The Disposable Database: Inside duplicati/documentation

How a GUI-first backup engine uses field-level SQLite encryption and stateless caching to survive complete hardware failure.

7 min read • View on GitHub • More from duplicati

A heavy iron vault suspended by a glowing tether over crumbling wooden scaffolding. It represents the secure remote state surviving local hardware failure.
The local machine is treated as an ephemeral resource, while the remote encrypted vault remains the indestructible source of truth.
Key Takeaways

The Paradox of the Local Cache

Building a reliable backup system requires solving a fundamental paradox. The software needs massive amounts of local state to efficiently compare file hashes and calculate incremental changes. Yet the local machine hosting that state is exactly the hardware that will eventually be destroyed or compromised.

The duplicati/documentation repository reveals how the core engine resolves this tension through a dual-database architecture. The system maintains a Server Database for global settings and authentication alongside a Local Database for per-backup caching. The documentation heavily emphasizes a critical design principle: the Local Database is entirely disposable.

The Disposable Cache Recovery: Rebuilding local state from encrypted remote shards.

Security in Plain Sight

Encrypting an entire SQLite database file is a common approach to securing local credentials. It is also an operational nightmare. Full-file encryption breaks standard database inspection tools and complicates debugging for maintainers.

Duplicati solves this via field-level encryption. The technical manuals detail how the engine encrypts only specific sensitive strings, such as passwords and API tokens, before writing them to the database. The surrounding schema, timestamps, and file paths remain perfectly readable in plaintext.

A vintage accountant's ledger book with specific columns covered by riveted metal plates, representing field-level database encryption.
Field-level encryption locks down sensitive credentials while leaving the database structure readable for standard tooling.

Compiling the Source of Truth

The documentation repository itself is a masterclass in managing legacy knowledge. For years, Duplicati relied on a fragmented community wiki. The transition to a modern GitBook architecture required more than just converting markdown files.

The repo utilizes a massive .gitbook.yaml redirect engine. This configuration preserves years of accumulated SEO value by mapping legacy flat URL structures to a strict, categorized new hierarchy. It is a docs-as-code pipeline designed to respect history while enforcing order.

The GUI-First Divide

The open-source backup landscape is dominated by CLI-native tools that prioritize terminal speed and content-defined chunking. Duplicati targets a completely different demographic. It is built around a native web interface and integrated support for over 25 cloud storage providers without requiring external command-line utilities.

Duplicati is better if you need a web UI for configuring backups or prefer a point-and-click interface over writing scripts.

selfhostingsh, Community Contributor, DEV Community · Duplicati vs Restic: Which Backup Tool to Self-Host?
FeatureDuplicatiRestic / Borg
Primary InterfaceWeb UI (Integrated)CLI Native
DeduplicationBlock-level IncrementalContent-Defined Chunking
Cloud SupportNative (25+ Providers)Requires rclone or SSH
Target AudienceProsumer / Home ServerSysadmin / Developer