Back to articles
Technology Insight

Building an Absolute Ransomware-Proof Immutable Backup System for VPS Using BorgBackup and Rclone Append-Only

May 29, 2026

The Escalating Threat: Why Traditional Backups Fail Against Ransomware

In the modern digital landscape, Virtual Private Servers (VPS) serve as the backbone for countless business applications, databases, and web services. However, this centralization makes them prime targets for cybercriminals. Among the myriad of security threats, Ransomware remains the most destructive. Modern ransomware variants no longer just encrypt your live production data; they actively scan your network and configuration files to locate, compromise, and delete your backup repositories before triggering the primary payload. If your backups are accessible with write or delete permissions from the compromised server, your entire disaster recovery plan is rendered useless.

To survive such sophisticated attacks, businesses must shift from traditional backup strategies to an Immutable Backup architecture. Immutability guarantees that once data is written, it cannot be modified, overwritten, or deleted for a predetermined retention period—even if an attacker gains root access to your VPS. This comprehensive guide outlines how to architect and implement an absolute ransomware-proof backup system using two powerful open-source tools: BorgBackup and Rclone configured in Append-Only mode.

Understanding the Architecture: BorgBackup and Rclone Append-Only

To build a resilient defense, we separate the responsibilities of data efficiency and access control into a two-tiered layer:

  • BorgBackup (Borg): A deduplicating backup program that provides authenticated, encrypted, and highly compressed backups. It ensures that only modified data blocks are uploaded, drastically reducing storage costs and backup windows.
  • Rclone: A versatile command-line program to manage files on cloud storage. By leveraging Rclone's advanced configuration profiles, specifically its --append-only flag and restricted API tokens, we can restrict the communication channel so that data can only be added, never deleted.

By combining these tools, the VPS can write new backup chunks to a remote cloud destination (such as AWS S3, Backblaze B2, or MinIO) via Rclone, but it completely lacks the administrative privileges required to execute delete operations. Even if an attacker gains full root access to your VPS, your historical backup archives remain entirely safe and untouched.

Step-by-Step Implementation Guide

Step 1: Installing the Prerequisites

First, we must install BorgBackup and Rclone on your production VPS. Ensure your system repositories are up to date before installing the packages.

# For Debian/Ubuntu systems
sudo apt update && sudo apt install borgbackup rclone -y

# For CentOS/RHEL/Fedora systems
sudo dnf install borgbackup rclone -y

Step 2: Initializing the Local Borg Repository

Before pushing data to the cloud, Borg initializes a secure local or staged repository. We will encrypt the repository using a strong passphrase to ensure that even if the raw storage is intercepted, your data remains confidential.

# Define the repository path and initialize with encryption
export BORG_PASSPHRASE="YourSuperSecurePassphraseHere"
borg init --encryption=repokey-blake2 /var/backup/borg-repo
Security Note: Store your BORG_PASSPHRASE and the exported repository keys in a secure offline password manager. If you lose these keys, your backup data cannot be recovered under any circumstances.

Step 3: Configuring the Remote Cloud Destination via Rclone

Next, configure Rclone to connect to your preferred object storage provider. Run rclone config and follow the interactive prompt to create a new remote named remote-storage. For maximum security, the API credentials provided to Rclone should only have read and write permissions, explicitly excluding delete permissions at the IAM bucket policy level.

Step 4: Implementing the Append-Only Enforcement Script

The core of our immutable strategy relies on forcing the backup sync process into an append-only state. We create a dedicated automation script that performs the local deduplicated backup first, and then synchronizes the data to the cloud using Rclone's strict restricted flags.

Create a script at /usr/local/bin/secure_backup.sh with the following structural workflow:

#!/bin/bash
# Enforce strict error handling
set -euo pipefail

# Environment Variables
export BORG_PASSPHRASE="YourSuperSecurePassphraseHere"
LOCAL_REPO="/var/backup/borg-repo"
REMOTE_DEST="remote-storage:my-immutable-backup-bucket"
TIMESTAMP=$(date +"%Y-%m-%d_%H-%M-%S")

echo "[${TIMESTAMP}] Starting Borg Backup..."
# Create the deduplicated archive of critical system paths
borg create --stats --progress ${LOCAL_REPO}::"archive-${TIMESTAMP}" /var/www /etc /var/log

echo "[${TIMESTAMP}] Syncing to Cloud with Append-Only Restrictions..."
# Execute Rclone with append-only flags to prevent deletions
rclone sync ${LOCAL_REPO} ${REMOTE_DEST} \
    --append-only \
    --immutable \
    --fast-list \
    --transfers 4

echo "[${TIMESTAMP}] Backup Process Successfully Completed."

Make the script executable and restrict its access permissions so only the root user can read or execute it:

sudo chmod 700 /usr/local/bin/secure_backup.sh
sudo chown root:root /usr/local/bin/secure_backup.sh

Crucial Strategy: Handling Pruning and Retention Policies Safely

A standard backup lifecycle involves "pruning" or deleting old archives to save space. However, because our Rclone architecture enforces strict immutability from the VPS, running a borg prune operation directly from the production server will fail to sync to the cloud, as the VPS is forbidden from deleting remote files.

To manage retention and storage costs safely, you must utilize a Two-Way Decoupled Architecture:

  1. The Production VPS: Operates entirely in a blind, write-only/append-only state. It continuously pushes new backup data but can never destroy historical data.
  2. The Isolated Management Server: A separate, highly secure, offsite server (or local administrative machine) that holds the full-access API credentials to the cloud bucket. This machine connects periodically to run retention policies, prune old archives, and clear storage space. Since this machine is completely isolated from the production VPS, a compromise on the VPS does not affect the retention controller.

Best Practices for Absolute Ransomware Resilience

Implementing the tools is only half the battle. To guarantee absolute resilience against sophisticated cyber extortion campaigns, incorporate the following operational standards:

  • Implement Object Locking: If your cloud provider supports it, enable compliance-mode Object Locking (S3 Object Lock) on your bucket with a legal hold duration (e.g., 30 days). This enforces immutability directly at the storage hardware layer, overriding even compromised root cloud credentials.
  • Automate Monitoring and Alerting: Configure automated cron jobs to execute your backup scripts daily and send immediate notification alerts (via Slack webhooks, Discord, or Email) upon failure.
  • Regularly Test Disaster Recovery: A backup system is only as good as its restore process. Periodically pull down remote archives to an isolated sandbox environment to test data integrity and ensure your recovery time objectives (RTO) are met.

Conclusion

Ransomware is no longer an issue that can be mitigated solely by reactive security measures. By architecting a proactive, immutable backup pipeline utilizing BorgBackup and Rclone Append-Only, you successfully eliminate the single point of failure in your disaster recovery plan. Even under a worst-case scenario where an attacker gains complete administrative sovereignty over your VPS, your historical data remains securely locked in an immutable cloud vault, allowing you to rebuild, restore, and resume operations without ever paying a ransom.

Building an Absolute Ransomware-Proof Immutable Backup System for VPS Using BorgBackup and Rclone Append-Only | DPTCloud