Back to articles
Technology Insight

Automated VPS Backup to Cloud Storage: A Complete Guide for Backblaze B2 and Wasabi

May 17, 2026

Why Automated VPS Backups Are Non-Negotiable for Business Operations

In today's digital landscape, your Virtual Private Server (VPS) is more than just infrastructure; it's the operational backbone of your business. Whether hosting critical applications, databases, or customer-facing services, data loss is not a matter of if, but when. Hardware failures, software corruption, security breaches, and human error are constant threats. Relying on manual backups is a significant business risk, as they are prone to being forgotten, incomplete, or outdated when disaster strikes. Automated backups transform this vulnerability into a strategic strength, ensuring your data is consistently and reliably preserved without ongoing manual intervention.

Cloud storage solutions like Backblaze B2 and Wasabi have revolutionized data protection by offering durable, scalable, and cost-effective storage tiers specifically designed for backup and archival. Unlike traditional on-premises solutions, they provide geographic redundancy, eliminating the single point of failure inherent in local backups. For businesses, this means achieving enterprise-grade disaster recovery without the enterprise-grade price tag, making robust data protection accessible for organizations of all sizes.

Choosing Your Cloud Storage Partner: Backblaze B2 vs. Wasabi

Selecting the right cloud storage provider is a critical decision that balances cost, performance, and features. Both Backblaze B2 and Wasabi are excellent choices for VPS backups, but they cater to slightly different needs.

Backblaze B2: Simplicity and Predictable Pricing

Backblaze B2 Cloud Storage is renowned for its straightforward, transparent pricing model. You pay for the storage you use and the data you transfer out (egress). Its free egress tier (up to 3x your average daily stored data) is particularly attractive for backup scenarios where restores are infrequent. Backblaze offers a robust API, integrates seamlessly with many backup utilities, and provides strong durability guarantees. It's an ideal choice for businesses seeking a no-nonsense, reliable storage backend with excellent documentation and community support.

Wasabi: High Performance with No Egress Fees

Wasabi Hot Cloud Storage differentiates itself with a simple, flat rate that includes no charges for egress or API requests. This predictable cost structure is highly advantageous for businesses that require frequent data validation, test restores, or have unpredictable recovery needs. Wasabi boasts S3-compatible APIs, making it compatible with a vast ecosystem of tools, and offers performance-optimized storage. It's a compelling option for organizations that prioritize cost predictability and high-speed data access during recovery operations.

Key Consideration: While both services offer high durability, always verify their specific Service Level Agreements (SLAs) and data center locations to ensure compliance with your business's regulatory and latency requirements.

Architecting Your Automated Backup Solution

A robust automated backup system follows a clear, repeatable pipeline: data selection, compression/encryption, transfer, verification, and lifecycle management. The goal is to create a "set and forget" system that operates reliably in the background.

  1. Data Identification: Precisely define what needs to be backed up. This typically includes application directories (e.g., /var/www/), configuration files (/etc/), and most critically, database dumps.
  2. Local Processing: Before transmission, data should be compressed (using tar and gzip or zstd) and encrypted. Encryption is essential for protecting sensitive business data in the cloud. Use a strong passphrase or key-based encryption with tools like gpg or openssl.
  3. Cloud Transfer: Use a dedicated CLI tool like rclone or the provider's SDK to sync the processed backup archive to the cloud bucket. These tools handle retries, integrity checks, and incremental updates efficiently.
  4. Verification & Logging: The script must verify the upload was successful and log the outcome (success or failure with details) to a system log file or a monitoring service. Failure alerts are crucial.
  5. Lifecycle Management: Configure object lifecycle policies on the cloud storage bucket to automatically transition older backups to colder storage tiers or delete them after a defined retention period (e.g., 90 days).

Step-by-Step Implementation Guide

Prerequisites and Initial Setup

Begin by provisioning your resources and installing necessary software. On your VPS, ensure you have a non-root user with sudo privileges. You will need to install rclone, a powerful command-line tool for syncing files with cloud storage. Most Linux distributions offer it via their package manager (e.g., apt install rclone on Debian/Ubuntu). Simultaneously, create a storage bucket in your chosen cloud provider's console (Backblaze B2 or Wasabi). Note down the bucket name, endpoint URL, and your access keys (Key ID and Application Key for B2; Access Key and Secret Key for Wasabi).

Configuring Rclone for Secure Access

Run rclone config to create a new remote connection. Follow the interactive prompts. For Backblaze B2, select the b2 provider; for Wasabi, select s3 and specify the Wasabi endpoint (s3.wasabisys.com or region-specific). Provide your access credentials when prompted. This configuration is stored encrypted in ~/.config/rclone/rclone.conf. You can name this remote connection, for example, my-backblaze or my-wasabi.

Crafting the Backup Shell Script

Create a script, e.g., /usr/local/bin/vps-backup.sh. Below is a template demonstrating core principles. Remember to make it executable (chmod +x).

#!/bin/bash
# VPS Automated Backup Script
set -euo pipefail

# --- Configuration ---
BACKUP_NAME="vps-backup-$(date +%Y%m%d-%H%M%S)"
RCLONE_REMOTE="my-backblaze"  # Change to your rclone remote name
BUCKET_NAME="your-bucket-name"
ENCRYPTION_PASSPHRASE="your-strong-passphrase"  # Store this securely!
LOG_FILE="/var/log/vps-backup.log"

# Directories to back up
BACKUP_SOURCES=("/etc" "/var/www" "/home")

# --- Functions ---
log() {
    echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" | tee -a "$LOG_FILE"
}

# --- Main Execution ---
log "Starting VPS backup: $BACKUP_NAME"

# 1. Dump MySQL/MariaDB databases (if any)
mkdir -p "/tmp/$BACKUP_NAME"
if command -v mysqldump &> /dev/null; then
    log "Dumping MySQL databases..."
    mysqldump --all-databases --single-transaction --routines --events | gzip > "/tmp/$BACKUP_NAME/alldbs.sql.gz"
fi

# 2. Create compressed archive of file system directories
log "Creating filesystem archive..."
tar -czf "/tmp/$BACKUP_NAME/files.tar.gz" "${BACKUP_SOURCES[@]}" 2>/dev/null || true

# 3. Encrypt the backup bundle
log "Encrypting backup bundle..."
tar -czf - -C "/tmp" "$BACKUP_NAME" | \
    openssl enc -aes-256-cbc -salt -pbkdf2 -pass pass:"$ENCRYPTION_PASSPHRASE" -out "/tmp/$BACKUP_NAME.enc"

# 4. Upload to Cloud Storage
log "Uploading to $RCLONE_REMOTE:$BUCKET_NAME..."
if rclone copy "/tmp/$BACKUP_NAME.enc" "$RCLONE_REMOTE:$BUCKET_NAME/" --progress 2>&1 | tee -a "$LOG_FILE"; then
    log "Backup SUCCESS: $BACKUP_NAME.enc"
    # Optional: Send success notification (e.g., via email, Slack)
else
    log "Backup FAILED: $BACKUP_NAME.enc"
    # CRITICAL: Send failure alert to administrator
    exit 1
fi

# 5. Cleanup local temporary files
log "Cleaning up temporary files..."
rm -rf "/tmp/$BACKUP_NAME" "/tmp/$BACKUP_NAME.enc"

log "Backup process completed."

Security Note: The encryption passphrase in the script is a placeholder. In production, inject it via a secure environment variable or a dedicated secrets management tool, and never commit it to version control.

Automating with Systemd Timers or Cron

For robust, Linux-native scheduling, a systemd timer is recommended. Create a service file (/etc/systemd/system/vps-backup.service) to define the backup job and a timer file (/etc/systemd/system/vps-backup.timer) to schedule it (e.g., daily at 2 AM). Alternatively, the traditional cron scheduler works well. Add a line to the root crontab (sudo crontab -e):

0 2 * * * /usr/local/bin/vps-backup.sh > /dev/null 2>&1

Best Practices for a Production-Ready System

  • Implement the 3-2-1 Rule: Maintain at least three total copies of your data, on two different media, with one copy off-site. Your VPS is one copy, the cloud storage is the off-site copy. Consider a second, independent backup to a different provider or region for ultimate resilience.
  • Regularly Test Restores: An untested backup is as good as no backup. Schedule quarterly recovery drills. Download a backup archive, decrypt it, and verify you can extract critical files and restore a database. This validates the entire pipeline.
  • Monitor and Alert: Do not assume silent success. Monitor the backup log for errors. Integrate failure alerts with your existing monitoring stack (e.g., Nagios, Prometheus, or a simple email/Slack notification via a script hook).
  • Manage Retention and Costs: Configure lifecycle rules on your cloud bucket to automatically delete backups older than your defined retention period (e.g., 30, 60, or 90 days). This prevents cost overruns from indefinite storage accumulation.
  • Secure Your Credentials: Use IAM roles or limited-access keys where possible. For rclone, consider using its built-in support for obscuring configuration files or retrieving credentials from environment variables.

Conclusion: Building Unshakeable Data Resilience

Automating VPS backups to cloud storage is a fundamental pillar of modern IT operations. By leveraging services like Backblaze B2 or Wasabi and automation tools like rclone, you construct a cost-effective, reliable, and secure safety net for your business's digital assets. The initial investment in setting up this automated pipeline pays continuous dividends in risk reduction, operational peace of mind, and compliance readiness. Start by implementing the core script, then iteratively enhance it with monitoring, testing, and multi-region strategies. In the world of data, resilience is not a feature—it's the foundation.