# Trying to migrate my ODK deployment and its data from AWS to Digital Ocean

**URL:** <https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404>\
**Category:** Support\
**Tags:** odk-central\
**Created:** [October 29, 2022, 10:21pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404 "2022-10-29T22:21:38Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![cmuhindo](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/cmuhindo/32/19070_2.png) [@cmuhindo](https://forum.getodk.org/u/cmuhindo)\
**Post date:** [October 29, 2022, 10:21pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/1 "2022-10-29T22:21:38Z")

</div>

Hello,

My ODK deployment works fine on AWS. However, I would like to move the current deployment as well as its current data/state to a new virtual machine on Digital Ocean (while maintaining the domain name). Any ideas on how to achieve this in the fasted and safest way possible?

---

<div class="post-metadata">

**Author:** ![yanokwa](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/yanokwa/32/1695_2.png) [@yanokwa](https://forum.getodk.org/u/yanokwa)\
**Post date:** [October 30, 2022, 6:57pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/2 "2022-10-30T18:57:30Z")

</div>

The following assumes you're comfortable on the command line and with basic networking. Also, I haven't tried this recently so I'd strongly recommend you try this out on a test install before doing it on a production install.

**Pre-reqs**

- Verify your full machine backup and restore works.
- Verify you can whitelist traffic to Central only from your IP. An upstream firewall is great for this.
- Verify you have the same OS on the source (src) and destination (dest). If you don't, the folders noted below may not match. Adjust adjust accordingly.
- Verify you can set the TTL of the DNS record on the domain to something low (~300 secs) to reduce downtime.
- Verify you have an effective way to communicate a maintenance window with users.

**Migration**

1. Take a full machine backup of src.
2. Over ssh, rsync the key folders (`/var/lib/docker`, `/root/central`) from src to dest. This might take some time.
3. Start the maintenance window.
4. Block all incoming HTTP/S traffic to src.
5. Shutdown Central on src with `docker-compose stop`;
6. Rsync the key folders from src to dest again to pick up the latest changes to data. This will be faster than the first rsync.
7. Shutdown src and take another full machine backup.
8. Only allow incoming HTTP/S traffic only from your IP to dest.
9. Update the DNS record to point to the dest. This should happen quickly if your DNS TTL is low.
10. Bring the dest server back up (`docker-compose build; docker-compose up -d`).
11. Verify you can login via the Central UI to dest, see records, preview forms, etc.
12. Allow all incoming HTTP/S traffic to dest.
13. Stop the maintenance window.

**Notes**

- If you value speed over safety, you can skip the backups. I don't recommend it.
- Running the first rsync outside the maintenance window should be safe, but if you want to be extra safe, you can run it after blocking all incoming traffic.

---

<div class="post-metadata">

**Author:** ![Mohinder\_Singh](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/mohinder_singh/32/21056_2.png) [@Mohinder\_Singh](https://forum.getodk.org/u/Mohinder_Singh)\
**Post date:** [April 25, 2023, 5:24am UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/3 "2023-04-25T05:24:48Z")

</div>

Thanks for your update.  
Please confirm by running sync command, it'll migrate the users and databases etc?

Thanks

---

<div class="post-metadata">

**Author:** ![yanokwa](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/yanokwa/32/1695_2.png) [@yanokwa](https://forum.getodk.org/u/yanokwa)\
**Post date:** [April 25, 2023, 6:35pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/4 "2023-04-25T18:35:17Z")

</div>

Yes, it will move everything about the install including users and data.

---

<div class="post-metadata">

**Author:** ![Mohinder\_Singh](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/mohinder_singh/32/21056_2.png) [@Mohinder\_Singh](https://forum.getodk.org/u/Mohinder_Singh)\
**Post date:** [April 26, 2023, 6:16am UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/5 "2023-04-26T06:16:17Z")

</div>

Thanks for your quick response.

One question, how can we renew the Letsencrypt SSL for odk central server?

Thanks

---

<div class="post-metadata">

**Author:** ![yanokwa](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/yanokwa/32/1695_2.png) [@yanokwa](https://forum.getodk.org/u/yanokwa)\
**Post date:** [April 26, 2023, 5:34pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/6 "2023-04-26T17:34:42Z")

</div>

LetsEncrypt certs renew automatically.

---

<div class="post-metadata">

**Author:** ![Mohinder\_Singh](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/mohinder_singh/32/21056_2.png) [@Mohinder\_Singh](https://forum.getodk.org/u/Mohinder_Singh)\
**Post date:** [April 27, 2023, 4:03am UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/7 "2023-04-27T04:03:35Z")

</div>

I much appreciate your support. You are the guru. 👍

---

<div class="post-metadata">

**Author:** ![Mohinder\_Singh](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/mohinder_singh/32/21056_2.png) [@Mohinder\_Singh](https://forum.getodk.org/u/Mohinder_Singh)\
**Post date:** [May 5, 2023, 7:36am UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/8 "2023-05-05T07:36:20Z")

</div>

Hello @yanokwa.

Users aren't receiving emails like forgot password. Shall we need to add mail server host, port, and authentication details in .env ? Or this will work without adding

Thanks

---

<div class="post-metadata">

**Author:** ![yanokwa](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/yanokwa/32/1695_2.png) [@yanokwa](https://forum.getodk.org/u/yanokwa)\
**Post date:** [May 5, 2023, 4:42pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/9 "2023-05-05T16:42:14Z")

</div>

See [https://docs.getodk.org/central-troubleshooting/#users-aren-t-receiving-emails](https://docs.getodk.org/central-troubleshooting/#users-aren-t-receiving-emails).

---

<div class="post-metadata">

**Author:** ![Mohinder\_Singh](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/mohinder_singh/32/21056_2.png) [@Mohinder\_Singh](https://forum.getodk.org/u/Mohinder_Singh)\
**Post date:** [August 11, 2023, 1:33pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/10 "2023-08-11T13:33:56Z")

</div>

Dear @yanokwa,

I wanted to know that how many days before expire letsencrypt ssl automatically renew? As our letsencrypt SSL will be expire on Wednesday, September 6, 2023.  
On the server I see the logs and its saying below logs:

++--------------------------------------------------  
2023/08/04 11:44:25 [info] Starting certificate renewal process  
2023/08/04 11:44:25 [info] Requesting an ECDSA certificate for '[odk.xxx.xxx.org](http://odk.xxx.xxx.org)' (http-01 through webroot)  
Saving debug log to /var/log/letsencrypt/letsencrypt.log  
Certificate not yet due for renewal  
Certificate not yet due for renewal; no action taken.  
++--------------------------------------------------

Can you please help me with this?

Thanks

---

<div class="post-metadata">

**Author:** ![yanokwa](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/yanokwa/32/1695_2.png) [@yanokwa](https://forum.getodk.org/u/yanokwa)\
**Post date:** [August 11, 2023, 1:51pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/11 "2023-08-11T13:51:50Z")

</div>

LetsEncrypt certs auto-renew as necessary (typically every 90 days). You can check the various renewals at [https://crt.sh/?q=odk.xxx.xxx.org](https://crt.sh/?q=odk.xxx.xxx.org) to see if everything is working as expected. From what you've showed in the logs, it is working. Maybe set a calendar even for Sept 1 and check the cert then.

---

<div class="post-metadata">

**Author:** ![Mohinder\_Singh](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/mohinder_singh/32/21056_2.png) [@Mohinder\_Singh](https://forum.getodk.org/u/Mohinder_Singh)\
**Post date:** [August 11, 2023, 2:15pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/12 "2023-08-11T14:15:26Z")

</div>

Thanks for your quick response.

We seeing the attached output.

![image](https://getodk.b-cdn.net/uploads/default/original/3X/1/e/1e4bd9eb3006ba112702ffd662a9f912d3464cac.png)

---

<div class="post-metadata">

**Author:** ![manghig](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/manghig/32/11609_2.png) [@manghig](https://forum.getodk.org/u/manghig)\
**Post date:** [November 12, 2024, 1:22pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/13 "2024-11-12T13:22:07Z")

</div>

> [@yanokwa](#):
>
> 1. Bring the dest server back up (`docker-compose build; docker-compose up -d`).

At docker-compose build I'm getting

```auto
 - LegacyKeyValueFormat: "ENV key=value" should be used instead of legacy "ENV key value" format (line 14)
postgres14.dockerfile:1
--------------------
   1 | >>> FROM postgres:14.10
   2 |
   3 | COPY files/postgres14/start-postgres.sh /usr/local/bin/
--------------------
ERROR: failed to solve: failed to register layer: rename /var/lib/docker/image/overlay2/layerdb/tmp/write-set-702993805 /var/lib/docker/image/overlay2/layerdb/sha256/fb1bd2fc52827db4ce719cc1aafd4a035d68bc71183b3bc39014f23e9e5fa256: file exists
ERROR: Service 'postgres14' failed to build : Build failed

```

any hint about how to solve this? I'm following your post/instructions to the letter.

thanks in advance

---

<div class="post-metadata">

**Author:** ![manghig](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/manghig/32/11609_2.png) [@manghig](https://forum.getodk.org/u/manghig)\
**Post date:** [November 13, 2024, 8:30pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/14 "2024-11-13T20:30:09Z")

</div>

> [@manghig](#):
>
> At docker-compose build I'm getting

@yanokwa I have been able to move on after issuing a

`docker builder prune -a`

anyway now I face a new issue. The resulting Central instance on the new server works. The domain/host name is the same as the original, forms work, what is not working in enketo. The container is up, but forms do not open. The new server is behind a reverse proxy, so I adapted .env and docker-compose.yaml as decribed here

> **[Installing Central on DigitalOcean](https://docs.getodk.org/central-install-digital-ocean/#using-upstream-ssl)**
>
> If you'd like to set up an ODK server that's accessible from anywhere via the Internet, DigitalOcean provides a one-click configuration that's nicely geared with nearly all the tools you'll need to...

Strange thing, a clean install with the same configs (on the reverse proxy too) results in enketo working without problems.

What could be the issue? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![manghig](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/manghig/32/11609_2.png) [@manghig](https://forum.getodk.org/u/manghig)\
**Post date:** [January 31, 2026, 10:09am UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/15 "2026-01-31T10:09:36Z")

</div>

> [@yanokwa](#):
>
> - Take a full machine backup of src.
> - Over ssh, rsync the key folders (`/var/lib/docker`, `/root/central`) from src to dest. This might take some time.
> - Start the maintenance window.
> - Block all incoming HTTP/S traffic to src.
> - Shutdown Central on src with `docker-compose stop`;
> - Rsync the key folders from src to dest again to pick up the latest changes to data. This will be faster than the first rsync.
> - Shutdown src and take another full machine backup.
> - Only allow incoming HTTP/S traffic only from your IP to dest.
> - Update the DNS record to point to the dest. This should happen quickly if your DNS TTL is low.
> - Bring the dest server back up (`docker-compose build; docker-compose up -d`).
> - Verify you can login via the Central UI to dest, see records, preview forms, etc.
> - Allow all incoming HTTP/S traffic to dest.
> - Stop the maintenance window.

Just to note that the above steps worked ok again for me once to migrate my Central instance to a new server. I’m still affected by [Central: containers not starting after boot, do start manually with "docker compose up"](https://forum.getodk.org/t/central-containers-not-starting-after-boot-do-start-manually-with-docker-compose-up/50991) even after upgrading to Central latest version after the migration. Not really sure how to fix that (other than restarting the containers after boot), I would appreciate any pointer.

---

<div class="post-metadata">

**Author:** ![rfvieira](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/rfvieira/32/16852_2.png) [@rfvieira](https://forum.getodk.org/u/rfvieira)\
**Post date:** [February 2, 2026, 12:50pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/16 "2026-02-02T12:50:08Z")

</div>

Hi @manghig ,

Not sure if it’s just that but have you tried _docker compose up **-d** _ (or - - detach)?

“Running `docker compose up --detach` starts the containers in the background and leaves them running.”

---

<div class="post-metadata">

**Author:** ![manghig](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/manghig/32/11609_2.png) [@manghig](https://forum.getodk.org/u/manghig)\
**Post date:** [February 2, 2026, 1:03pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/17 "2026-02-02T13:03:12Z")

</div>

> [@rfvieira](#):
>
> Not sure if it’s just that but have you tried _docker compose up **-d** _ (or - - detach)?

of course. Issuing that manually (or with cron) after boot the containers start ok, they do not start as expected automatically after rebooting the system.

---

<div class="post-metadata">

**Author:** ![rfvieira](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/rfvieira/32/16852_2.png) [@rfvieira](https://forum.getodk.org/u/rfvieira)\
**Post date:** [February 2, 2026, 1:31pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/18 "2026-02-02T13:31:20Z")

</div>

1. Is docker engine running as a service?

sudo systemctl enable docker

1. Is the container restart policy set correctly?

docker inspect --format='{{.HostConfig.RestartPolicy.Name}}' \<container\_name\_or\_id\>

Should be "always" or "unless-stopped"

You can check that also on the docker-compose.yml file at Central’s folder:

less docker-compose.yml

1. If a container depends on a network share or another service, it might fail to start if the dependency is not available when Docker attempts to start it. Review container logs for connection errors.

docker container logs \<container\_name\_or\_id\>

1. Monitor system logs for docker service errors:

journalctl -u docker.service

---

<div class="post-metadata">

**Author:** ![Dr\_Vivek\_Gupta](https://getodk.b-cdn.net/user_avatar/forum.getodk.org/dr_vivek_gupta/32/15988_2.png) [@Dr\_Vivek\_Gupta](https://forum.getodk.org/u/Dr_Vivek_Gupta)\
**Post date:** [April 8, 2026, 5:01pm UTC](https://forum.getodk.org/t/trying-to-migrate-my-odk-deployment-and-its-data-from-aws-to-digital-ocean/39404/19 "2026-04-08T17:01:57Z")

</div>

May be helpful to see docker post install steps

> **[Configure Docker to start on boot with systemd - Post-installation steps](https://docs.docker.com/engine/install/linux-postinstall/#configure-docker-to-start-on-boot-with-systemd)**
>
> These optional post-installation procedures describe how to configure your Linux host machine to work better with Docker. | Find the recommended Docker Engine post-installation steps for Linux users, including how to run Docker as a non-root user and...
