Yep, bind mount the data and config directories and back those up. You can test a backup by spinning up a new container with the data/config directories.
This is both easy and generally the recommended thing I've seen for many services.
The only thing that could cause issues is breaking changes caused by the docker images themselves, but that's an issue regardless of backup strategy.
But that's kinda the flaw in all of it. If I live with other people, any one of them can let the vampire in, but he never got permission from me then it's not about individual permission.
If we say anyone with authority over the space can let someone in, then that would probably extend to the law or property owners.