Where it is
- In the UI: Encryption Key on Edge’s main page. It’s masked; click Copy to copy it.
- On disk:
config/encryption.keynext to Edge’sdocker-compose.yml(/config/encryption.keyinside the container).
Back it up
Store the copied key somewhere that survives losing this machine, such as a password manager. Better still, back up the wholeconfig folder, which also holds the instance ID needed to restore through Edge.
When you need it
- Downloading from Central’s UI. Central asks for the key and decrypts the snapshot in your browser. See Download a snapshot.
- Restoring from Edge. Edge uses its current key automatically. See Restore.
Rotate the key
Rotate generates a new key for archives built afterward. Snapshots already on Central stay encrypted with the old key. Rotation does not rebuild staged archives or force unchanged jobs to upload.1
Pause backup cycles
Wait for any backup or restore operation to finish. In Edit Edge Settings, enable Pause uploads (skip backup cycles) and save. Confirm the setting is saved before continuing; if another cycle started and the save was rejected, wait for it to finish and try again. Keep cycles paused until the new-key backups below are complete.
2
Download anything you want to keep
Before rotating, download any older snapshots you may need from Central’s UI while it still accepts the current key.
3
Copy the old key
Click Copy and save the current key somewhere safe. The downloaded archives are already decrypted, but keep the key in case you need it later.
4
Rotate
With cycles paused, clear any staged backups, then click Rotate and confirm.
5
Save the new key
Copy and store the new key.
6
Create backups with the new key
Refresh Edge and check each job for staged backups again. Before its first Force Upload after rotation, use Clear staged backup if one is present: Force Upload reuses staged archives, which may still use the old key.Use Force Upload on each job, including jobs whose paths and sizes have not changed, and wait for each upload to finish. Force Upload works while backup cycles are paused. Confirm each job uploads successfully with the new key before continuing.
7
Resume backup cycles
If you paused cycles for this rotation, turn off Pause uploads (skip backup cycles) in Edit Edge Settings and save. Leave it enabled if you intended to keep cycles paused.
