DominusVault – Administrator Guide

A guide for IT administrators. It covers the initial configuration, adding database servers and repositories, user accounts, backup plans and day-to-day upkeep of the console.

0. Panel navigation

The sidebar is arranged in this order: Dashboard → Operations → Connections → Backup/restore → Plans → the expandable History & analysis group (History, Reports registry, Charts, Logs) → Settings → License (overview only) → Documentation. You activate license keys in Settings, on the License tab.

DominusVault dashboard with sidebar, alerts, Recovery Score and trends
The dashboard straight after signing in. Menu on the left, widgets with alerts and Recovery Score above, backup size chart at the bottom.

1. First-time setup

After installation, open the panel in your browser. The first time you do, you get the setup wizard (/setup) instead of the login screen. Installation is described first, separately for Windows and Docker, and the wizard steps follow.

Windows installation (Setup.exe)

Windows installer — information (README) page
The first screen of the Windows installer, showing the README before the license agreement.
  1. Download DominusVault-Setup-<version>.exe from the releases page (or DominusVault-Setup-latest.exe).
  2. Run the file as administrator. Windows will show a UAC prompt.
  3. Work through the wizard: language, information page, license, install folder (C:\Program Files\DominusVault by default).
  4. On the tasks page, leave PostgreSQL tools (pg_dump/psql) ticked if the server does not have them yet. You can also add a desktop icon and the Caddy reverse proxy (HTTPS, usually port 8445).
  5. Once the files are copied, the installer registers the DominusVault Windows service and may open the /setup wizard in your browser.
Windows installer — additional tasks
On the additional tasks page you pick the PostgreSQL tools, the desktop shortcut and the optional HTTPS proxy (Caddy).

Docker installation (Windows and Linux)

DominusVault Docker package contents
The ZIP package holds install.cmd or install-linux.sh, the Compose files and the DominusVault-app-….tar image.

Download DominusVault-Docker-<version>.zip from www.dominusvault.pl/releases/docker/. The full guide is the INSTRUKCJA-INSTALACJA.md file inside the package. In short:

  1. Install Docker Desktop (Windows) or Docker Engine 24+ (Linux) and wait until the status reads Running.
  2. Extract the ZIP into the install directory. We suggest C:\DominusVault\Docker on Windows and /opt/dominusvault on Linux. Do not pull the installer script out of the package on its own.
  3. Run the installer: double-click install.cmd on Windows, or run ./install-linux.sh on Linux. The script loads the image from the tar file, writes .env and starts the containers.
  4. Open http://localhost:8444/setup, or the same address using the host's LAN IP.
install.cmd console during Docker installation
A typical install.cmd run: the script loads the image and brings the containers up with Compose.

Setup wizard (/setup)

DominusVault login screen
Once the wizard finishes, the panel asks you to sign in with the administrator account created during setup.
/setup wizard — encryption key unlock
On an installation that is already configured, /setup asks for the encryption key from the original setup and then returns you to the login screen. On a first run the wizard walks through the application database, the admin account, the key and the repository.

The wizard takes you through these steps:

  1. Language – the default panel language for the whole organization.
  2. Application database – the PostgreSQL server where DominusVault creates its DominusVault database with settings, accounts and plans. Usually a server you already run, often the very one you back up.
  3. Administrator account – username, password and optionally an e-mail address for password resets and notifications.
  4. Encryption key – the wizard generates it for you. The key protects passwords and .dvb archives, so put a copy somewhere safe straight away. In a Docker installation, leave the field empty if the key is already in .env.
  5. E-mail (SMTP) – optional, for reports and password resets.
  6. Notifications (Gotify) – optional.
  7. Backup repository – a local disk, an SMB share or S3-compatible storage.
  8. Backup tools – optional; on Windows some of the tools are already bundled.
  9. Source servers – add them now or later under Settings.
  10. License – activation is optional. Without a key you get a local 30-day trial, and the Free edition after that.

Passwords and credentials are stored encrypted in the database. Anything you set in the wizard can be changed later under Settings.

Uninstalling Docker (test machine / clean start)

The full procedure is in INSTRUKCJA-INSTALACJA.md in the ZIP. In short:

  1. In the install directory, run docker compose -f docker-compose.prod.yml --env-file .env down -v. That removes the containers along with the bundled PostgreSQL volume.
  2. If setup created the database on your PostgreSQL server, run DROP DATABASE IF EXISTS "DominusVault" there. down -v leaves that database alone.
  3. Delete .env and the contents of data\, which hold the encryption key and application data. Only wipe the backup folder if you also want to start with an empty repository.
  4. Extract the new ZIP, run install.cmd or install-linux.sh, and go through /setup from the beginning.

Updating Docker (production)

The easiest way to update is from the panel: Settings → Application updates (see section 17). If you prefer to do it by hand, updating comes down to swapping the application image. Do not use down -v, do not overwrite .env (it holds the encryption key, the PostgreSQL password and the path to the backup folder), and do not run the /setup wizard from scratch.

  1. Take a copy of .env and the data\ directory.
  2. Extract the new ZIP into the same directory and run the installer (install.cmd or install-linux.sh). Answer no when it asks about overwriting .env — that keeps your encryption key and passwords. The script loads the new image from the package for you, without logging in to a registry.

The full Docker procedure is described in INSTRUKCJA-INSTALACJA.md from the ZIP package.

Sign in with your existing administrator account. The local repository still points to the backup folder on the server disk (the same one shown in Settings).

Import configuration from an existing database (reinstall / Docker)

If PostgreSQL still holds a DominusVault database from a previous installation, the wizard offers to import the saved settings. Enter the same encryption key you used during the first setup, because without it the program cannot decrypt the passwords held in the database. Once the key is accepted, the panel loads the settings from the database immediately (servers, repositories, plans, mail) and goes to the login screen, so you do not have to click through the remaining wizard steps. Sign in with your existing administrator username and password, and make any further changes, such as SMTP, the repository or the password, under Settings.

Reconfiguration via the wizard (/setup)

On a server where DominusVault is already configured, the /setup URL is protected by the encryption key from the original installation. Once you enter the key, the settings from the database are applied immediately and you are back at the login screen, exactly as with the import after a reinstall. Change SMTP, the repository or the administrator password after signing in, under Settings.

2. Settings – overview

Settings — Application parameters
The Application parameters tab: active repository, filename patterns, .dvb compression and the look of the menu.

3. Adding database servers

Settings — SQL database servers
The list of source servers for PostgreSQL, MySQL and MS SQL. Test the connection before you save an entry.

You can add the first server in the setup wizard, although that step is optional. Every further backup source is added under Settings → Servers:

For PostgreSQL the application picks the backup tool that matches the server version by itself. MS SQL backups can be written in the product's own .dvb archive format.

Migration (Backup/restore wizard → Migrate): on Standard you can move a database to another server running the same engine (PG→PG, MySQL→MySQL, MSSQL→MSSQL). Trial and Professional add cross-engine migration in all six directions (PG↔MySQL, PG↔MSSQL, MySQL↔MSSQL, by copying tables directly), with trial staying inside its own slot limits. You pick the source and target servers in the wizard.

Tip: use an address that resolves from the machine or container where DominusVault runs. A name that works from your own workstation does not always resolve the same way for the service.

4. Backup repositories

Settings — Backup repositories
Repositories on a local disk, an SMB share and S3 storage. Each one shows its usage and an access test button.

A repository is where backup files end up: a local disk, an SMB share on a NAS, or S3-compatible object storage (MinIO, AWS S3, Cloudflare R2 and similar). Inside it, or under the chosen prefix on S3, the program creates a subfolder for each server and each database. Before your first backup, add at least one repository under Settings → Repositories or in the /setup wizard, and check it with Test access.

Windows (installer .exe)

Docker (application in a container)

In the panel you see and edit the folder on this computer/server disk (e.g. D:\DominusVault\backup). DominusVault maps it to the local repository for you — you do not need to know any internal container path.

Under Settings → Backup repositories you see Backup folder on this computer. You can change it; after saving, recreate the DominusVault service (installer: docker compose up -d) so new copies physically land in the new place. Until recreate, copies still go to the previous folder.

EnvironmentPath in panelNotes
Windows + Docker folder from the installer, e.g. D:\DominusVault\backup install-windows.ps1 asks for the folder and writes it to .env
Linux + Docker (server) e.g. /backup/dominusvault created by install-linux.sh

What to check before you start:

  1. The backup folder on disk exists (the install script creates it) and has enough space for the backups you plan.
  2. On Linux, the directory has to be writable by the user running Docker. Usually chmod 775 on the backup folder is enough, and the install script sets ownership for you.
  3. On Windows with Docker Desktop, the backup folder from the installer (e.g. D:\DominusVault\backup) must be writable by Docker.
  4. Change the location in the panel (Settings → Repositories) or in .env (DOMINUS_BACKUP_DIR) as described in INSTRUKCJA-INSTALACJA.md — then recreate the service.

NAS and SMB shares in Docker: enter a UNC path \\server\share\backups with credentials. That is a separate repository — it does not use the local backup folder block above.

S3-compatible (MinIO / AWS / R2) — what each field means

S3 is file storage reached over the network, either a "disk in the cloud" or MinIO on your own server. You do not need an Amazon account; any endpoint that speaks the S3 API will do. Under Settings → Repositories set the storage type to S3-compatible (MinIO / AWS / R2). Below is the same form with each field explained.

DominusVault Settings — S3-compatible repository form (English UI)
The S3 repository form. The table rows below follow the fields in the same order, from top to bottom.
Field in the UIWhat it isWhat to enter
Storage type The kind of backup destination. Choose S3-compatible (MinIO / AWS / R2) rather than local disk or SMB.
Name A label used only inside DominusVault, on the repository list and in plans. Something like Cold MinIO or R2 off-site. It does not have to match the bucket name.
S3 endpoint URL The address of the storage API, which is not always the provider's web console. Use HTTPS and no trailing slash. For MinIO, something like https://minio.company.local:9000; for Cloudflare R2, the address from the R2 console; for AWS, the regional S3 endpoint from their documentation.
S3 bucket The container that holds the objects. It is not an ordinary folder, and you create it at the provider beforehand. The exact name of an existing bucket, case included. DominusVault normally does not create the bucket for you.
S3 prefix (optional) A logical subfolder inside the bucket, so backups stay apart from other objects. For example dominusvault or prod/sql. An empty field means the root of the bucket.
S3 region The region name that most S3 clients insist on. AWS: the bucket's real region, e.g. eu-central-1. MinIO and most self-hosted setups: usually leave us-east-1 unless the vendor says otherwise. R2: normally auto, or the value from the Cloudflare documentation.
Force path-style (MinIO) The addressing style. The bucket goes into the URL path (…/bucket/…) instead of a subdomain (bucket.endpoint/…). MinIO and most self-hosted setups: tick it. AWS S3: usually leave it clear. If you hit NoSuchBucket, SSL or DNS errors, try toggling this first.
Object Lock retention (days) How many days a freshly written backup stays untouchable on the S3 side, with no way to delete or overwrite it. This is your protection against ransomware and accidental deletion. 0 turns the lock off, which is a sensible setting while testing. 30 means a 30-day lock. It only works when the bucket has Object Lock enabled at the provider; the field in the panel protects nothing on its own.
Object Lock mode How strict the lock is. GOVERNANCE is the default, and an administrator with the right privileges can sometimes override it, depending on the provider. COMPLIANCE is stricter, and not even an administrator can delete a file before its date. Start with GOVERNANCE, or with retention 0.
Access key The public API identifier, the S3 equivalent of a username. The key from the MinIO console, from AWS IAM, or an R2 API token. It is not your DominusVault panel login.
Secret key The secret API password, kept encrypted in the application database. Paste it once when you add the repository. Never send it by e-mail or in a screenshot.
Step by step: create the bucket, generate an access and secret key pair, then in the panel set the S3 type, your own name, the endpoint, the bucket, the prefix dominusvault, the region as above, path-style depending on MinIO or AWS, and Object Lock retention 0. Then Save and Test access. Only once the test passes should you enable Object Lock on the bucket at the provider and set the retention days.
Cold / immutable: the note in the form is a reminder that real delete protection needs Object Lock on the bucket itself. A lock set only in the panel, with no support from the storage, will not stop a ransomware attack.

Before your first backup to S3, check that:

  1. The bucket exists and the key pair can write, read and list. If you use retention in the panel or the cleanup actions, it also needs delete rights.
  2. The DominusVault machine can reach the endpoint (firewall, VPN, HTTPS).
  3. Test access in Settings succeeds.
  4. The repository is selected as a target in the backup plan or the wizard. A common arrangement is local or SMB storage day to day, with S3 as a second, off-site copy.

Common

Manage backups — logical and native
Manage backups screen: pick repository, server and database; table with size and type, filters (type, date/time), and collapsible groups.

5. Backup plans

Backup plans list
The list of backup and verification plans, with schedule, retention, a manual run button and job progress.
Backup/restore wizard — choose operation
The Backup/restore wizard, where you choose the operation: backup, restore, decrypting .dvb to .sql, migration or uploading a file from disk.

Under Backup plans you define jobs that run on a schedule or on demand. In a plan you set:

Important — native scope: the native engine (FULL / DIFF / LOG, point-in-time recovery with STOPAT, every-N-minutes schedules for LOG, and verification against a native chain) is currently available for MS SQL databases only. PostgreSQL and MySQL still use logical .dvb backups; native equivalents for those engines are planned later.

Editing a plan opens a panel on the right. You can jump straight to the section you need, the schedule for instance, without walking through the whole wizard again.

Running a plan:

Progress and history: both appear on the plan list, as a percentage bar and a database counter, and on the Operations page. Each run is its own row. You can cancel a single job, a selected group, or all of them at once.

A recommendation: point the plan at an explicit list of production databases rather than at "all databases". That way you avoid copying temporary databases, such as those with a _test suffix.

Backup plans — native MSSQL engine
Plan wizard with an MS SQL server: backup policy FULL + differential (DIFF) + LOG (point-in-time recovery), .dvenc encryption.

Verification (test restore) can also use the native engine (MS SQL only): the plan does not create a new backup; it restores the FULL→DIFF→LOG chain (.bak / .diff / .trn, including .dvenc) onto a test database — optionally with STOPAT when you pick a specific point in time. The test target must be MS SQL and must see the same backup files (a shared native backup folder on the SQL server).

5.0a Native MS SQL recovery (FULL + DIFF + LOG / point-in-time)

This path is MS SQL only (Professional / Enterprise; lab). When a plan stores native backups — FULL (.bak), DIFF (.diff), LOG (.trn) — open Backup/restore multiple databases → MSSQL native recovery, pick a FULL point, optional DIFF and LOG files and a target database name. Unchecking a LOG automatically clears newer LOGs (restore stops at the older segment). .dvenc files are decrypted automatically with the same key as .dvb. Restoring under a different name relocates the data files so the source database files are not overwritten.

Native MS SQL recovery — FULL, LOG and STOPAT
Native recovery screen: FULL points (with DIFF/LOG counts), chain, STOPAT, and VERIFYONLY / Restore.

5.1 Backup verification plans (test restore)

This is a separate plan mode, and it does not create a new backup. Instead it restores the latest backup, or one you choose, onto a test server and checks that the archive can be decrypted and imported.

Verification works on the Trial, Standard, Professional and Enterprise editions, but not on Free. On the product site customers most often choose Standard, largely for this feature.

If verification sits there with no progress, stop it with Cancel on the Operations page. Very large databases, the ones measured in gigabytes, need a matching amount of RAM and temp disk space on the DominusVault host; see the performance section for detail.

5.2 Recovering .dvb without DominusVault

A .dvb archive is an encrypted, compressed logical backup. Once you decrypt it in the panel, which works on Free as well, you get a plain SQL file for that engine. You can load it with the PostgreSQL, MySQL or SQL Server tools without running DominusVault any longer.

6. Notifications

Settings — Notifications
Notification settings: SMTP, Gotify, webhooks for Slack, Teams and Discord, and report retention.

E-mail (SMTP)

Enter the details of your company mail server: host, port, username and password. Reports go out over SMTP, so port 25 without encryption, 587 with STARTTLS or 465 over SSL. Port 993 is IMAP, the inbox side, and the wizard rejects it. Once saved, send a test message. Backup and restore reports can be attached as CSV and PDF files.

Gotify (optional)

Gotify sends short push notifications to a server of your own. It is handy when you would rather not rely on e-mail alone. Enter the server address, the application token and the priority, then send a test notification.

7. Product license

DominusVault license overview
The License page shows the edition, slot usage and a comparison of packages. Keys are activated under Settings.

The License item in the sidebar shows the license holder, the edition, the expiry date and slot usage (servers, database workloads, plans, concurrent jobs) against your limits. It also compares your package with the higher ones and links to the purchase or upgrade page.

Activation and offline import are handled under Settings → License:

Without a valid license, some backup operations may be restricted.

8. Logs and audit

Operations page — job progress and history
The Operations page with running jobs, their progress, and the history of finished operations.

Under History & analysis → Logs you get three views:

9. Users and permissions

Settings — Users
The account list with roles, access blocking and permissions for individual panel sections.

Accounts are created with either the administrator or the user role. On top of that you can restrict:

Panel sectionWhat it allows
DashboardStatus, alerts and quick actions
OperationsProgress of parallel jobs and the persistent operation history; available with Dashboard, Plans or Backup permission
HistoryThe list of completed backups and restores, in the History & analysis group
ReportsThe registry of operation reports in CSV and PDF, with in-panel preview, filters and downloads; needs the Reports permission
ChartsBackup size and duration trends, with size anomalies marked
ConnectionsActive sessions on the database servers
Backup/restoreRunning backups and restores
Backup plansViewing plans and running them manually
SettingsSystem configuration, normally administrators only
LogsApplication and audit logs, in the History & analysis group
LicenseSlot usage overview and package comparison; activation stays in Settings

How to grant the Reports permission:

  1. Sign in as an administrator and open Settings.
  2. Go to the Users tab.
  3. Next to the account, click Permissions (the clipboard icon).
  4. Tick the Reports checkbox, along with any other sections the user should reach.
  5. Click Save permissions. After refreshing the panel, the user will see Reports registry in the menu.

Administrators can reach every section by default. An account with the user role and no Reports tick will not see the registry, although it can still use the dashboard export if it has dashboard access.

10. Reports and retention

CSV/PDF reports registry
The reports registry: view the table and PDF in the panel, or download the files from the reports folder in the repository.
PDF report personalization
PDF report personalization: logo, accent color, report language and the set of columns for each operation type.
Backup size charts
The charts show how backup size changes over time. You set the anomaly threshold under Notifications.
Operation history
History of completed backups, restores and verifications, with filters.

Reports and notifications

Under Settings → Notifications you configure:

After every operation, meaning backups, restores, uploads, decryption, migration and verification, the system saves a CSV and PDF report in the Reports registry and in the reports folder inside the repository.

PDF report personalization

Under Settings → PDF report personalization you set:

In the reports registry you can look at the table and the PDF in the panel itself, without downloading anything.

On the dashboard, the Got it button hides an alert. It comes back if the problem is fixed and then returns.

11. Encryption key — details

DominusVault works with one master key, set in the first-run wizard. The key does two jobs:

The key itself lives in the installation's secure store: the program data folder on Windows, the application data volume in Docker. Keep a copy of it in your organization's password manager. Losing the key means you can decrypt neither the backups nor the stored passwords.

In a Docker installation the script already places the key in the .env file. The first time you open /setup, leave the key field empty so that exactly the same key is used. Otherwise .env, the key store and the database will drift apart.

Important rules

12. Plan schedules and time zone

The time in a plan, 02:00 for instance, refers to the application time zone. You set it in the panel: Settings → Time zone (Europe/Warsaw by default).

If a plan "did not run overnight", check in turn whether DominusVault was on at that hour, whether the plan list shows a last run, what the logs say, and which time zone is set in Settings. If the app was off at the scheduled time, it still runs that plan once for that day (or week / month) after it starts — you do not need to start it by hand unless the run was interrupted mid-way.

13. Performance and hardware

OperationGuidance
Backing up a large databaseFree repository space at least equal to the database size. How long it takes depends mostly on the network and the disk.
Verifying or restoring a large databaseCount on at least 4 GB of RAM and several GB free on the temp disk. Decompressed SQL is often many times larger than the .dvb file.
Parallel jobsThe number of concurrent jobs depends on the license: Free and trial 1, Standard 5, Professional 10, Enterprise unlimited. On a modest host, avoid running a large backup and a verification at the same time.
SchedulePlan times use the application time zone, which you set in the panel (Settings → Time zone).
MS SQLFor large dumps the import uses sqlcmd when it is available, and it is included in the Docker image. Large SQL scripts put pressure on memory both on SQL Server and on the DominusVault host.

Edition limits (summary)

14. Advanced application settings

Database connections — session view
A view of the connections to your databases, useful when planning a maintenance window.

The Application tab in Settings holds, among other things:

TLS certificates: you can upload your own certificate for the built-in HTTPS, or put a reverse proxy in front of the application.

15. Troubleshooting

SymptomWhat to check
Docker panel unreachable from another PCThe panel listens on port 8444 on the network — check that port 8444 is open in the firewall. Connect to the server's LAN IP address (its Ethernet or Wi-Fi address).
Empty database list on a serverSettings → Servers → Test connection. The host has to be reachable from the machine running DominusVault.
Backup decryption errorThe key in Settings must be the one the backup was encrypted with. A file from another installation needs that installation's key.
Verification of a large database failsMemory and temp disk space. Run the verification on its own, without a large backup alongside it.
Nightly plan with no reportWhether DominusVault was running at the scheduled hour, and which time zone is set in Settings. As a quick check, use the Run button.
Backup of 0 B, or ERROR statusThe repository access test, write permissions and free disk space.
MS SQL backup failsThe port, usually 1433, and a user with backup rights. You also need the ODBC 18 driver, which ships with the Windows installer.

When you raise a support ticket, include the version from the user menu → Recent changes and the part of the log covering the failure (History & analysis → Logs).

16. HTTPS and panel access

17. Updates

Under Settings → Application updates you can check whether a newer version exists and install it without leaving the panel.

Updating from the panel (recommended)

  1. Open Settings → Application updates.
  2. Click Update to the new version.
  3. The panel downloads the package, verifies the SHA256 checksum and installs the update.

If updating from the panel is not an option, use the manual download link or the procedure below. The change list is in the user menu → Recent changes.

Manual Docker update

  1. Download the ZIP package from the releases page.
  2. Unpack it into the same installation directory.
  3. Run install.cmd on Windows or ./install-linux.sh on Linux.
  4. Answer no when asked about overwriting .env, which keeps your key and passwords.

If the panel reports a problem connecting to Docker, run this in the installation directory:

docker compose -f docker-compose.prod.yml --env-file .env up -d --force-recreate

18. In-app documentation

The Documentation menu opens the guide inside the panel. Administrators can switch between the user guide and the administrator guide with the button on the left or the link at the top of the page. Additional HTML files may sit in the installation folder for reading in a browser without signing in.

19. Interface language

You set the default language in the first-run wizard. Each user can then change it for themselves, in the menu under the icon in the top-right corner.

DominusVault – Database backup console. Copyright (c) DominuNet, Maciej Janas.