Back to articles
Technology Insight

Automating VPS Backups: How to Configure Borgmatic with Cloudflare R2 for Daily Enterprise-Grade Security

May 30, 2026

Introduction: The Imperative of Automated VPS Backups

In the digital-first business landscape, data is arguably an organization's most valuable asset. Whether you are running a production web application, a customer relationship management (CRM) system, or a database backend on a Virtual Private Server (VPS), data integrity is paramount. Hardware failures, software corruption, malicious cyberattacks, or simple human error can result in catastrophic data loss. To mitigate these risks, a robust, automated, and offsite backup strategy is not just a best practice—it is a fundamental business operational requirement.

However, traditional backup methods often suffer from high storage costs, slow transfer speeds, or complex management overhead. This article provides a comprehensive, technical walkthrough on how to implement an enterprise-grade, automated backup pipeline. By combining Borgmatic—a powerful, configuration-driven wrapper for the BorgBackup tool—with Cloudflare R2, an S3-compatible object storage service known for its zero-egress fees, businesses can achieve secure, deduplicated, and highly cost-effective daily backups.


Why Choose Borgmatic and Cloudflare R2?

Before diving into the technical configuration, it is essential to understand why this specific technology stack represents an optimal solution for modern enterprise infrastructure.

1. Borgmatic: Efficiency, Encryption, and Automation

Borgmatic is built on top of BorgBackup, a deduplicating backup program. Unlike traditional backup utilities that copy entire files or rely on brittle incremental chains, Borgmatic breaks data into variable-sized chunks. Only unique chunks are stored, resulting in massive space savings. Key benefits include:

  • Authenticated Encryption: All data is encrypted client-side using AES-256 before leaving your VPS, ensuring absolute privacy.
  • Declarative Configuration: Backups are managed via a single, human-readable YAML configuration file, minimizing the risk of deployment errors.
  • Data Integrity Validation: Built-in consistency checks verify that your archives are not corrupted and remain fully restorable.

2. Cloudflare R2: High Performance with Zero Egress Fees

Cloudflare R2 provides object storage that eliminates the unpredictable financial burden traditionally associated with cloud backups: egress fees. In standard cloud ecosystems, retrieving your data during a disaster recovery scenario incurs heavy bandwidth charges. Cloudflare R2 charges purely for storage volume and operations, making budget forecasting predictable and reducing total cost of ownership (TCO).


Prerequisites and Architecture Overview

To successfully implement this architecture, ensure you have the following administrative access and components ready:

  1. A VPS running a modern Linux distribution (e.g., Ubuntu 22.04 LTS or Debian 12) with root or sudo privileges.
  2. A Cloudflare account with R2 storage enabled.
  3. Basic familiarity with the Linux command-line interface.
Architecture Note: The backup workflow operates entirely on a push model. The VPS initiates the backup process, securely compresses and encrypts the targeted directories and databases locally, and then streams the encrypted chunks directly to the Cloudflare R2 bucket using the S3 compatibility API layer.

Step-by-Step Implementation Guide

Step 1: Provisioning Cloudflare R2 Storage and Credentials

First, we must prepare the cloud storage destination and generate the necessary API keys for authentication.

  1. Log in to your Cloudflare Dashboard and navigate to the R2 section from the sidebar.
  2. Click Create bucket. Name your bucket descriptively (e.g., enterprise-vps-backups) and select your preferred data location hint, then click Create bucket.
  3. Navigate back to the main R2 page and click on Manage R2 API Tokens on the right side.
  4. Click Create API token. Provide a token name, set the permissions to Edit (required to write and delete old backups), and restrict it to your specific bucket for security isolation.
  5. Click Create Token. Copy the Access Key ID, Secret Access Key, and the S3 Endpoint URL immediately. These will not be displayed again.

Step 2: Installing Borg and Borgmatic on the VPS

Connect to your VPS via SSH. Update your system package repository and install BorgBackup along with Borgmatic. We will utilize Python's package manager to ensure we receive the latest stable version of Borgmatic, which includes robust S3-compatibility features.

sudo apt update && sudo apt install -y borgbackup python3-pip python3-venv
sudo pip3 install --upgrade borgmatic

Verify the installation by checking the versions:

borg --version
borgmatic --version

Step 3: Generating the Borgmatic Configuration

Borgmatic simplifies backup administration via a central YAML file. Generate a default schema template using the built-in generator:

sudo generate-borgmatic-config

This creates a file at /etc/borgmatic/config.yaml. Open this file in your preferred text editor (e.g., sudo nano /etc/borgmatic/config.yaml) and modify it to reflect your corporate backup policies. Below is an enterprise-hardened configuration template customized for Cloudflare R2:

# /etc/borgmatic/config.yaml
location:
# Source directories to back up
source_directories:
- /var/www
- /etc
- /home

# Path to local or remote repositories. For R2, we use the S3 format.
repositories:
- s3://access_key_id:secret_access_key@bucket_name?endpoint_url=https://account_id.r2.cloudflarestorage.com

storage:
# Encryption passphrase for the repository
encryption_passphrase: "YOUR_SUPER_SECRET_PASSPHRASE_CHANGE_ME"

# Compression algorithm
compression: lz4

retention:
# Keep a rolling window of historical archives
keep_daily: 7
keep_weekly: 4
keep_monthly: 12

consistency:
# Verify consistency of archives daily
checks:
- repository
- archives
check_last: 1

Warning: Ensure you replace placeholders like access_key_id, secret_access_key, account_id, and YOUR_SUPER_SECRET_PASSPHRASE_CHANGE_ME with your actual Cloudflare credentials and a strong, randomly generated passphrase. Secure this file immediately by restricting access permissions:

sudo chmod 600 /etc/borgmatic/config.yaml

Step 4: Initializing the Remote Repository

Before Borgmatic can execute scheduled backups, the remote Cloudflare R2 repository must be initialized with the chosen encryption parameters. Execute the following initialization command:

sudo borgmatic rcreate --encryption repokey-blake2

This initializes the R2 bucket as a valid Borg repository. The repokey-blake2 mode stores the encryption key inside the repository itself, secured by your passphrase. Crucial: Back up your passphrase and repository key to an offline password manager. If you lose this key and passphrase, your cloud backups cannot be recovered.

Step 5: Testing a Manual Backup Execution

Validate your configuration and connectivity by running a manual backup in verbose mode:

sudo borgmatic create --verbosity 1 --progress

Monitor the console output. Borgmatic will parse the directories, chunk the data, apply compression and encryption, and transmit the payloads via HTTPS to Cloudflare R2. Once complete, list the remote archives to verify success:

sudo borgmatic list

Automating Daily Backups with Systemd

To ensure consistency, backups must run automatically without human intervention. We will leverage systemd timers, the modern standard for cron-like jobs in Linux enterprise environments, due to their superior logging via journalctl.

Borgmatic provides native systemd service files upon installation. You can activate the systemd timer directly to execute the backup routine automatically every day:

sudo systemctl enable --now borgmatic.timer

To view the schedule and verify that the timer is active, execute:

sudo systemctl list-timers borgmatic.timer

By default, the timer triggers Borgmatic daily at midnight, randomized slightly to prevent resource spikes on the host node.


Disaster Recovery: Restoring Your Data

A backup system is only as good as its restore process. In a total system failure scenario, spin up a replacement VPS, install Borgmatic, copy your original config.yaml to /etc/borgmatic/, and execute the following commands to inspect and extract your data.

To list all available recovery points:

sudo borgmatic list

To extract a specific archive entirely back into the root directory or a targeted directory:

# Extract the entire system from a specific archive date
sudo borgmatic extract --archive enterprise-vps-backups-2026-05-30

Conclusion

By leveraging the structural efficiency and cryptographic strength of Borgmatic alongside the cost efficiency and scale of Cloudflare R2, you have established a premier backup solution for your enterprise infrastructure. Data is deduplicated to minimize storage costs, encrypted to maintain compliance standards, and automated to ensure continuity. Regularly test your restoration workflow in an isolated staging environment to guarantee that your operational recovery time objectives (RTO) are continuously met.

Automating VPS Backups: How to Configure Borgmatic with Cloudflare R2 for Daily Enterprise-Grade Security | DPTCloud