Module BackupGuard
| Editor | Theo Pequignot (theopequignot.fr) |
|---|---|
| Module ID | 194158 |
| Version | 2.2.0 |
| Dolibarr | 16 to 24 |
| Where to get it | DoliStore (BackupGuard) |
| Support | contact@theopequignot.fr |
| Presentation and support | modules.theopequignot.fr |
The native Dolibarr backup relies on the mysqldump command, which many shared hostings and containers do not have or refuse to run ("Failed to execute external command"). It is not scheduled, not encrypted, and stays on the same server as the data. BackupGuard makes a complete, scheduled, encrypted, verified backup and sends it elsewhere, without installing anything on the server.
What it does
- Pure PHP database dump: every Dolibarr table is read inside a consistent InnoDB snapshot (REPEATABLE READ, START TRANSACTION WITH CONSISTENT SNAPSHOT) and streamed to a SQL file, 2,000 rows at a time, grouped INSERT statements of about 1 MB. No binary needed, constant memory. When mysqldump exists and the option is enabled, it is used instead, with automatic fallback to the PHP dump.
- Documents included: the documents directory (DOL_DATA_ROOT) is added file by file to a zip, with configurable exclusions (default: temp folders, cache, .tmp files). The zip holds database.sql, manifest.json and documents/.
- AES-256-CBC encryption in the exact format of the openssl enc command (Salted__ header, PBKDF2-SHA256 10,000 iterations, PKCS7). A backup can be decrypted on any machine with:
openssl enc -d -aes-256-cbc -pbkdf2 -in backup.zip.enc -out backup.zip - Destinations, several at once: local copy (always), WebDAV (Nextcloud, ownCloud, kDrive, Infomaniak, Apache or nginx DAV), S3 compatible storage (AWS, Scaleway, OVH, Backblaze B2, Wasabi, MinIO, AWS signature v4 in pure PHP), FTP/FTPS (PHP extension ftp) and SFTP (PHP extension ssh2). Streaming uploads through curl. Each destination has a "Test connection" button that writes then deletes a witness file and shows the real error message.
- Scheduling: a daily Dolibarr scheduled job at the chosen hour (the Scheduled jobs module is enabled at installation), a CLI script for a system cron, and a URL trigger with a secret key for hostings without any cron. "Back up now" button. A lock prevents two simultaneous runs and is released even after a fatal error.
- Retention per destination: keep the N most recent backups (7 by default) plus the first backup of each month for M months (6 by default). Purge happens only after a successful upload to that destination.
- Verification and log: SHA-256 of the final file, zip integrity, end marker inside database.sql, control decryption of the first 64 KB. Every run is logged (status, size, duration, tables, rows, files, result per destination, trigger). Email alerts on failure and when no successful backup exists for N days.
- Dashboard (Tools, Backups): last successful backup, scheduling state, server diagnostic (mysqldump, extensions, disk space, estimated size), destinations, last thirty runs with download and deletion of the local file.
- Restore from the browser: chunked upload, analysis without any change, control of every SQL statement, safety backup of the current state, restore in short steps followed live, "Retry" and "Go back to the previous state" buttons if it stops halfway. Also used to move to a fresh Dolibarr where only BackupGuard is installed. A command line script is still provided for very large databases.
- Dolibarr update: the latest maintenance release and the next major version are offered; the official package is checked file by file against the checksums published by Dolibarr, a full backup and a copy of the replaced files are made first, and a button puts the previous files back as long as the database has not been upgraded.
Installation
Home → Setup → Modules → "Deploy/install external app/module", upload the zip and enable BackupGuard. Activation creates the table llx_backupguard_run, the protected directory documents/backupguard, the daily scheduled job and the URL key. The first local backup works with no setting at all.
Settings
- Content: database and documents (default) or database only; exclusion patterns; use of mysqldump when available.
- Encryption: on/off and passphrase (12 characters minimum, never displayed again). Without the passphrase a backup is unreadable: keep it somewhere else than on the server.
- Destinations: one section per type with its test button. Destinations whose PHP extension is missing are shown as unavailable with the reason.
- Scheduling and retention: hour of the daily backup, real state of the scheduled job (last and next run), trigger URL with its key and a cron line example, CLI command, number of backups kept, monthly retention.
- Alerts: email address (default: first administrator), "no successful backup for N days" delay, test email.
Permissions
- Read: dashboard and log.
- Run: start a backup, download and delete local files. A backup contains the whole database: grant this right with care.
- Setup: settings (administrators only).
- Restoring a backup and updating Dolibarr are reserved to administrators.
Restore a backup
From the browser
Tools, Backups, "Restore a backup" button.
- Upload the .zip or .zip.enc file (with its passphrase when encrypted), or pick a backup already on the server. The upload is sent in 2 MB chunks: the PHP upload size limit does not apply.
- Analysis, without changing anything: decryption, integrity, Dolibarr versions, content, modules. The restore is refused when the backup comes from a more recent Dolibarr than the installed one. Warnings (upgrade needed, different table prefix, missing modules) are shown before going on.
- Options: safety backup of the current state (recommended), documents, external modules. Confirm by typing the requested word.
- SQL control: every statement of the backup is checked before anything is written; only those of a dump, on Dolibarr tables, go through.
- Restore in short steps, followed live: the PHP maximum execution time is not an obstacle. Passwords encrypted by Dolibarr (SMTP, API keys) are re-encrypted for the new installation when the backup is encrypted.
- Log in again. When the backup comes from an older version, a button opens the Dolibarr upgrade wizard.
If the restore stops halfway, "Retry" resumes without duplicating anything and "Go back to the previous state" puts the safety backup back.
From the command line
For very large databases, or when Dolibarr no longer starts.
- Get the file dolibarr-<database>-YYYY-MM-DD-HHMM.zip.enc from a destination or the dashboard.
- Decrypt it with openssl (see above) or let the script do it (passphrase asked on the keyboard or read from the environment variable BACKUPGUARD_ENCRYPTION_PASSWORD).
- Put Dolibarr in maintenance mode, then on the target server:
php htdocs/custom/backupguard/scripts/restore.php backup.zip.enc --documents=/path/to/documents. - Clear the Dolibarr cache (documents/admin/temp) and log in again.
Update Dolibarr
Tools, Backups, "Update Dolibarr" button. The page shows the installed version, the checks (web server write access, curl and zip extensions, disk space) and two offers: the latest maintenance release, and the next major version (Dolibarr is upgraded one major version at a time).
- Prepare, without changing anything: download of the official package, then control of every file (PHP, JavaScript, migration SQL, images) against the checksums published on dolibarr.org and, for what they do not cover, those of the release on GitHub. An altered or unknown file makes the update refused.
- Confirm: full safety backup, copy of the files about to be replaced, then writing of the new files. The configuration and the custom directory are never touched.
- Upgrade the database with the Dolibarr wizard, opened by a button (upgrade.unlock since Dolibarr 17).
- As long as the database has not been upgraded, a button puts the previous files back.
Under Docker, the Dolibarr files belong to the image: the page explains what to do (change the image version) instead of replacing files.
Known limits
- Database dump for MySQL and MariaDB only. On PostgreSQL the module says so and backs up the documents only.
- Views, triggers and stored procedures are not exported (Dolibarr creates none).
- A backup can only be restored on the same or a more recent Dolibarr version.
- Updating Dolibarr requires the web server to be able to write the Dolibarr files; otherwise the page says so and nothing is changed. External modules are not updated.
- FTP and SFTP depend on the PHP extensions ftp and ssh2. WebDAV: Basic authentication only (Nextcloud, ownCloud, kDrive, Apache mod_dav).
- Encryption protects the remote copy, not the server itself: whoever reads the Dolibarr configuration reads the passphrase.
Compatibility
- Dolibarr 16 to 24, verified on 16.0, 18.0, 20.0, 22.0, 23.0 and 24.0.
- PHP 7.4 to 8.4. Extensions zip, openssl and curl required; ftp and ssh2 depending on the destination.
- English and French included.
Screenshots
Versions
- 2.2.0 (2 October 2026): update recommended for everyone. The command line scripts (scripts/backup.php and scripts/restore.php) could be called through the web server without logging in; they now only answer on the command line. Restore: every SQL statement is checked, restore across different servers (MySQL 8 and MariaDB), "Retry" and "Go back to the previous state" buttons. Dolibarr update: every file of the package is checked. Dump: BIT and JSON columns fixed.
- 2.1.0 (2 October 2026): Dolibarr update from the module.
- 2.0.0 (2 October 2026): restore from the browser, external modules included in the backup, encrypted passwords carried to the new installation.
- 1.0.0 (2 October 2026): first version.
Support
Questions before buying, installation or update issues: write to contact@theopequignot.fr. I am the developer of this module and I answer myself. Support and updates are included for 2 years with the DoliStore purchase. The full presentation of the module, its screenshots, frequently asked questions and the support form are on modules.theopequignot.fr. Purchases are made on the DoliStore.