Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Running the server

Updates and backups

Updating the server

This server runs version 0.9.0 (also shown at the bottom of the sidebar). Updates come from Larström Technologies' signed update repository, which every installation is already set up to use. Sign in to the server (console or SSH) and run:

sudo apt update
sudo apt upgrade

Or use Server > System & updates in the admin center (see Managing the server itself).

The mail server restarts by itself as part of the update, which interrupts connections for a few seconds; phones and apps reconnect on their own. Mail arriving during those seconds is retried by the sending server. Settings, mail and the database are kept; new settings introduced by an update are added with their defaults, and existing ones are never changed.

The repository is trusted through one signing key only, shipped with the server in /usr/share/keyrings/obsidian-archive-keyring.gpg (fingerprint ACD1 AB0A 95E1 84CF 60CA 8731 24A7 FB31 E35B EE13). apt refuses packages that are not signed with it, and refuses a copy of the repository older than 30 days, so nobody can hold the server back on an old version by replaying an old copy.

Ubuntu's own security updates arrive the same way (apt upgrade installs both). A restart of the whole machine is only needed when Ubuntu says so (/var/run/reboot-required exists).

Servers without internet access

Set Enabled: no in /etc/apt/sources.list.d/obsidian-mailserver.sources, copy the new package (obsidian-mailserver_<version>_amd64.deb) to the server, and install it:

sudo apt install ./obsidian-mailserver_<version>_amd64.deb

What to back up

WhatWhereWhy
DatabasePostgreSQL database omsUsers, folders, message index, calendars, settings, history
Mail content/var/lib/obsidian-mailserver/blobsThe messages and attachments themselves
Configuration/etc/obsidian-mailserverSettings, the database password, certificates copied there
Certificates/etc/letsencrypt (if you use Let's Encrypt)So renewals keep working after a restore

The database and the mail content belong together: back them up at the same time.

Backups from the admin center

Server > Backup makes scheduled backups to a share, NFS export or another disk and restores them; see Managing the server itself. The sections below are for doing it by hand or with other tools.

The simplest backup: snapshots

If the server is a virtual machine, a snapshot or VM backup (Hyper-V checkpoint export, Veeam, VMware snapshot backup, Proxmox backup) taken while it runs captures everything consistently enough for a restore. Keep backups on another machine and test a restore now and then.

A file-level backup

For backups to another system, dump the database and then copy the files:

sudo -u postgres pg_dump -Fc oms > /var/backups/oms.dump
sudo tar -czf /var/backups/oms-files.tar.gz /var/lib/obsidian-mailserver/blobs /etc/obsidian-mailserver

Then copy both files off the server (for example with scp or your backup software). For a perfectly consistent copy, stop the mail server during these two commands (sudo systemctl stop obsidian-mailserver, then start); running them back to back without stopping is fine for everyday backups.

To run this every night, put the commands in a script and schedule it with sudo crontab -e.

Restoring

On a freshly installed server of the same or newer version, skip the first-organization step of the setup, then:

sudo systemctl stop obsidian-mailserver
sudo tar -xzf oms-files.tar.gz -C /
sudo -u postgres dropdb oms
sudo -u postgres createdb -O oms -E UTF8 oms
sudo -u postgres pg_restore -d oms oms.dump
sudo chown -R omsd:omsd /var/lib/obsidian-mailserver
sudo systemctl start obsidian-mailserver

Starting the server re-applies the database password from the restored configuration and upgrades the database if the new version needs it.

Moving to new hardware

Restore a backup onto the new server as above, give it the old server's IP address (or change the DNS A record of mail.example.com to the new address), and switch the old one off.

Keeping an eye on the server

  • The home page shows whether each service is running, the mail traffic, and the queue.
  • The certificate box in the sidebar turns amber 30 days and red 14 days before the certificate expires.
  • https://mail.example.com/healthz answers ok while the server runs; point your monitoring at it.
  • The disk use of the mail store is shown at the bottom of the sidebar (global administrators).