Back to articles
Technology Insight

Build a Zero-Trust Cloud Backup Server: Implementing Enterprise Encryption and Deduplication with Kopia and rsync.net

June 1, 2026

Introduction: The Growing Challenges of Enterprise Data Protection

In the modern digital landscape, data is arguably an organization's most valuable asset. However, securing this data against ransomware, hardware failures, and accidental deletion has become increasingly complex. IT professionals and businesses face a triple challenge: ensuring absolute data privacy, managing skyrocketing cloud storage costs, and maintaining fast, reliable recovery pipelines.

Traditional backup solutions often force a compromise between security and efficiency. Legacy systems may lack modern Zero-Trust encryption, or they may fail to optimize storage space, leading to bloated cloud bills. To address these challenges, enterprise architects are turning to modular, best-of-breed open-source tooling paired with hardened cloud storage providers. This article provides a comprehensive blueprint for building a high-performance, fully encrypted, and highly deduplicated cloud backup server using Kopia and rsync.net.

Why Kopia and rsync.net? The Architecture of a Perfect Backup Strategy

To understand why the combination of Kopia and rsync.net is exceptionally powerful, we must look at the structural strengths of both components. Together, they fulfill the core requirements of the robust 3-2-1 backup strategy (3 copies of data, across 2 different media types, with 1 copy stored offsite).

Kopia: Next-Generation Fast and Secure Open-Source Backup

Kopia is an open-source backup tool that stands out for its speed, security, and efficiency. Unlike older utilities, Kopia is designed from the ground up with modern cloud topology in mind. It operates on a repository-based architecture and offers several critical advantages:

  • Content-Defined Chunking (CDC): Kopia breaks files into variable-sized chunks to perform global deduplication. If multiple files share identical blocks of data, those blocks are uploaded only once, radically reducing storage usage.
  • End-to-End Client-Side Encryption: All data is encrypted before it leaves your infrastructure. Kopia utilizes state-of-the-art cryptographic algorithms like AES-256-GCM or ChaCha20-Poly1305, ensuring that even if the storage layer is compromised, your data remains completely unreadable to third parties.
  • Mountable Snapshots: Kopia allows administrators to mount historical backup snapshots as local filesystems, facilitating seamless, granular file recovery.

rsync.net: The Hardened, Cloud-ZFS Storage Layer

A backup tool is only as good as the storage backend hosting its repository. While standard object storage providers are common, rsync.net offers a uniquely robust platform designed specifically for technical professionals. Operating since 2001, rsync.net provides a raw, standard UNIX filesystem accessible entirely over SSH. Key advantages include:

  • ZFS Underlying Filesystem: Every rsync.net account runs on a ZFS storage pool, providing native protection against silent data corruption (bit rot) via automated scrub cycles.
  • Immutable ZFS Snapshots: Even if a malicious actor gains access to your backup credentials and attempts to delete your Kopia repository, rsync.net maintains independent, immutable ZFS snapshots that cannot be altered or deleted by the user client. This provides definitive protection against ransomware.
  • No Egress or API Fees: Unlike traditional cloud vendors, rsync.net charges a flat fee based strictly on storage volume, eliminating unpredictable costs during mass data recoveries.

Step-by-Step Implementation: Building the Infrastructure

This technical guide assumes access to a Linux-based server acting as the production environment and an active rsync.net account. We will walk through installing Kopia, configuring the secure connection to rsync.net, initializing the deduplicated repository, and automating the backup lifecycle.

Step 1: Installing Kopia on the Source Infrastructure

Kopia is written in Go, resulting in a single, self-contained binary. To install Kopia on a Debian/Ubuntu-based server, execute the following commands to add the official repository:

curl -s [https://kopia.io/signing-key](https://kopia.io/signing-key) | sudo gpg --dearmor -o /usr/share/keyrings/kopia-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/kopia-keyring.gpg] [https://kopia.io/apt](https://kopia.io/apt) stable main" | sudo tee /etc/apt/sources.list.d/kopia.list
sudo apt-get update
sudo apt-get install kopia

Verify the installation by checking the client version: kopia --version.

Step 2: Configuring SSH Key Authentication for rsync.net

Kopia interacts with rsync.net using the Secure Shell (SSH) protocol via SFTP. To allow automated, non-interactive backups, you must configure passwordless SSH keys. Generate a secure SSH key pair on your source server:

ssh-keygen -t ed25519 -b 4096 -f ~/.ssh/id_kopia_backup -C "kopia-backup-key"

Next, upload the public key to your rsync.net account using the standard SSH copy utility:

cat ~/.ssh/id_kopia_backup.pub | ssh [email protected] "dd of=.ssh/authorized_keys oflag=append conv=notrunc"
Note: Replace '12345' with your actual rsync.net user ID and 'ch-s012.rsync.net' with your assigned rsync.net hostname. Verify you can connect seamlessly via SFTP before proceeding.

Step 3: Initializing the Encrypted Kopia Repository

With the transport layer secured, we can now initialize the Kopia repository directly on rsync.net. During this initialization phase, Kopia establishes its internal database, chunking algorithms, and primary encryption keys.

Run the following initialization command, explicitly defining SFTP as the backend:

kopia repository create sftp \
  --host=ch-s012.rsync.net \
  --username=12345 \
  --keyfile=$HOME/.ssh/id_kopia_backup \
  --path=kopia-repository \
  --encryption=AES256-GCM-HMAC-SHA256 \
  --block-hash=BLAKE3-256-COPPER

You will be prompted to create a repository password. Warning: This password is the master key used to derive your client-side encryption keys. If lost, the data hosted on rsync.net is permanently unrecoverable. Store this password securely in an enterprise password manager.

Step 4: Executing the First Deduplicated Backup

Once the repository is initialized, Kopia automatically connects to it. To verify your connection status at any time, use kopia repository status. To perform your first deduplicated backup snapshot of a critical directory (e.g., /var/www/html or /opt/data), run:

kopia snapshot create /opt/data

During the initial run, Kopia scans the source directory, breaks files into chunks, hashes them via BLAKE3, encrypts them locally, and pushes them to rsync.net via SFTP. On subsequent runs, Kopia will only process and upload blocks that have physically changed, minimizing bandwidth consumption and shrinking backup windows to seconds.


Advanced Configuration: Compression, Retention, and Automation

To optimize an enterprise deployment, relying on default settings is insufficient. We must tune compression algorithms, establish strict data retention policies, and automate execution via system schedulers.

Optimizing Compression and Global Policies

Kopia allows administrators to set global or directory-specific compression policies. For optimal performance with mixed text and binary data, the ZSTD (Zstandard) compression algorithm offers an ideal balance between speed and compression ratio:

kopia policy set --global --compression=zstd-better-compression

Additionally, define retention schedules to automatically purge obsolete data while retaining critical historical snapshots. A standard enterprise retention policy can be applied via:

kopia policy set --global \
  --keep-latest 10 \
  --keep-hourly 24 \
  --keep-daily 7 \
  --keep-weekly 4 \
  --keep-monthly 12

Automating Backups with Systemd Timers

To integrate this setup into production environments, automate execution using Linux systemd service and timer units, which offer far superior error logging and reliability over traditional cron jobs.

Create a service file at /etc/systemd/system/kopia-backup.service:

[Unit]
Description=Kopia Automated Cloud Backup
After=network-online.target

[Service]
Type=oneshot
Environment="KOPIA_PASSWORD=your_secure_repository_password"
ExecStart=/usr/bin/kopia snapshot create /opt/data
StandardOutput=journal

Create the accompanying timer file at /etc/systemd/system/kopia-backup.timer to run the backup every 4 hours:

[Unit]
Description=Run Kopia Backup Every 4 Hours

[Timer]
OnCalendar=*-*-* 00,04,08,12,16,20:00:00
Persistent=true

[Install]
WantedBy=timers.target

Enable and start the timer using systemctl: sudo systemctl enable --now kopia-backup.timer.


Conclusion: Achieving Total Peace of Mind

By coupling the cutting-edge deduplication and architectural speed of Kopia with the unyielding, ZFS-backed environment of rsync.net, you create a top-tier backup matrix. Data is heavily optimized before ingestion, strictly encrypted on the client side, and completely shielded from ransomware threats via immutable snapshots. Implementing this architecture ensures your enterprise remains secure, regulatory-compliant, and fiscally lean.

Build a Zero-Trust Cloud Backup Server: Implementing Enterprise Encryption and Deduplication with Kopia and rsync.net | DPTCloud