---
title: "How to automate VPS backups with restic and cron | StreetHosting"
description: "Automate VPS backups with restic and cron: external destination, schedule, retention with forget and prune, and the restore test that proves it works."
url: "https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron"
type: "page"
language: "en-US"
---

VPS · 9 min · Advanced

Published on Jun 17, 2026 · Updated on Sep 28, 2026

# Automatic VPS backups with restic and cron: strategy, retention and restore

A backup that depends on you remembering does not work. With restic and cron you create encrypted snapshots, send them off the VPS, control retention and test restores without daily effort.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Backup and recovery](https://streethosting.com.br/en/guides/topics/backup) [Linux administration](https://streethosting.com.br/en/guides/topics/linux) [Automation and webhooks](https://streethosting.com.br/en/guides/topics/automation)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=How%20to%20automate%20VPS%20backups%20with%20restic%20and%20cron&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron "Share on LinkedIn") [](https://wa.me/?text=How%20to%20automate%20VPS%20backups%20with%20restic%20and%20cron%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fvps-backup-restic-cron "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron.md)

In this guide 8 sections

* [Why restic](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#por-que-restic)
* [What to back up, how often and for how long](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#estrategia)
* [Prepare the repository](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#preparar)
* [Backup script](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#script-backup)
* [Schedule with cron](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#agendar)
* [Retention with forget and prune](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#retencao)
* [Test the restore](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#testar-restauracao)
* [Where to keep the backup](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#onde-guardar)

Quick answer

To automate **VPS backups with restic and cron**, install restic, initialize an encrypted repository at an external destination, write a script that dumps the databases, runs the backup and applies retention with forget and prune, and schedule it in cron at a quiet hour. Keep the repository password off the VPS, notify a monitor when the backup finishes and test the restore every month.

## Why restic[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#por-que-restic)

restic takes incremental, encrypted, deduplicated snapshots, which saves space and protects the data. Each run sends only the blocks that changed, but every snapshot can be restored on its own, without depending on a chain of incrementals. It is a single binary with no server of its own, and it talks to several destinations: a local folder, another server over SFTP, S3-compatible storage and the project's own rest server.

Paired with cron, it turns backup into an invisible routine. That habit is the practical foundation of the [3 2 1 backup strategy](https://streethosting.com.br/en/guides/infrastructure/3-2-1-backup-strategy), which explains why you want three copies on two kinds of media, one of them off-site. Here the focus is execution: what to copy, the script, the schedule, retention and the test.

## What to back up, how often and for how long[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#estrategia)

Frequency answers one question: how much data can you afford to lose? With a daily backup at 3 AM, a failure at 11 PM costs almost a full day of work. Not everything needs the same rhythm:

| What                          | Frequency                | Suggested retention          | Notes                                                           |
| ----------------------------- | ------------------------ | ---------------------------- | --------------------------------------------------------------- |
| Databases                     | Daily or every few hours | 7 daily, 4 weekly, 6 monthly | Always through a dump, never by copying the live database files |
| Uploads and application files | Daily                    | 7 daily, 4 weekly, 6 monthly | Exclude cache, logs and dependencies that reinstall themselves  |
| System configuration          | Daily                    | Same as the rest             | The etc folder, Compose files, crontabs, certificates           |
| Code in a Git repository      | Not needed               | Not applicable               | It already lives outside the VPS; copy only what is not in Git  |
| Operating system and packages | Not needed               | Not applicable               | Reinstalling is faster than restoring                           |

There are two places for the copies. The local copy, like the dumps that sit in a folder on the VPS itself, restores a file deleted by mistake in seconds, but it disappears along with the machine and takes up its disk. The external copy, on another server or in S3-compatible storage, is the one that saves you when the whole VPS is lost, gets compromised or someone runs the wrong command as root. The script below does both: it generates the local dump and ships everything out.

## Prepare the repository[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#preparar)

`sudo apt update && sudo apt install -y restic restic version # random repository password, readable only by root sudo sh -c 'openssl rand -base64 32 > /root/.restic-senha && chmod 600 /root/.restic-senha'`

The repository password encrypts everything. If you lose that password, the backups become unrecoverable. Copy the contents of `/root/.restic-senha` to a password manager, outside the VPS itself: if the VPS disappears, the file goes with it.

The repository variables live in a file the script loads. Pick one of the destinations:

### Another server over SFTP[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#destino-sftp)

Create a regular user on the destination server and authorize the SSH key of the VPS root for it, the way described in [setting up passwordless SSH keys](https://streethosting.com.br/en/guides/vps/passwordless-ssh-login-vps). On the destination, the `/srv/restic` folder must exist and belong to that user. Then connect once manually as root, with `sudo ssh backup@IP_DO_SERVIDOR_DE_BACKUP`, to accept the server's identity: cron has no way to type a password or answer that prompt.

`# /root/.restic-env (chmod 600) export RESTIC_REPOSITORY="sftp:backup@IP_DO_SERVIDOR_DE_BACKUP:/srv/restic/minha-vps" export RESTIC_PASSWORD_FILE="/root/.restic-senha"`

### S3-compatible storage[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#destino-s3)

Any provider that speaks the S3 protocol works, or a MinIO of your own on another server, as in [installing MinIO on a VPS](https://streethosting.com.br/en/guides/vps/install-minio-on-vps). Create an access key restricted to the backup bucket.

`# /root/.restic-env (chmod 600) export RESTIC_REPOSITORY="s3:https://s3.seu-provedor.com/nome-do-bucket/minha-vps" export RESTIC_PASSWORD_FILE="/root/.restic-senha" export AWS_ACCESS_KEY_ID="SUA_CHAVE_DE_ACESSO" export AWS_SECRET_ACCESS_KEY="SEU_SEGREDO"`

With the file in place, initialize the repository once. From then on, every backup becomes a snapshot you can restore independently.

`sudo chmod 600 /root/.restic-env sudo bash -c 'source /root/.restic-env && restic init'`

## Backup script[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#script-backup)

The script does four things in order: it generates the dumps, sends the backup, applies retention and tells a monitor it finished. With `set -euo pipefail`, any error stops execution before the final notification, and that silence is what becomes the alert.

`#!/usr/bin/env bash # /usr/local/sbin/backup-restic.sh set -euo pipefail umask 077 # dumps and files created here are readable only by root source /root/.restic-env # 1. database dumps (keep only what the VPS uses) mkdir -p /var/backups/db sudo -u postgres pg_dump -Fc app > /var/backups/db/app.dump # mariadb-dump --single-transaction --routines --all-databases > /var/backups/db/mariadb.sql # 2. backup to the external repository restic backup /etc /srv /opt /var/backups/db \ --exclude-caches \ --exclude "node_modules" \ --tag diario # 3. retention restic forget --tag diario --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --prune # 4. tell the monitor everything went fine curl -fsS -m 10 "https://kuma.seu-dominio.com.br/api/push/SEU_TOKEN?status=up&msg=OK" > /dev/null`

`sudo chmod 700 /usr/local/sbin/backup-restic.sh sudo /usr/local/sbin/backup-restic.sh`

For databases, generate a dump before the backup. Copying the database file while it is in use can produce an inconsistent snapshot. Both `pg_dump` and `mariadb-dump --single-transaction` produce a coherent copy without stopping the application.

The last line uses an Uptime Kuma Push monitor: if the script fails or never runs, the call never arrives and the alert fires. How to create that monitor is covered in [VPS monitoring with Uptime Kuma](https://streethosting.com.br/en/guides/vps/uptime-kuma-vps-monitoring). Set the monitor interval slightly above 24 hours for a daily backup.

## Schedule with cron[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#agendar)

Add the script to cron so it runs at a low-usage hour, like the early morning. If you are not yet comfortable with scheduling, see [cron and scheduled tasks on a VPS](https://streethosting.com.br/en/guides/vps/schedule-tasks-vps-cron). A file in `/etc/cron.d` keeps the routine visible and versionable:

`# /etc/cron.d/backup-restic SHELL=/bin/bash PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin # daily backup at 3:30 AM 30 3 * * * root flock -n /run/backup-restic.lock /usr/local/sbin/backup-restic.sh >> /var/log/backup-restic.log 2>&1 # Sunday at 5 AM: checks integrity by reading a random 10% of the data 0 5 * * 0 root source /root/.restic-env && restic check --read-data-subset=10\% >> /var/log/backup-restic.log 2>&1`

The `flock -n` call prevents a backup from starting while the previous one is still running, which happens when the volume grows or the destination gets slow. The weekly check reads 10% of the data, picked at random on every run, and over the weeks it detects corruption at the destination before you need it. On the command line the value is just `10%`; in the crontab, the backslash before the symbol is mandatory, because cron turns an unescaped percent sign into a line break. Watch the log to catch failures before they turn into an emergency.

## Retention with forget and prune[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#retencao)

Without retention, the repository grows forever. The `forget` command decides which snapshots stay, and `prune` deletes the data that no remaining snapshot uses. The script's policy works like this:

* **keep daily 7:** the last snapshot from each of the 7 most recent days that had a backup.
* **keep weekly 4:** the last one from each of the 4 most recent weeks.
* **keep monthly 6:** the last one from each of the 6 most recent months.

That is up to 17 restore points covering half a year. Thanks to deduplication, this does not take up 17 times the size of the data: each snapshot only adds what changed. Before changing the policy, see what would be removed:

`sudo bash -c 'source /root/.restic-env && restic forget --tag diario --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --dry-run' sudo bash -c 'source /root/.restic-env && restic stats --mode raw-data'`

On large repositories, prune is the heaviest step. If it starts delaying the backup, take `--prune` out of the daily script and run prune once a week, from cron. And keep the backup paths stable: forget groups snapshots by host and by folder list, and changing the list creates a new group with its own retention.

## Test the restore[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#testar-restauracao)

The restore test is what separates a real backup from a false sense of security. Once a month, restore a folder and a database to a temporary area and compare:

`sudo -i source /root/.restic-env restic snapshots restic ls latest /etc/nginx # restores only one folder into a test directory restic restore latest --target /tmp/restore-teste --include /etc/nginx diff -r /etc/nginx /tmp/restore-teste/etc/nginx # restores the database dump and loads it into a test database restic restore latest --target /tmp/restore-teste --include /var/backups/db sudo -u postgres createdb app_teste sudo -u postgres pg_restore -d app_teste < /tmp/restore-teste/var/backups/db/app.dump`

From time to time, run the full rehearsal: order a new VPS, install restic, point it at the same repository using the password stored in your manager, restore everything and bring the application up. Write down how long it took. That rehearsal proves the password really is off the VPS, that the destination access key works on a fresh machine and that the step by step is written down. When you need to move a stray file between the machines during the test, [SCP and rsync](https://streethosting.com.br/en/guides/vps/transfer-files-to-vps-scp-rsync) get it done.

* Snapshots created at an external destination
* Repository password stored off the VPS
* Retention policy keeping space under control
* Push monitor alerting when the backup does not run
* Restore tested in a separate environment

## Where to keep the backup[](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#onde-guardar)

StreetHosting VPS plans do not come with automatic snapshots or an included backup service: the routine in this guide is what protects your data, and it is worth setting up the same day the VPS goes into production. The VPS itself runs in São Paulo, with root access, Anti-DDoS and activation within 60 seconds, so restic works with no restrictions at all.

For the external destination, a second VPS dedicated to storing backups is the simplest path with SFTP. Since restic deduplicates, repositories of a few dozen GB fit on a Xeon VPS with 40 GB of NVMe for R$ 40.00 a month, or 80 GB for R$ 77.00. One honest caveat: two VPS in the same datacenter protect against losing the machine, intrusion and human error, but not against a problem that hits the whole site. For the off-site copy the 3 2 1 rule calls for, also keep a repository in S3-compatible storage in another region or on a server at another location. Compare the plans on the [VPS page](https://streethosting.com.br/en/vps).

Think about whoever breaks into the VPS too. With root, the intruder reads `/root/.restic-env` and can delete the repository along with the server. To close that door, use a destination the VPS can write to but not delete from: restic's rest server in `--append-only` mode or an S3 key without delete permission. In that arrangement, forget and prune leave the VPS script and run from another trusted machine, with credentials the VPS does not know.

In this guide

* [Why restic](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#por-que-restic)
* [What to back up, how often and for how long](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#estrategia)
* [Prepare the repository](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#preparar)
* [Backup script](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#script-backup)
* [Schedule with cron](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#agendar)
* [Retention with forget and prune](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#retencao)
* [Test the restore](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#testar-restauracao)
* [Where to keep the backup](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron#onde-guardar)

## Frequently asked questions

Why send the backup off the VPS?

Because a backup on the same machine does not protect against losing the server, ransomware or accidental deletion. Keeping an external copy, on another server or in S3-compatible storage, follows the rule of keeping copies in different places.

Does restic encrypt the backups?

Yes. restic encrypts everything with the repository password before sending it to the destination. That is why you should keep that password somewhere safe and separate from the VPS. Without it, not even you can recover the data.

How do I keep the backup from filling the disk?

With the retention policy. forget with options like keep daily, keep weekly and keep monthly decides which snapshots stay, and prune deletes the data no snapshot uses anymore, keeping the space at the destination under control.

How often should I back up the VPS?

It depends on how much data you can afford to lose. A daily backup covers most projects. Write-heavy databases call for dumps every few hours, and configuration files can go into every backup because they take up almost nothing.

Does an automatic backup remove the need for testing?

No. A backup that has never been restored is not reliable. Restore a folder every month and do a full recovery on a fresh VPS from time to time to make sure the data really comes back when you need it.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Xeon VPS Xeon VPS for steady workloads, automation and long-running projects.](https://streethosting.com.br/en/vps/xeon)

## Related guides

[Infrastructure Beginner The 3-2-1 backup strategy for servers The 3-2-1 rule is one of the most reliable ways to reduce data loss after a technical failure or a human mistake. 2 min Read guide](https://streethosting.com.br/en/guides/infrastructure/3-2-1-backup-strategy) [VPS Intermediate How to schedule tasks on a VPS with cron A repetitive task you do by hand is a task you forget. Cron runs commands at fixed times: a backup overnight, a weekly cleanup, a scheduled restart. Here is how to set it up. 3 min Read guide](https://streethosting.com.br/en/guides/vps/schedule-tasks-vps-cron) [VPS Advanced How to install MinIO on a VPS: S3, HTTPS and alternatives MinIO became the go-to name for self-hosted S3 storage, but the community edition was archived and no longer receives fixes. Here is how to install it anyway, with a volume, a domain and HTTPS, and which maintained alternatives to evaluate for new projects. 10 min Read guide](https://streethosting.com.br/en/guides/vps/install-minio-on-vps)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
