Files
BackupX/docs-site/docs/deployment/configuration.md
Wu Qing 5827074334 feat: 优化集群部署与堡垒机接入 (#106)
支持受限网络、正向代理、私有 CA 与 SSH 堡垒机部署 Agent。

加固 Docker、systemd、Nginx、安装器、Release 校验与可信代理边界,并完善命令队列索引、前端安装向导及中英文运维文档。
2026-08-09 02:45:17 +08:00

3.7 KiB

sidebar_position, title, description
sidebar_position title description
4 Configuration Reference All server.yaml configuration keys with defaults and matching environment variables.

Configuration Reference

BackupX loads ./config.yaml from the working directory by default. You can override the path with --config. Every key can also be set via a BACKUPX_ prefixed environment variable.

Full config reference

server:
  host: "0.0.0.0"             # BACKUPX_SERVER_HOST
  port: 8340                  # BACKUPX_SERVER_PORT
  mode: "release"             # release | debug
  external_url: ""            # BACKUPX_SERVER_EXTERNAL_URL — stable public Master URL
  trusted_proxies:             # BACKUPX_SERVER_TRUSTED_PROXIES — exact proxy IPs/CIDRs
    - "127.0.0.1"
    - "::1"
  web_root: ""                # BACKUPX_SERVER_WEB_ROOT — built frontend directory

database:
  path: "./data/backupx.db"   # BACKUPX_DATABASE_PATH — embedded SQLite

security:
  jwt_secret: ""              # BACKUPX_SECURITY_JWT_SECRET — auto-generated if empty
  jwt_expire: "24h"           # BACKUPX_SECURITY_JWT_EXPIRE
  encryption_key: ""          # AES-256-GCM key for storage config encryption

backup:
  temp_dir: "/tmp/backupx"    # BACKUPX_BACKUP_TEMP_DIR
  max_concurrent: 2           # BACKUPX_BACKUP_MAX_CONCURRENT
  retries: 3                  # Per-upload rclone low-level retries
  bandwidth_limit: ""         # e.g. "10M" to cap transfers at 10 MB/s

log:
  level: "info"               # debug | info | warn | error
  file: "./data/backupx.log"

Secret generation

If jwt_secret or encryption_key is empty on first start, BackupX generates a random value and persists it to the system_configs table. Keep a backup of data/backupx.db — losing it invalidates all existing encrypted storage configurations.

Environment variables

The environment wins when both file and env are set. All dot-paths become underscores and uppercase:

Config key Env variable
server.port BACKUPX_SERVER_PORT
server.external_url BACKUPX_SERVER_EXTERNAL_URL
server.trusted_proxies BACKUPX_SERVER_TRUSTED_PROXIES (comma-separated for env)
security.jwt_expire BACKUPX_SECURITY_JWT_EXPIRE
log.level BACKUPX_LOG_LEVEL
backup.max_concurrent BACKUPX_BACKUP_MAX_CONCURRENT
backup.temp_dir BACKUPX_BACKUP_TEMP_DIR
backup.bandwidth_limit BACKUPX_BACKUP_BANDWIDTH_LIMIT

Master external URL

Set server.external_url when BackupX is behind Docker, Nginx, a load balancer, or any reverse proxy whose internal Host is not reachable by remote Agents:

server:
  external_url: "https://backup.example.com"

This value is used when BackupX renders one-click Agent install scripts and docker-compose snippets. It must be reachable from every Agent host. Leave it empty only when X-Forwarded-Proto / X-Forwarded-Host are reliable and point to the same URL that Agents can access.

The install wizard can set an Agent-specific runtime URL for a proxy or SSH-bastion node. The public install link continues to use server.external_url, while the generated Agent config uses that override.

Trusted reverse proxies

BackupX trusts forwarded client-address headers only from server.trusted_proxies. The default permits loopback Nginx only. If a reverse proxy runs in another container or host, add its exact IP or subnet:

server:
  trusted_proxies:
    - "127.0.0.1"
    - "172.18.0.0/16"

Do not configure 0.0.0.0/0: client addresses feed authentication throttling, install-token throttling, and audit records. Set an empty list when BackupX is exposed directly and should trust no forwarded headers.