# Kopia repository server installation doc

**URL:** <https://kopia.discourse.group/t/kopia-repository-server-installation-doc/251>\
**Category:** General\
**Created:** [December 28, 2020, 8:34am UTC](https://kopia.discourse.group/t/kopia-repository-server-installation-doc/251 "2020-12-28T08:34:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![samuel](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@samuel](https://kopia.discourse.group/u/samuel)\
**Post date:** [December 28, 2020, 8:34am UTC](https://kopia.discourse.group/t/kopia-repository-server-installation-doc/251/1 "2020-12-28T08:34:04Z")

</div>

Hi,  
I managed to have a working backup using Kopia repository server’s feature. I’m on a Debian 9. Here is what I did. If you see something wrong, feel free to comment and/or correct. Once doc is ok, I’ll add it to website

- Install kopia on server using the appropriate method

- Create a user on the server (kopia)

```bash
useradd kopia

```

- Change user’s homedir to a partition with space if your /home doesn’t have enough (could be /opt, /var, etc.)

```bash
usermod -d /opt/kopia kopia

```

- Create a kopia\_conf dir

```bash
cd /opt/kopia
mkdir kopia_conf

```

- Create a storage directory

```bash
mkdir datas

```

- Create service ([https://forum.frank-mankel.org/topic/848/kopia-http-s-server/3](https://forum.frank-mankel.org/topic/848/kopia-http-s-server/3))

```bash
vi /etc/systemd/service/kopia.service

```

```ini
[Unit]
Description=Kopia Server
After=syslog.target
After=network.target

[Service]
Type=simple
User=kopia
Group=kopia
ExecStart=/usr/bin/kopia server --htpasswd-file full_path/kopia_conf/kopia_auth --tls-cert-file full_path/kopia_conf/kopia.cert --tls-key-file full_path/kopia_conf/kopia.key --address <server IPv4>:51515
Restart=always
RestartSec=5

[Install]
WantedBy=multi-user.target
# and adjust paths

```

- Configure kopia (Based on this page [https://kopia.io/docs/repository-server/](https://kopia.io/docs/repository-server/))  
Create user(s) account(s)

```bash
cd kopia_conf
htpasswd -c kopia_auth user1@host1
# !!! (Lowercase client host)

```

- Start server to generate keys

```bash
kopia server start --htpasswd-file full_path/kopia_conf/kopia_auth --tls-generate-cert --tls-cert-file full_path/kopia_conf/kopia.cert --tls-key-file full_path/kopia_conf/kopia.key --address <server IPv4>:51515
# !!! Write down the hash SERVER CERT SHA256

```

- Configure repository  
Connect to web interface https://\<server\_ip\>:51515 with credentials created earlier  
Create a local storage Dir : “datas”

- Stop server and start service  
Stop server ()  
start kopia service

```bash
systemctl start kopia.service

```

- Connect with client (kopiaUI)

1. Start KopiaUI, fill the fields with according informations
2. enter server address : https://\<server\_ip\>:51515
3. use SERVER CERT SHA256 generated earlier
4. use password created earlier
5. add directories to backup
6. create snapshots

---

<div class="post-metadata">

**Author:** ![jkowalski](https://yyz2.discourse-cdn.com/free1/user_avatar/kopia.discourse.group/jkowalski/32/3_2.png) [@jkowalski](https://kopia.discourse.group/u/jkowalski)\
**Post date:** [December 28, 2020, 6:27pm UTC](https://kopia.discourse.group/t/kopia-repository-server-installation-doc/251/2 "2020-12-28T18:27:00Z")

</div>

That’s nice, note you can also use pre-existing trusted TLS certificate files.

For example If you own `somedomain.com` you can use LetsEncrypt to generate trusted cert and key for `kopia.somedomain.com` and use that instead of your server IP and since the cert is trusted you won’t need to pass SHA256 at all.

---

<div class="post-metadata">

**Author:** ![peter](https://yyz2.discourse-cdn.com/free1/user_avatar/kopia.discourse.group/peter/32/441_2.png) [@peter](https://kopia.discourse.group/u/peter)\
**Post date:** [December 8, 2022, 3:47pm UTC](https://kopia.discourse.group/t/kopia-repository-server-installation-doc/251/3 "2022-12-08T15:47:13Z")

</div>

As it took me several tries to setup a kopia server (in my case on a raspberry pi using the nextcloudpi image) and connect to it, here the steps that did work for me:

```bash
# create a user to run the kopia server
sudo adduser kopia
sudo usermod -a -G kopia kopia
# it makes life easier if you can access the conf & repo as the default 'pi' user
sudo usermod -a -G kopia pi

# allow access to this port from outside, nextcloudpi uses the universal firewall
sudo ufw allow 51515/tcp comment 'kopia server'

# now some steps as user kopia
sudo su - kopia
mkdir kopia_conf
cd kopia_conf

# this might be no longer necessary, I'm not sure?
htpasswd -c kopia_auth myuser@another-host

# IMPORTANT: You need to connect locally to server's repo before the server is started!
kopia repository connect filesystem --path=.../repo/

# Once connected, you can then add users:
kopia server user add $USER@$HOSTNAME
kopia server user add myuser@another-host

# NOW: at the FIRST server start: generate KEY & write down fingerprint

kopia server start --htpasswd-file /home/kopia/kopia_conf/kopia_auth --tls-generate-cert --tls-cert-file /home/kopia/kopia_conf/kopia.cert --tls-key-file /home/kopia/kopia_conf/kopia.key --address 192.168.178.xx:51515`

# next starts: keep certificate
kopia server start --htpasswd-file /home/kopia/kopia_conf/kopia_auth --tls-cert-file /home/kopia/kopia_conf/kopia.cert --tls-key-file /home/kopia/kopia_conf/kopia.key --address 192.168.178.xx:51515

```

And to connect from a client, connect to the this nice server from myuser@another-host (added above as user):

```bash
kopia repository connect server --url https://192.168.178.xx:51515 --server-cert-fingerprint <fingerprint-noted-from-above>
kopia snapshot create ...

```

I plan to improve the documentation and provide a PR, as soon as I have some spare time.

---

<div class="post-metadata">

**Author:** ![wayland](https://yyz2.discourse-cdn.com/free1/user_avatar/kopia.discourse.group/wayland/32/268_2.png) [@wayland](https://kopia.discourse.group/u/wayland)\
**Post date:** [December 4, 2023, 6:08pm UTC](https://kopia.discourse.group/t/kopia-repository-server-installation-doc/251/4 "2023-12-04T18:08:05Z")

</div>

Do I really need to use tls certificates? I will be connecting over VPN so not sure if it is really necessary to have additional certificates? I remember having issues in the browser when I tried to open the local web page
