Skip to main content
Each Edge creates its own encryption key on first start and uses it to encrypt every archive before upload. Central’s server never receives the key; its browser UI uses a key you paste locally to decrypt downloads.
If you lose the key, that Edge’s snapshots are permanently unrecoverable. Nobody, including Central, can decrypt them. Back it up now.

Where it is

  • In the UI: Encryption Key on Edge’s main page. It’s masked; click Copy to copy it.
  • On disk: config/encryption.key next to Edge’s docker-compose.yml (/config/encryption.key inside the container).
The file contains 32 raw key bytes. The UI’s Copy button provides their base64url text representation for pasting into Central. Preserve the file as-is when restoring Edge’s config; do not replace it with the copied text. Edge also shows a fingerprint of the key. Central uses the fingerprint to confirm you’ve pasted the right key before it decrypts a download. It isn’t secret and can’t be used to decrypt anything.

Back it up

Store the copied key somewhere that survives losing this machine, such as a password manager. Better still, back up the whole config folder, which also holds the instance ID needed to restore through Edge.

When you need it

  • Downloading from Central’s UI. Central asks for the key and decrypts the snapshot in your browser. See Download a snapshot.
  • Restoring from Edge. Edge uses its current key automatically. See Restore.

Rotate the key

Rotate generates a new key for archives built afterward. Snapshots already on Central stay encrypted with the old key. Rotation does not rebuild staged archives or force unchanged jobs to upload.
After rotating, older snapshots become hard to get back. Edge restores only use the new key. Central’s UI checks every pasted key against the latest fingerprint Edge reported, and that switches to the new key on Edge’s next upload. From then on Central rejects the old key, so its snapshots can’t be downloaded from the UI either.
1

Pause backup cycles

Wait for any backup or restore operation to finish. In Edit Edge Settings, enable Pause uploads (skip backup cycles) and save. Confirm the setting is saved before continuing; if another cycle started and the save was rejected, wait for it to finish and try again. Keep cycles paused until the new-key backups below are complete.
2

Download anything you want to keep

Before rotating, download any older snapshots you may need from Central’s UI while it still accepts the current key.
3

Copy the old key

Click Copy and save the current key somewhere safe. The downloaded archives are already decrypted, but keep the key in case you need it later.
4

Rotate

With cycles paused, clear any staged backups, then click Rotate and confirm.
5

Save the new key

Copy and store the new key.
6

Create backups with the new key

Refresh Edge and check each job for staged backups again. Before its first Force Upload after rotation, use Clear staged backup if one is present: Force Upload reuses staged archives, which may still use the old key.Use Force Upload on each job, including jobs whose paths and sizes have not changed, and wait for each upload to finish. Force Upload works while backup cycles are paused. Confirm each job uploads successfully with the new key before continuing.
7

Resume backup cycles

If you paused cycles for this rotation, turn off Pause uploads (skip backup cycles) in Edit Edge Settings and save. Leave it enabled if you intended to keep cycles paused.
Rotation doesn’t remove old snapshots from Central. Retention prunes them as new snapshots arrive, so they’ll age out after Keep Last Snapshots new backups of each job.