Where it is
- In the UI: Encryption Key on Scout’s main page. It’s masked, so click Copy to copy it.
- On disk:
config/encryption.keynext to Scout’sdocker-compose.yml(/config/encryption.keyinside the container).
Back it up
Keep the copied key somewhere that survives losing this machine, such as a password manager. Even better, back up the wholeconfig folder, which also holds the instance ID needed to restore through Scout.
When you need it
- Downloading from Station’s UI. Station asks for the key and decrypts the snapshot in your browser. See Download a snapshot.
- Restoring from Scout. Scout uses its current key automatically. See Restore.
Rotate the key
Rotate creates a new key for archives built from then on. Snapshots already on Station keep the old key, and staged archives aren’t rebuilt.1
Pause backup cycles
Wait for any backup or restore to finish. In Edit Scout Settings, turn on Pause uploads (skip backup cycles) and save. If the save is rejected because a cycle started, wait for it to finish and save again.
2
Download old snapshots you need
Download them from Station’s UI while it still accepts the current key.
3
Save the old key
Click Copy and store it somewhere safe.
4
Rotate
Click Clear staged backup on any job that has one, then click Rotate and confirm. Copy and store the new key.
5
Back up every job with the new key
Refresh Scout and clear any staged backup again, since Force Upload reuses staged archives that may use the old key. Then click Force Upload on every job, including unchanged ones, and wait for each to succeed. Force Upload works while cycles are paused.
6
Resume backup cycles
Turn off Pause uploads (skip backup cycles) and save.
