Backblaze-Personal

Backblaze-Personal

Docker app from allornothing's Repository

Overview

Backblaze Personal Backup running under Wine in a container, with a browser desktop (no VNC client needed) and a monitor, status and settings dashboard beside it. This is a fork of iamfoz/backblaze-64-personal-wine-container with a Container tab that changes every setting below from the browser, update notices for the image, Wine and the Backblaze client, and a template that exposes every option. Not affiliated with or supported by Backblaze. The container needs read-write access to what it backs up: Backblaze writes a .bzvol folder into the root of every drive. Map each folder you want protected to /drive_d, /drive_e and so on. Image tags (edit the Repository field to switch): latest = WineHQ stable, pins client 10.0.1.1069; latest-patched = the fork's patched Wine, fixes on, follows the newest client; beta = patched Wine with the performance patches on, weekly; ubuntu26 = early access. On a patched or beta tag, clear Pin the Backblaze client. First start: open the Web UI, sign in to your Backblaze account in the desktop, and let the first backup run. Nothing is sent to this project; update checks fetch version numbers from Docker Hub, WineHQ and Backblaze only. Moving from iamfoz's template: point Config at the same appdata folder and the Wine prefix and your Backblaze identity carry over. Do not run two containers on one folder.

Running this on Unraid

This is a fork of iamfoz/backblaze-64-personal-wine-container with a Container tab that changes every setting from the browser, update notices, and an Unraid template that exposes every option. Everything in the upstream README about Backblaze under Wine, the monitor, the API and troubleshooting still applies.

Install

  1. Apps tab, search for Backblaze-Personal (or, before it is listed, run this on the server and use Docker → Add Container → pick the template):

    wget -O /boot/config/plugins/dockerMan/templates-user/my-Backblaze-Personal.xml \
      https://raw.githubusercontent.com/aon082910/AoN-Unraid-Apps/main/Backblaze-Personal/backblaze-personal.xml
    
  2. Set Backup Source (Drive D) to the first folder you want protected, for example /mnt/user/Photos. Add more with E, F, G in Show more settings, or Add another Path with container path /drive_h/ up to /drive_z/. The mapping must be read-write: Backblaze writes a .bzvol folder into the root of each drive.

  3. Leave User ID 99 and Group ID 100 (nobody:users) unless your data is owned by someone else.

  4. Apply, open the WebUI, sign in to Backblaze in the desktop tab, and let the first backup run.

The template sets --restart=unless-stopped. The Container tab's Restart button relies on it: the container stops itself cleanly and Docker starts it again.

Which tag

Edit the Repository field to change tag.

Tag Wine Backblaze client Use it when
allornothing/backblaze-personal:latest WineHQ stable pinned to 10.0.1.1069 You want the least surprise. Default.
:latest-patched the fork's patched Wine, fixes on follows Backblaze's newest You want client 10.0.3+ or the upload fix. Clear Pin the Backblaze client.
:beta patched Wine, performance patches on, rebuilt weekly follows the newest Upload speed is why you are here.
:ubuntu26 WineHQ stable on Ubuntu 26.04 pinned Early access to the next base.
:v10.2.2-aon.1 and so on as the tag it was cut from You want to stay on one release.

Moving between :latest and a patched tag is safe: the Wine prefix upgrades in place. Moving back down usually works but Wine does not promise it.

Changing settings

Open the WebUI and the Container tab. Everything the template lists is there, grouped, with the image default, what is running now, and whether the value comes from the template or from the tab.

  • A value saved on the tab wins over the same field in the Unraid template. Follow the container puts it back.
  • Everything is read when the container starts, so changes apply after a restart. The tab says which settings are waiting.
  • Passwords are write-only: the tab can set or clear one and never shows it again.
  • If you lock yourself out (a web login with a password you mistyped), add the variable BB_IGNORE_UI_SETTINGS = 1 in the template, apply, fix the setting, then set it back to 0.

The Wine patch switches, notifications, quiet hours and exclusions stay on the Settings tab, as upstream.

Update notices

Once a day (UPDATE_CHECK_INTERVAL_HOURS) the container asks Docker Hub, WineHQ and Backblaze whether a newer image, Wine or client exists. The answers are on the Container tab. To be told rather than have to look, add a notification endpoint on the Settings tab (ntfy, Discord, Slack, Gotify, Pushbullet or any webhook) and leave the events Container image update, Newer Wine and Newer Backblaze client ticked.

Updating is still yours to do: Unraid's Docker tab → Check for updates → apply update. Unraid shows "update ready" for this container on its own once a new image is pushed.

Moving from iamfoz's template

Point Config at the same appdata folder. The Wine prefix and your Backblaze identity carry over, because this image uses the same layout. Stop the old container first: two containers on one folder will corrupt it. Your old settings that were Docker variables are in the new template under the same names.

Networks

  • bridge (default): map port 5800.
  • br0 / custom network: the container gets its own address; the port mapping is ignored. Port 5800 is used as is.
  • host: set Web port inside the container (and the VNC one) to free ports, since the mapping is ignored.
  • Behind a reverse proxy: turn on Web interface on localhost only only if the proxy shares the container's network namespace; otherwise leave it off and put the web login on.

Security notes

The monitor can pause the backup, run repairs and, now, change this container's settings. With no web login, anything on your network that can reach port 5800 can use it. Turn on Encrypted connection and Web login (Container tab → Security), or keep the port off the network. The tab will not let you save a web login without a username, a password and a transport that protects it.

Download Statistics

230
Total Downloads

Related apps

Explore more like this

Explore all

Details

Repository
allornothing/backblaze-personal:latest
Last Updated2026-10-11
First Seen2026-10-11

Runtime arguments

Web UI
http://[IP]:[PORT:5800]/
Network
bridge
Shell
bash
Privileged
false
Extra Params
--restart=unless-stopped

Template configuration

Web UI PortPorttcp

Port for the browser desktop, the monitor and the Container tab. With a custom network (br0) or host networking set Web port inside the container instead.

Target
5800
Default
5800
Value
5800
VNC PortPorttcp

Port for a VNC client. Leave unmapped if you only use the browser.

Target
5900
Default
5900
Value
5900
ConfigPathrw

Persistent storage for the Wine prefix, your Backblaze identity and every setting saved on the Container tab. Must survive restarts. Back this folder up.

Target
/config
Default
/mnt/user/appdata/backblaze-personal
Value
/mnt/user/appdata/backblaze-personal
Backup Source (Drive D)Pathrw

Optional: a host folder to back up as drive D:. Must be read-write: Backblaze creates a .bzvol folder in the drive's root. For more drives add another Path with Container Path /drive_h/ and so on up to /drive_z/.

Target
/drive_d/
Backup Source (Drive E)Pathrw

Optional: a host folder to back up as drive E:. Must be read-write: Backblaze creates a .bzvol folder in the drive's root. For more drives add another Path with Container Path /drive_h/ and so on up to /drive_z/.

Target
/drive_e/
Backup Source (Drive F)Pathrw

Optional: a host folder to back up as drive F:. Must be read-write: Backblaze creates a .bzvol folder in the drive's root. For more drives add another Path with Container Path /drive_h/ and so on up to /drive_z/.

Target
/drive_f/
Backup Source (Drive G)Pathrw

Optional: a host folder to back up as drive G:. Must be read-write: Backblaze creates a .bzvol folder in the drive's root. For more drives add another Path with Container Path /drive_h/ and so on up to /drive_z/.

Target
/drive_g/
User IDVariable

The user ID the app runs as. It must own the files it backs up, because Backblaze writes a .bzvol folder into the root of every drive. Find yours with: id -u Not 0. Files already in /config keep their old owner until the container takes ownership at start. (1 to 65534)

Target
USER_ID
Default
99
Value
99
Group IDVariable

The group ID the app runs as. Find yours with: id -g (1 to 65534)

Target
GROUP_ID
Default
100
Value
100
Supplementary group IDsVariable

Comma-separated extra groups, for a share that is group-readable only. Empty for none.

Target
SUP_GROUP_IDS
File creation maskVariable

Octal mask for files the app creates. 0022 is readable by everyone, writable by the owner; 0000 is writable by everyone, the usual Unraid choice.

Target
UMASK
Default
0022
Value
0022
Time zoneVariable

A tz database name such as America/New_York. Backup schedules, quiet hours and log times follow it.

Target
TZ
Default
Etc/UTC
Value
Etc/UTC
Screen widthVariable

Width in pixels of the virtual screen. Must be divisible by 4. (400 to 7680)

Target
DISPLAY_WIDTH
Default
900
Value
900
Screen heightVariable

Height in pixels of the virtual screen. Must be divisible by 4. (300 to 4320)

Target
DISPLAY_HEIGHT
Default
700
Value
700
Disable Wine's virtual desktopVariable

Draw Backblaze's windows directly on the screen instead of inside one Wine desktop window.

Target
DISABLE_VIRTUAL_DESKTOP
Default
false|true
Value
false
Dark modeVariable

Use a dark theme for the browser desktop's own controls. (1 is on, 0 is off.)

Target
DARK_MODE
Default
0|1
Value
0
Chinese, Japanese and Korean fontVariable

Installs the WenQuanYi Zen Hei font at start, for file names in those scripts. Needs internet access at start. (1 is on, 0 is off.)

Target
ENABLE_CJK_FONT
Default
0|1
Value
0
Pin the Backblaze clientVariable

Run exactly this client version, for example 10.0.1.1069. At each start the container installs it if a different one is there, newer or older, and skips the update check. Empty lets the two switches below decide. The stable image pins 10.0.1.1069 because 10.0.3.1075 completes no backup pass under WineHQ's Wine; the patched and beta images follow Backblaze's newest. Pinning a client that needs the Wine service-token fix on an image without it will stall backups.

Target
BACKBLAZE_VERSION
Default
10.0.1.1069
Value
10.0.1.1069
Update the client at every startVariable

Download the newest Backblaze client at each start. Off keeps the installed version and skips the check.

Target
FORCE_LATEST_UPDATE
Default
true|false
Value
true
Skip the update check at startVariable

Start faster by not asking Backblaze for a newer client. The client's own updater is separate.

Target
DISABLE_AUTOUPDATE
Default
false|true
Value
false
Web port inside the containerVariable

Change only when the container shares the host's network and 5800 is taken. With a bridge network leave it and change the port mapping instead. (1 to 65535)

Target
WEB_LISTENING_PORT
Default
5800
Value
5800
VNC port inside the containerVariable

As above, for VNC clients. (1 to 65535)

Target
VNC_LISTENING_PORT
Default
5900
Value
5900
File manager in the browserVariable

Adds a file manager to the desktop's side panel, for looking at what is mapped into the container. Anyone who can open the desktop can then browse the allowed paths. (1 is on, 0 is off.)

Target
WEB_FILE_MANAGER
Default
0|1
Value
0
File manager: allowed pathsVariable

AUTO allows the mapped folders. Otherwise a comma-separated list of paths.

Target
WEB_FILE_MANAGER_ALLOWED_PATHS
Default
AUTO
Value
AUTO
File manager: denied pathsVariable

Comma-separated paths the file manager must not show.

Target
WEB_FILE_MANAGER_DENIED_PATHS
Terminal in the browserVariable

Adds a shell to the desktop's side panel. Anyone who can open the desktop gets a shell as the app's user. Turn the web login on first. (1 is on, 0 is off.)

Target
WEB_TERMINAL
Default
0|1
Value
0
Desktop notificationsVariable

Show the desktop's own notifications as browser notifications. (1 is on, 0 is off.)

Target
WEB_NOTIFICATION
Default
0|1
Value
0
Clipboard syncVariable

Copy and paste between your computer and the desktop. (1 is on, 0 is off.)

Target
WEB_HOST_CLIPBOARD_SYNC
Default
1|0
Value
1
Web interface on localhost onlyVariable

Listen on 127.0.0.1 only, for use behind a reverse proxy in the same network namespace. Nothing outside the container can reach the desktop, or this page, while it is on. (1 is on, 0 is off.)

Target
WEB_LOCALHOST_ONLY
Default
0|1
Value
0
VNC on localhost onlyVariable

Do not accept VNC clients from outside the container. (1 is on, 0 is off.)

Target
VNC_LOCALHOST_ONLY
Default
0|1
Value
0
Encrypted connectionVariable

Serve the desktop over HTTPS and VNC over TLS, with a certificate made on first start. Needed for the web login unless you allow the insecure one. (1 is on, 0 is off.)

Target
SECURE_CONNECTION
Default
0|1
Value
0
VNC encryption methodVariable

SSL wraps the connection (stunnel); TLS uses VNC's own upgrade.

Target
SECURE_CONNECTION_VNC_METHOD
Default
SSL|TLS
Value
SSL
Web loginVariable

Ask for a username and password before the desktop, this page and the monitor open. Off by default, which leaves the monitor's controls open to anything on your network. Set the username and password below first. If you lock yourself out, set BB_IGNORE_UI_SETTINGS=1 on the container, restart it, fix the settings here, remove the variable. (1 is on, 0 is off.)

Target
WEB_AUTHENTICATION
Default
0|1
Value
0
Web login usernameVariable

The username for the web login.

Target
WEB_AUTHENTICATION_USERNAME
Web login passwordVariable

The password for the web login. It is stored in the settings file on your appdata share and is never shown again.

Target
WEB_AUTHENTICATION_PASSWORD
Allow the web login over plain HTTPVariable

Lets the login work without the encrypted connection. The password then crosses your network in the clear. (1 is on, 0 is off.)

Target
WEB_AUTHENTICATION_ALLOW_INSECURE
Default
0|1
Value
0
Login lifetime (hours)Variable

How long a browser stays logged in. (1 to 8760)

Target
WEB_AUTHENTICATION_TOKEN_VALIDITY_TIME
Default
24
Value
24
VNC passwordVariable

Password for VNC clients and the browser desktop. VNC passwords are cut to 8 characters by the protocol. Stored in the settings file and never shown again.

Target
VNC_PASSWORD
API originsVariable

Comma-separated origins a browser page may call the HTTP API from. Empty allows none. There is no wildcard.

Target
API_CORS_ORIGINS
Priority (niceness)Variable

-20 is the highest priority, 19 the lowest. Lower the priority to keep a busy server responsive. A negative value needs the container to be started with --cap-add=SYS_NICE. (-20 to 19)

Target
APP_NICENESS
Default
0
Value
0
Restart the app when it exitsVariable

When Backblaze's launcher exits, start it again instead of stopping the container. (1 is on, 0 is off.)

Target
KEEP_APP_RUNNING
Default
0|1
Value
0
Shutdown grace time (ms)Variable

How long each service gets to stop before it is killed when the container stops. Raise it if a stop leaves the client's database in recovery. (0 to 600000)

Target
SERVICES_GRACETIME
Default
5000
Value
5000
Check for updatesVariable

Once a day, ask Docker Hub, WineHQ and Backblaze whether anything newer exists. Only version numbers are fetched; nothing about your backup leaves the container.

Target
UPDATE_CHECK
Default
true|false
Value
true
Hours between checksVariable

How often the check runs. (1 to 168)

Target
UPDATE_CHECK_INTERVAL_HOURS
Default
24
Value
24
Enable watchdogVariable

Recover automatically from the known stalls: clear a stale four-hour lock left by an out-of-memory kill and stop a pass stuck on a lost upload child. Every action is logged. Off by default because it deletes a lock file and kills processes. The Settings tab has a switch that overrides this without a restart.

Target
ENABLE_WATCHDOG
Default
false|true
Value
false
Datasets as foldersVariable

Patched and beta tags only. Which drives show the separate filesystems inside them (ZFS datasets, a mounted cache pool) as ordinary folders so the client backs them up: all, or drive letters such as d,e. Empty for none. Without it the client skips every dataset inside a drive. A dataset already backed up under its own letter uploads again under the new path.

Target
MOUNTPOINTS_AS_DIRS
Wine: upload writability fixVariable

Patched and beta tags only. Lifts the stock-Wine cap of about 140 KB/s on a single upload stream (WineHQ bug 59893). The Settings tab overrides it.

Target
WINE_SOCK_SEND_READY
Default
1|0
Value
1
Wine: FD_WRITE re-armVariable

Patched and beta tags only. About three times the upload rate on high-latency links; a workaround that differs from Windows and needs the writability fix. The beta image turns it on; :latest-patched leaves it off.

Target
WINE_SOCK_FDWRITE_REARM
Default
0|1
Value
0
Wine: service tokenVariable

Patched and beta tags only. Gives services the LocalSystem group, which client 10.0.3.1075 and later need to complete a backup pass. Off means the client must stay on 10.0.1.1069.

Target
WINE_SERVICE_TOKEN
Default
1|0
Value
1
Wine: OFD file locksVariable

Patched and beta tags only. Stops the client's database leaking file descriptors until nothing can open a file.

Target
WINE_OFD_LOCKS
Default
1|0
Value
1
Wine: case-sensitivity cacheVariable

Patched and beta tags only. Decides case sensitivity once per device instead of after every failed lookup; large speed-up on Unraid user shares. The beta image turns it on; :latest-patched leaves it off.

Target
WINE_CASE_CACHE
Default
0|1
Value
0
Ignore saved Container-tab valuesVariable

Set to 1 for one start to ignore everything saved on the Container tab, for example after locking yourself out with a web login. Set it back to 0 afterwards.

Target
BB_IGNORE_UI_SETTINGS
Default
0|1
Value
0