, back up its database, and know what is kept apart from your other services.
Update the server
cp /home/USER/burrow-sync/* /home/USER/burrow-sync/.dockerignore /opt/burrow-sync/
rm -r /home/USER/burrow-sync
cd /opt/burrow-sync
docker compose up -d --build.env and the database stay as they are.
Back up the database
cd /opt/burrow-sync
docker compose exec burrow-sync node backup.js
docker cp burrow-sync:/data/backup-$(date +%F).db /home/USER/
chown USER /home/USER/backup-*.dbscp USER@SERVER_IP:~/backup-*.db .docker compose logs -f in /opt/burrow-sync.
What is isolated and what isn’t
Network: other containers can’t reach the sync server. Data: its own volume and SQLite database. Configuration: its own folder and .env.Resources: at most 128 MB of RAM and half a CPU, so it can’t slow down anything else. Container: runs as a non-root user with a read-only file system, no Linux capabilities, no privilege escalation and (except with 5E) no internet access.