this post was submitted on 10 May 2025
177 points (99.4% liked)

Selfhosted

52480 readers
1548 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I'm planning on setting up a nas/home server (primarily storage with some jellyfin and nextcloud and such mixed in) and since it is primarily for data storage I'd like to follow the data preservation rules of 3-2-1 backups. 3 copies on 2 mediums with 1 offsite - well actually I'm more trying to go for a 2-1 with 2 copies and one offsite, but that's besides the point. Now I'm wondering how to do the offsite backup properly.

My main goal would be to have an automatic system that does full system backups at a reasonable rate (I assume daily would be a bit much considering it's gonna be a few TB worth of HDDs which aren't exactly fast, but maybe weekly?) and then have 2-3 of those backups offsite at once as a sort of version control, if possible.

This has two components, the local upload system and the offsite storage provider. First the local system:

What is good software to encrypt the data before/while it's uploaded?

While I'd preferably upload the data to a provider I trust, accidents happen, and since they don't need to access the data, I'd prefer them not being able to, maliciously or not, so what is a good way to encrypt the data before it leaves my system?

What is a good way to upload the data?

After it has been encrypted, it needs to be sent. Is there any good software that can upload backups automatically on regular intervals? Maybe something that also handles the encryption part on the way?

Then there's the offsite storage provider. Personally I'd appreciate as many suggestions as possible, as there is of course no one size fits all, so if you've got good experiences with any, please do send their names. I'm basically just looking for network attached drives. I send my data to them, I leave it there and trust it stays there, and in case too many drives in my system fail for RAID-Z to handle, so 2, I'd like to be able to get the data off there after I've replaced my drives. That's all I really need from them.

For reference, this is gonna be my first NAS/Server/Anything of this sort. I realize it's mostly a regular computer and am familiar enough with Linux, so I can handle that basic stuff, but for the things you wouldn't do with a normal computer I am quite unfamiliar, so if any questions here seem dumb, I apologize. Thank you in advance for any information!

top 50 comments
sorted by: hot top controversial new old
[–] huquad@lemmy.ml 41 points 5 months ago (6 children)

Syncthing to a pi at my parents place.

[–] AtariDump@lemmy.world 14 points 5 months ago (4 children)

But doesn’t that sync in real-time? Making it not a true backup?

[–] huquad@lemmy.ml 9 points 5 months ago (3 children)

Agreed. I have it configured on a delay and with multiple file versions. I also have another pi running rsnapshot (rsync tool).

load more comments (3 replies)
load more comments (3 replies)
[–] Malatesta@lemmy.world 12 points 5 months ago

Low power server in a friends basement running syncthing

[–] SorteKanin@feddit.dk 4 points 5 months ago (1 children)

A pi with multiple terabytes of storage?

[–] huquad@lemmy.ml 9 points 5 months ago* (last edited 5 months ago)

My most critical data is only ~2-3TB, including backups of all my documents and family photos, so I have a 4TB ssd attached which the pi also boots from. I have ~40TB of other Linux isos that have 2-drive redundancy, but no backups. If I lose those, i can always redownload.

load more comments (3 replies)
[–] rutrum@programming.dev 31 points 5 months ago

I use borg backup. It, and another tool called restic, are meant for creating encrypted backups. Further, it can create backups regularly and only backup differences. This means you could take a daily backup without making new copies of your entire library. They also allow you to, as part of compressing and encrypting, make a backup to a remote machine over ssh. I think you should start with either of those.

One provider thats built for being a cloud backup is borgbase. It can be a location you backup a borg (or restic I think) repository. There are others that are made to be easily accessed with these backup tools.

Lastly, I'll mention that borg handles making a backup, but doesn't handle the scheduling. Borgmatic is another tool that, given a yml configuration file, will perform the borgbackup commands on a schedule with the defined arguments. You could also use something like systemd/cron to run a schedule.

Personally, I use borgbackup configured in NixOS (which makes the systemd units for making daily backups) and I back up to a different computer in my house and to borgbase. I have 3 copies, 1 cloud and 2 in my home.

[–] mhzawadi@lemmy.horwood.cloud 25 points 5 months ago (6 children)

There's some really good options in this thread, just remember that whatever you pick. Unless you test your backups, they are as good as not existing.

[–] redbr64@lemmy.world 6 points 5 months ago (2 children)

Is there some good automated way of doing that? What would it look like, something that compares hashes?

[–] mhzawadi@lemmy.horwood.cloud 6 points 5 months ago

That very much depends on your backup of choice, that's also the point. How do you recover your backup?

Start with a manual recover a backup and unpack it, check import files open. Write down all the steps you did, how do you automate them.

load more comments (1 replies)
load more comments (5 replies)
[–] traches@sh.itjust.works 16 points 5 months ago* (last edited 5 months ago) (1 children)

NAS at the parents’ house. Restic nightly job, with some plumbing scripts to automate it sensibly.

load more comments (1 replies)
[–] doodledup@lemmy.world 16 points 5 months ago (3 children)

I'm just skipping that. How am I going to backup 48TB on an off-site backup?!

[–] Appoxo@lemmy.dbzer0.com 18 points 5 months ago (3 children)

Only back up the essentials like photos and documents or rare media.
Don't care about stuff like Avengers 4K that can easily be reaquired

[–] dave@lemmy.wtf 7 points 5 months ago* (last edited 5 months ago) (1 children)

a "poor mans" backup can be useful for things like this, movie/tv/music collections, and will only be a few MB instead of TB.

if things go south at least you can rebuild your collection in time. obviously if theres some rare files that were hard to get then you can backup those ones, but even at that it will probably still be a small backup

load more comments (1 replies)
load more comments (2 replies)
[–] ryannathans@aussie.zone 3 points 5 months ago (1 children)

Get a tiny ITX box with a couple 20TB refurbished HDDs, stick it at a friend's house

[–] doodledup@lemmy.world 4 points 5 months ago* (last edited 5 months ago) (4 children)

In theory. But I already spent my pension for those 64TB drives (raidz2) xD. Getting off-site backup for all of that feels like such a waste of money (until you regret it). I know it isn't a backup, but I'm praying the Raidz2 will be enough protection.

[–] Cyber@feddit.uk 10 points 5 months ago (2 children)

Just a friendly reminder that RAID is not a backup...

Just consider if something accidentally overwrites some / all your files. This is a perfectly legit action and the checksums will happily match that new data, but your file(s) are gone...

load more comments (2 replies)
[–] cwista@lemmy.world 5 points 5 months ago

The cost of storage is always more than double the sticker price. The hidden fee is that you need a second and maybe a third one and a system to put it all in. Most our operational lab cost is backups. I can't replace the data if it's lost.

[–] PeriodicallyPedantic@lemmy.ca 5 points 5 months ago (1 children)

Do you have to back up everything off site?

Maybe there are just a few critical files you need a disaster recovery plan for, and the rest is just covered by your raidz

load more comments (1 replies)
load more comments (1 replies)
load more comments (1 replies)
[–] pHr34kY@lemmy.world 15 points 5 months ago* (last edited 5 months ago)

I have a job, and the office is 35km away. I get a locker in my office.

I have two backup drives, and every month or so, I will rotate them by taking one into the office and bringing the other home. I do this immediately after running a backup.

The drives are LUKS encrypted btrfs. Btrfs allows snapshots and compression. LUKS enables me to securely password protect the drive. My backup job is just a btrfs snapshot followed by an rsync command.

I don't trust cloud backups. There was an event at work where Google Cloud accidentally deleted an entire company just as I was about to start a project there.

[–] Matriks404@lemmy.world 12 points 5 months ago

I don't 🙃

[–] dataprolet@lemmy.dbzer0.com 11 points 5 months ago (1 children)
load more comments (1 replies)
[–] merthyr1831@lemmy.ml 9 points 5 months ago

Rsync to a Hetzner storage box. I dont do ALL my data, just the nextcloud data. The rest is...linux ISOs... so I can redownload at my convenience.

[–] Bassman1805@lemmy.world 8 points 5 months ago

The easiest offsite backup would be any cloud platform. Downside is that you aren't gonna own your own data like if you deployed your own system.

Next option is an external SSD that you leave at your work desk and take home once a week or so to update.

The most robust solution would be to find a friend or relative willing to let you set up a server in their house. Might need to cover part of their electric bill if your machine is hungry.

[–] sxan@midwest.social 8 points 5 months ago (1 children)

I used to say restic and b2; lately, the b2 part has become more iffy, because of scuttlebutt, but for now it's still my offsite and will remain so until and unless the situation resolves unfavorably.

Restic is the core. It supports multiple cloud providers, making configuration and use trivial. It encrypts before sending, so the destination never has access to unencrypted blobs. It does incremental backups, and supports FUSE vfs mounting of backups, making accessing historical versions of individual files extremely easy. It's OSS, and a single binary executable; IMHO it's at the top of its class, commercial or OSS.

B2 has been very good to me, and is a clear winner for this is case: writes and space are pennies a month, and it only gets more expensive if you're doing a lot of reads. The UI is straightforward and easy to use, the API is good; if it weren't for their recent legal and financial drama, I'd still unreservedly recommend them. As it is, you'd have you evaluate it yourself.

load more comments (1 replies)
[–] drkt@scribe.disroot.org 8 points 5 months ago (2 children)

I rsync a copy of it to a friends house every night. It's straight forward, simple and free.

[–] diegantobass@lemmy.world 5 points 5 months ago

I rsync a copy to mom's

load more comments (1 replies)
[–] WeirdGoesPro@lemmy.dbzer0.com 7 points 5 months ago (5 children)

My ratchet way of doing it is Backblaze. There is a docker container that lets you run the unlimited personal plan on Linux by emulating a windows environment. They let you set an encryption key so that they can’t access your data.

I’m sure there are a lot more professional and secure ways to do it, but my way is cheap, easy, and works.

load more comments (5 replies)
[–] Onomatopoeia@lemmy.cafe 7 points 5 months ago* (last edited 5 months ago)

As others have said, use tools like borg and restic.

Shop around for cloud storage with good pricing for your use-case. Many charge for different usage patterns, like restoring data or uploading.

Check out storj.io, I like their pricing - they charge for downloading/restore (IIRC), and I figure that's a cost I can live with if I need to restore.

Otherwise I keep 3 local copies of data:

1 is live, and backed up to storj.io

2 is mirrored from 1 every other week

3 is mirrored from 1 every other week, opposite 2

This works for my use-case, where I'm concerned about local failures and mistakes (and don't trust my local stores enough to use a backup tool), but my data doesn't change a lot in a week. If I were to lose 1 week of changes, it would be a minor issue. And I'm trusting my cloud backup to be good (I do test it quarterly, and do a single file restore test monthly).

This isn't an ideal (or even recommended approach), just works with the storages I currently have, and my level of trust of them.

[–] hendrik@palaver.p3x.de 7 points 5 months ago* (last edited 5 months ago) (2 children)

Next to paying for cloud storage, I know people who store an external hdd at their parent's or with friends. I don't do the whole backup thing for all the recorded TV shows and ripped bluerays... If my house burns down, they're gone. But that makes the amount of data a bit more manageable. And I can replace those. I currently don't have a good strategy. My data is somewhat scattered between my laptop, the NAS, an external hdd which is in a different room but not off-site, one cheap virtual server I pay for and critical things like the password manager are synced to the phone as well. Main thing I'm worried about is one of the mobile devices getting stolen so I focus on having that backed up to the NAS or synced to Nextcloud. But I should work on a solid strategy in case something happens to the NAS.

I don't think the software is a big issue. We got several good backup tools which can do incremental or full backups, schedules, encryption and whatever someone might need for backups.

[–] tburkhol@lemmy.world 5 points 5 months ago (1 children)

It really depends on what your data is and how hard it would be to recreate. I keep a spare HD in a $40/year bank box & rotate it every 3 months. Most of the content is media - pictures, movies, music. Financial records would be annoying to recreate, but if there's a big enough disaster to force me to go to the off-site backups, I think that'll be the least of my troubles. Some data logging has a replica database on a VPS.

My upload speed is terrible, so I don't want to put a media library in the cloud. If I did any important daily content creation, I'd probably keep that mirrored offsite with rsync, but I feel like the spirit of an offsite backup is offline and asynchronous, so things like ransomware don't destroy your backups, too.

load more comments (1 replies)
load more comments (1 replies)
[–] iknowitwheniseeit@lemmynsfw.com 5 points 5 months ago

I just use restic.

I'm pretty sure it uses checksums to verify data on the backup target, so it doesn't need to copy all of the data there.

[–] irmadlad@lemmy.world 5 points 5 months ago (2 children)

so if any questions here seem dumb

Not dumb. I say the same, but I have a severe inferiority complex and imposter syndrome. Most artists do.

1 local backup 1 cloud back up 1 offsite backup to my tiny house at the lake.

I use Synchthing.

load more comments (2 replies)
[–] corsicanguppy@lemmy.ca 4 points 5 months ago
  • wireguard
  • rsync
  • zfs
[–] Jimmycakes@lemmy.world 4 points 5 months ago* (last edited 5 months ago)

I use asustor Nas, one at my house south east US, one at my sister's house northeast us. The asus os takes care of the backup every night. It's not cheap but if you want it done right.

Both run 4 drives in raid 5. Pictures backup to the hdd and a raid 1 set of nvme in the nas. The rest is just movies and TV shows for plex so I don't really care about those. The pictures are the main thing. I feel like that's as safe I can be.

[–] ryannathans@aussie.zone 4 points 5 months ago (1 children)

I use syncthing to push data offsite encrypted and with staggered versioning, to a tiny ITX box I run at family member's house

[–] rumba@lemmy.zip 5 points 5 months ago (3 children)

The best part about sync thing is that you can set it to untrusted at the target. The data all gets encrypted and is not accessible whatsoever and the other side.

load more comments (3 replies)
[–] amorpheus@lemmy.world 3 points 5 months ago (2 children)

External drives that I keep in my office at work. Also cloud storage.

load more comments (2 replies)
[–] tuhriel@infosec.pub 3 points 5 months ago* (last edited 5 months ago)

I have a rpi4 awith an external hdd at my parents house, which I connect via a wireguard vpn, mount and decrypt the external hdd and then it triggers a restic backup to a restic-rest server as append only.

The whole thing is done via a python script

I chose the rest-server because it allows "append only", so the data can't be deleted easily from my side of the vpn.

[–] cron@feddit.org 3 points 5 months ago (1 children)

RClone to a cloud storage (hetzner in my case). Rclone is easy to configure and offers full encryption, even for the file names.

As the data is only uploaded once, a daily backup uploads only the added or changed files.

Just as a side note: make sure you can retrieve your data even in case your main system fails. Make sure you have all the passwords/crypto keys available.

load more comments (1 replies)
[–] bandwidthcrisis@lemmy.world 3 points 5 months ago

I use rsync.net

It's not the lowest price, but I like the flexibility of access.

For instance, I was able to run rclone on their servers to do a direct copy from OneDrive to rsync.net, 400Gb without having to go through my connection.

I can mount backups with sshfs if I want to, including the daily zfs snapshots.

[–] neidu3@sh.itjust.works 3 points 5 months ago* (last edited 5 months ago)

A huge tape archive in a mountain. It's pretty standard for geophysical data. I have some (encrypted) personal stuff on a few tapes there.

[–] hperrin@lemmy.ca 3 points 5 months ago* (last edited 5 months ago)

I just rsync it once in a while to a home server running in my dad’s house. I want it done manually in a “pull” direction rather than a “push” in case I ever get hit with ransomware.

load more comments
view more: next ›