Back to articles
Technology Insight

Automating Daily VPS Backups: A Comprehensive Guide to Setting Up Borgmatic

May 30, 2026

Introduction: The Imperative of Automated VPS Backups

In the modern digital economy, data is arguably a company's most valuable asset. For businesses operating on Virtual Private Servers (VPS), a robust backup strategy is not merely a technical best practice; it is a critical component of risk management and business continuity. Hardware failures, software corruption, cyberattacks, or simple human error can disrupt operations instantly. To mitigate these risks, automation is essential. Manually executing backups introduces inconsistency and room for error.

Enter BorgBackup and its powerful configuration wrapper, Borgmatic. BorgBackup provides secure, deduplicated, and encrypted backups, while Borgmatic simplifies the entire process with declarative configuration files. This guide delivers a step-by-step framework to establish fully automated, daily VPS backups using Borgmatic, ensuring your enterprise data remains resilient and recoverable.

Whether you manage a single application server or an entire infrastructure, implementing this setup will significantly elevate your data protection standards.

---

Why Choose Borgmatic for Enterprise VPS Backups?

Before diving into the configuration, it is vital to understand why Borgmatic stands out in a crowded marketplace of backup solutions. Traditional backup methods often copy entire files, leading to massive storage overhead and prolonged backup windows. Borgmatic solves these challenges through three core pillars:

  • Deduplication: Borg splits files into variable-sized chunks and only stores unique chunks. If a file changes slightly, only the modified pieces are saved, drastically reducing storage costs.
  • Strong Encryption: Data can be encrypted client-side using authenticated encryption (AES-256), ensuring that your backups remain confidential, even when stored on untrusted cloud providers.
  • Pruning and Flexibility: Borgmatic allows you to define complex retention policies (e.g., keep 7 daily, 4 weekly, and 12 monthly backups) and automates the deletion of obsolete archives.
"An untested backup is not a backup." Borgmatic includes built-in consistency checks, validating that your archives are not only created but are also fully functional and free from corruption.
---

Prerequisites and Environment Setup

To successfully implement this guide, ensure your environment meets the following requirements:

  1. A VPS running a modern Linux distribution (e.g., Ubuntu 22.04 LTS or Debian 12).
  2. Root or sudo administrative privileges on the server.
  3. A designated backup repository destination. This could be a separate storage VPS, a local secondary drive, or a cloud storage provider supporting SSH/SFTP (such as BorgBase or Rsync.net).

Step 1: Installing BorgBackup and Borgmatic

First, update your package repository and install the necessary software. While many distributions include Borgmatic in their default package managers, using Python's package installer (pip) or dedicated repositories ensures you receive the latest security patches and features.

For Ubuntu/Debian systems, execute the following commands:

sudo apt update && sudo apt install -y borgbackup borgmaticVerify the installation by checking the versions:

borg --version && borgmatic --version

---

Configuring Borgmatic for Daily Operations

Borgmatic relies on a central configuration file, typically formatted in YAML, located at /etc/borgmatic/config.yaml. This file dictates what to back up, where to store it, and how to manage retention.

Step 2: Generating the Configuration Template

Generate a clean template using the built-in Borgmatic initialization tool:

sudo generate-borgmatic-config

Next, open the file using your preferred text editor (e.g., sudo nano /etc/borgmatic/config.yaml) and modify the primary blocks to reflect your environment.

Step 3: Customizing the Configuration File

Below is a production-ready blueprint for your configuration. It specifies directories to include, database dumps, and retention policies.

# /etc/borgmatic/config.yaml
location:
    # List of local source directories to back up
    source_directories:
        - /var/www
        - /etc
        - /home

    # Paths to your encryption keys and cache
    repositories:
        - [email protected]:main.borg

storage:
    # Encryption passphrase for the repository
    encryption_passphrase: "YOUR_SUPER_SECURE_PASSPHRASE"

retention:
    # Keep daily backups for 7 days, weekly for 4, and monthly for 6
    keep_daily: 7
    keep_weekly: 4
    keep_monthly: 6

consistency:
    # Run checks to ensure repository integrity
    checks:
        - repository
        - archives
    check_frequency: 1 week

Note: Replace "YOUR_SUPER_SECURE_PASSPHRASE" with a strong, randomly generated string and store a copy in an offline password manager. If you lose this key, your backups will be permanently unrecoverable.

---

Initializing the Repository

Before Borgmatic can execute daily backups, the destination repository must be initialized with the chosen encryption settings. Run the initialization command via Borgmatic:

sudo borgmatic rcreate --encryption repokey-blake2

This command safely communicates with your remote or local storage, establishes the file structure, and applies the encryption key based on your config.yaml settings.

---

Automating Backups via Cron or Systemd

With configuration complete, the final phase is automation. We want the system to run these backups every day without human intervention. You can achieve this using either cron or systemd timers. We recommend systemd due to its superior logging capabilities.

Option A: Using Systemd Timers (Recommended)

Modern Linux distributions prefer systemd for scheduled tasks. Borgmatic often ships with systemd service files automatically. Enable and start the timer with these commands:

sudo systemctl enable borgmatic.timer --now

To view the status of the timer and confirm when the next backup is scheduled to run, use:

systemctl status borgmatic.timer

Option B: Using a Classic Cron Job

If you prefer standard cron, edit the root crontab file:

sudo crontab -e

Add the following line to execute Borgmatic every morning at 2:00 AM:

0 2 * * * /usr/bin/borgmatic --syslog --verbosity -1

The --syslog flag ensures that all outputs and errors are forwarded directly to the system logs for audit purposes.

---

Testing Your Backup Strategy

An untested backup strategy is a critical point of failure. You must proactively verify your configuration. Run a manual backup to ensure everything processes correctly:

sudo borgmatic create --verbosity 1

If the backup completes without errors, test the data extraction process. To list all available backups, execute:

sudo borgmatic listTo simulate a restoration of a single file or folder to a temporary directory:

sudo borgmatic extract --archive latest --path var/www

---

Conclusion: Peace of Mind Through Automation

Implementing an automated, encrypted backup system with Borgmatic drastically improves your enterprise security posture. By investing a small amount of time into setting up deduplicated daily backups, you insulate your business from devastating data loss incidents. Your VPS is now protected by enterprise-grade encryption, efficient storage utilization, and robust systemd automation. Regularly audit your logs, perform mock restorations quarterly, and let automation handle the heavy lifting.

Automating Daily VPS Backups: A Comprehensive Guide to Setting Up Borgmatic | DPTCloud