Back to articles
Technology Insight

Building a Bulletproof Immutable Backup System for VPS: Combatting Ransomware with BorgBackup and Rclone Append-Only

May 29, 2026

The Evolution of Ransomware and the Necessity of Backup Immutability

In the modern enterprise landscape, data is both the most valuable asset and the most targeted vulnerability. Traditional backup strategies operate on a simple principle: replicate data from a primary server to a secondary storage destination. However, modern ransomware strains have evolved far beyond simple localized file encryption. Today's sophisticated cyber threats actively search for network shares, API keys, and configuration files to locate, compromise, and delete your backups before encrypting the primary infrastructure.

If an attacker gains root access to your Virtual Private Server (VPS), any standard automated backup routine—such as a basic rsync cron job or a writable network mount—becomes a liability. The attacker can simply run a deletion script across your backup repositories, leaving your organization with zero recovery vectors. To mitigate this catastrophic risk, system administrators must pivot toward Immutable Backups: data that, once written, can neither be modified, overwritten, nor deleted by any user or process for a predetermined retention period, even if the primary server's root credentials are fully compromised.

This comprehensive technical guide outlines how to build an enterprise-grade, cost-effective, and completely immutable backup pipeline for your VPS. By combining the local efficiency of BorgBackup with the remote append-only isolation of Rclone, you can construct a resilient defense architecture that guarantees data recovery in the wake of a total system compromise.

Understanding the Architectural Components

To implement a zero-trust backup framework, we leverage two highly stable, open-source utilities that complement each other's strengths perfectly:

  • BorgBackup (Borg): A deduplicating backup program that provides secure, authenticated, and encrypted client-side backups. Borg excels at breaking files into variable-sized chunks to ensure only unique data is stored, radically reducing storage footprints and bandwidth utilization.
  • Rclone: A versatile command-line program used to manage and sync files with cloud storage providers. When configured with specialized flag parameters, Rclone can interface with cloud storage in a strict append-only manner, acting as an unidirectional gateway that prohibits file modifications or deletions from originating on the VPS.

The Security Topology

The core philosophy of this design relies on privilege separation. The architectural workflow operates through three distinct layers:

  1. The Source (VPS Local): Borg executes locally, creating encrypted, deduplicated snapshot archives stored inside a local staging repository directory.
  2. The Middleware (Rclone Gateway): Rclone takes the local Borg repository chunks and pushes them to a remote cloud object storage. Crucially, the Rclone configuration utilizes an Append-Only policy combined with a cloud bucket policy that explicitly denies the DeleteObject and PutObject (overwrite) permissions to the API keys stored on the VPS.
  3. The Immutable Destination: Cloud Object Storage (such as AWS S3, Backblaze B2, or Wasabi) configured with Object Lock or strict Identity and Access Management (IAM) restriction policies that prevent any data modification, even if the Rclone configuration file on the VPS is stolen by malicious actors.

Step-by-Step Implementation Guide

Let us walk through the complete deployment process required to provision this robust backup pipeline on a standard Linux-based VPS infrastructure.

Step 1: Installing the Required Toolsets

First, update your package repository and install both BorgBackup and Rclone. For modern Ubuntu/Debian distributions, execute the following commands:

sudo apt update && sudo apt install -y borgbackup rclone

Verify the installations by checking the software versions to ensure compatibility with advanced encryption algorithms:

borg --version
rclone --version

Step 2: Initializing the Local Borg Repository

Before saving any snapshots, you must create a dedicated storage directory and initialize a secure Borg repository. We recommend using the repokey-blake2 encryption mode, which embeds the encryption key securely inside the repository itself while protecting it with a heavy-duty passphrase.

# Create a secure staging directory for Borg
sudo mkdir -p /var/backups/borg-local
sudo chmod 700 /var/backups/borg-local

# Initialize the encrypted repository
export BORG_PASSPHRASE="YourSuperSecurePassphraseHere"
borg init --encryption=repokey-blake2 /var/backups/borg-local
Critical Security Warning: You must safely back up the BORG_PASSPHRASE text string and the repository key file to an external password manager. If this passphrase is lost, your backup data becomes completely unrecoverable, as the encryption cannot be brute-forced.

Step 3: Configuring the Cloud Storage and Rclone

Next, set up your target cloud bucket. For this blueprint, we will assume the use of an S3-compatible cloud provider. Log into your cloud management console and perform the following structural tasks:

  • Create a new private bucket dedicated solely to your VPS backups.
  • Enable Object Lock or Bucket Versioning if native API immutability is desired.
  • Create an isolated IAM user account with a policy restricted exclusively to this bucket. The IAM policy should permit ListBucket, GetObject, and PutObject, but must completely omit or explicitly Deny DeleteObject, DeleteObjectVersion, and PutBucketPolicy.

Once the cloud API access keys are generated, configure Rclone on your VPS by running:

rclone config

Follow the interactive prompt to create a new remote named remote-s3, assigning the correct S3 endpoint, region, Access Key, and Secret Key. Ensure that you test the connection by listing the bucket contents:

rclone lsd remote-s3:your-bucket-name

Step 4: Writing the Automation Script with Append-Only Enforcement

To bind these elements into an automated, ransomware-proof mechanism, we construct a bash script that triggers a local Borg backup archive creation, followed immediately by an immutable Rclone synchronization process.Create a script located at /usr/local/bin/backup-immutable.sh:

#!/bin/bash

# Exit immediately if any command fails
set -e

# Configuration Variables
export BORG_PASSPHRASE="YourSuperSecurePassphraseHere"
LOCAL_REPO="/var/backups/borg-local"
REMOTE_DEST="remote-s3:your-bucket-name/vps-backup"
TIMESTAMP=$(date +"%Y-%m-%d_%H-%M-%S")

echo "[$(date)] Starting local Borg Backup creation..."
borg create --stats --progress ${LOCAL_REPO}::"backup-${TIMESTAMP}" \
    /var/www \
    /etc \
    /home

echo "[$(date)] local snapshot created successfully."

echo "[$(date)] Initiating Append-Only Cloud Synchronization via Rclone..."
# The critical flag combination to enforce immutability:
rclone sync ${LOCAL_REPO} ${REMOTE_DEST} \
    --immutable \
    --append-only \
    --fast-list \
    --verbose

echo "[$(date)] Backup process fully finalized and secured."

Make the script executable and strictly restrict its read/write access permissions to the system root user:

sudo chmod 700 /usr/local/bin/backup-immutable.sh
sudo chown root:root /usr/local/bin/backup-immutable.sh

Why This Setup Prevents Ransomware Deletion

Understanding the defensive architecture requires examining a worst-case scenario. Imagine a malicious actor gains full root access to your VPS. They discover the backup script, extract the Rclone configuration file, and attempt to delete all cloud-hosted backups to force a ransom payment.

The attack fails completely due to the following layers of security enforcement:

  • The --immutable and --append-only Flags: The Rclone engine blocks local requests from processing deletions or modifications of existing cloud structures.
  • The Cloud IAM/Object Lock Policy: Even if the attacker bypasses the local Rclone executable and communicates directly with the cloud service using the intercepted API keys, the cloud provider will reject any DeleteObject API calls. Because the API keys lack deletion privileges, the cloud-side storage repository remains completely untouched.
  • Client-Side Cryptography: Because Borg completely encrypts the data locally before transmission, the cloud provider never sees raw server data. Even if the cloud console itself were somehow monitored, your data remains fully private and unreadable to third parties.

Maintenance and Pruning in an Append-Only Environment

An append-only architecture introduces an obvious practical challenge: storage accumulation. Over time, as your system generates files, the repository size grows indefinitely because the VPS cannot execute a borg prune or rclone cleanup command without deletion privileges.

To solve this without breaking security compliance, you must establish a Lifecycle Management System or a dedicated administrative workstation separated entirely from your production environment:

The Isolated Administrative Workstation Method

To safely prune old backups and minimize cloud storage costs, maintain a completely independent server or a local secure office machine that contains a separate, high-privilege cloud API credential. This credential does possess deletion rights to the backup bucket.

Once a week or once a month, this administrative machine connects directly to the cloud object bucket, mounts it, runs the borg prune and borg compact commands to clean up expired archives, and updates the cloud index. Because the VPS never holds these high-privilege keys, an attack on your live website or web server cannot affect your historical data repositories.

Conclusion

Ransomware defense requires moving away from traditional reactive strategies toward rigorous zero-trust systems. By implementing a bifurcated backup stack combining BorgBackup's deduplicating storage efficiency with Rclone's append-only remote synchronization, you effectively sever the bridge that allows attackers to destroy your recovery infrastructure.

Spend the hour required to set up this system today; the peace of mind knowing that your enterprise data is completely immutable and instantly restorable is worth every line of configuration.

Building a Bulletproof Immutable Backup System for VPS: Combatting Ransomware with BorgBackup and Rclone Append-Only | DPTCloud