Skip to main content
Edge can run on Kubernetes as well as Docker Compose. Only Edge is covered here; run Central with Docker Compose. This is an example, not a packaged chart. The image, ports, and folders are the same as in the Compose install, so adapt the manifest to your cluster. The scheduling, networking, and secret handling are up to you. Flux on the control plane deploys one Edge pod per node; each pod encrypts that node's folders and uploads to Central outside the cluster.

How it maps to Compose

Edge backs up files on a specific machine, so the pod has to run on the node that holds them and mount host folders directly.

Example manifest

This runs one Edge on the node named node-1 and backs up /home/alice. Replace the hostname, paths, EDGE_ID, and CENTRAL_URL.
edge.yaml
Then open http://node-1:6556/ and continue from Sign in and add the credential in the Compose install.

Things to keep in mind

  • Keep /config on persistent storage. It holds the settings database, encryption.key, and installation.id. Losing it means a new encryption key and a new instance on Central; losing the key means losing access to existing snapshots. Back up the key as described in Encryption key.
  • Run one pod per set of folders. Edge’s state is local to the pod. Use replicas: 1 with the Recreate strategy, and don’t share /config, /data/state, or /data/spool between Edges.
  • Edge always scans /scan. Inside the container, SCAN_DIR only sets the host path Edge shows in its UI. To back up several folders or drives, mount each at /scan/<name> as in Multiple folders and drives.
  • Mounts need write access. Edge writes .upload_dir markers and restores files into /scan. The image runs as root, so files it creates on the host are root-owned.
  • Reaching the UI. hostPort matches the Compose setup. If you put Edge behind a Service or Ingress instead, keep it private or use HTTPS; see Sign-in.
  • Credentials. Paste the Edge credential in Edge’s UI, as with Compose. It is stored in /config, so no Kubernetes Secret is needed. To set a first admin password, add INITIAL_ADMIN_PASSWORD from a Secret with valueFrom.secretKeyRef.
  • Moving from Compose. Point the hostPath volumes at the existing Compose folders and keep the same EDGE_ID. Stop the Compose container first (docker compose down, without -v). Edge keeps its key, settings, and instance ID.
  • Updating. Change the image tag or digest and re-apply, or let a tool such as Renovate or Flux do it. With Recreate, the old pod stops before the new one starts.

Several machines

Repeat the Deployment once per node with its own name, nodeSelector, EDGE_ID, and paths, or generate them from one template.

Sample: one template per device with Flux

This keeps a single Edge template in Git and builds one copy per device. Flux fills in the ${...} values from each device’s entry.
device-template/backup-edge.yaml
device-template/kustomization.yaml
Add one Flux Kustomization per device:
The nodeSelector pins each copy to its device, so the pod only exists once that node joins the cluster. If the device previously ran Edge with Compose in <home>/backup-edge, these hostPath folders pick up its existing config, key, and state.