Back to articles
Technology Insight

Building an Encrypted Decentralized Backup Node on a VPS with Garage HQ: Comprehensive Ransomware Protection

May 25, 2026

Introduction: The Growing Threat of Ransomware in Enterprise Infrastructure

In the contemporary digital landscape, data has become the most valuable asset for any enterprise. Consequently, it has also become the primary target for cybercriminals. Ransomware attacks are no longer a matter of 'if,' but 'when.' Modern ransomware strains do not merely encrypt local production systems; they actively seek out, compromise, and delete connected backup systems to eliminate any possibility of recovery without paying the ransom.

Traditional centralized backup strategies—such as relying solely on a single local Network Attached Storage (NAS) or a single public cloud bucket—increasingly represent single points of failure. If an attacker gains administrative access to your infrastructure, a centralized backup repository can be wiped out in seconds. To counter this threat, organizations must adopt a zero-trust, resilient architecture. This guide provides a comprehensive walkthrough on building an Encrypted Decentralized Backup Node on a Virtual Private Server (VPS) utilizing Garage HQ, an open-source, distributed object storage solution specifically designed for self-hosting resilient, multi-site storage clusters.

---

Understanding Garage HQ and Decentralized Storage Architecture

Garage HQ is a lightweight, distributed object storage service that implements the Amazon S3 API. Unlike heavy storage orchestrators designed for massive data centers, Garage is engineered to run efficiently on heterogeneous, low-spec infrastructure, including budget VPS instances spread across different geographic regions and providers.

By deploying Garage across multiple independent VPS nodes, you create a decentralized storage cluster. Data written to this cluster is automatically sliced, encrypted, and replicated across distinct physical locations. This architectural design yields several profound security advantages:

  • Elimination of Single Points of Failure (SPOF): Even if an entire data center goes offline or a specific VPS provider experiences a catastrophic outage, your data remains highly available and retrievable from the remaining nodes.
  • Ransomware Isolation: An attacker compromising your primary production network cannot easily destroy backups stored on an independent, geographically isolated, and decoupled decentralized cluster.
  • Cost Efficiency: Instead of paying premium egress and storage fees to hyperscalers, enterprises can utilize cost-effective VPS providers to build a highly redundant, enterprise-grade storage network.
---

Prerequisites and Architectural Design

Before initiating the deployment, it is crucial to outline the architectural prerequisites required for a robust setup. For a resilient production-grade cluster, the following configuration is highly recommended:

  1. Infrastructure Selection: At least three VPS instances from different providers (e.g., Hetzner, DigitalOcean, Linode) to achieve true decentralization and network split-brain resilience. However, for the scope of this guide, we will focus on configuring a dedicated, highly secure backup node that bridges into an existing or expanding Garage cluster.
  2. Operating System: Clean installations of Linux (Ubuntu 22.04 LTS or Debian 12 recommended) on all nodes.
  3. Network Configuration: Public IPv4/IPv6 addresses with strict firewall rules configured to allow cluster communication only among trusted node IPs.
  4. Encryption Keys: Pre-generated cryptographic keys for transport layer security (TLS) and data-at-rest encryption.
---

Step-by-Step Deployment Guide

Step 1: System Optimization and Security Hardening

First, access your designated backup VPS via SSH and ensure the system is completely updated. We will also implement initial firewall configurations to secure the node.

sudo apt update && sudo apt upgrade -y
sudo apt install ufw curl tailscale -y

Configure the Uncomplicated Firewall (UFW) to block all traffic by default, except for SSH and the explicit ports required by Garage HQ (typically port 3901 for cluster communication and port 3902 for the S3 API endpoint):

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 3901/tcp
sudo ufw allow 3902/tcp
sudo ufw enable
Security Note: For maximum ransomware isolation, avoid exposing port 3901 directly to the public internet. Instead, utilize a secure mesh VPN overlay like Tailscale or WireGuard to route inter-node cluster traffic through an encrypted private tunnel.

Step 2: Installing Garage HQ

Download the latest stable binary of Garage HQ directly from the official repository and move it to your system path:

_arch=$(dpkg --print-architecture)
curl -Lo garage [https://garagehq.deuxfleurs.fr/releases/v0.9.0/$](https://garagehq.deuxfleurs.fr/releases/v0.9.0/$){_arch}/garage
chmod +x garage
sudo mv garage /usr/local/bin/

Verify the installation by checking the version:

garage --version

Step 3: Configuring the Node

Create a dedicated configuration directory and define the configuration file (/etc/garage/garage.toml). This file dictates how the node behaves, where it stores data, and how it communicates with peer nodes.

sudo mkdir -p /etc/garage /var/lib/garage/meta /var/lib/garage/data

Populate /etc/garage/garage.toml with the following structural layout:

metadata_dir = "/var/lib/garage/meta"
data_dir = "/var/lib/garage/data"

bind_public_all = true

[rpc_config]
bind_rpc = "[::]:3901"
secret_key = "YOUR_GENERATED_CLUSTER_RPC_SECRET"

[s3_api]
bind_s3 = "[::]:3902"
api_region = "us-east-1"

Ensure that the secret_key matches precisely across all nodes within your decentralized network to permit cluster joining and authentication.

Step 4: Initializing the Cluster and Applying Layouts

Once the service is running across your nodes, you must instruct the cluster to arrange its layout. Execute the following commands on your primary node to check node status and assign geographical zones:

garage status
garage node index
garage layout assign  --zone vps-provider-1 --capacity 100
garage layout apply --version 1

This step establishes your data replication boundaries, ensuring that copies of your backup data are systematically written across distinct physical nodes rather than localized on a single machine.

---

Implementing Zero-Trust Client Encryption

A decentralized cluster provides physical resilience, but confidentiality requires end-to-end encryption (E2EE). To achieve absolute immunity against data breaches and ransomware inspection, data must be encrypted *before* it leaves your production infrastructure.

By utilizing backup tools like Restic or Kopia configured with your Garage S3 endpoint, data is automatically encrypted locally using AES-256 or ChaCha20-Poly1305. The backup node acts strictly as a zero-knowledge repository. Even if an attacker compromises the VPS root environment, they only gain access to encrypted chunks of data without the cryptographic keys necessary to read or alter the payload.

---

Achieving Immutability: The Ultimate Defense Against Ransomware

The definitive strategy to defeat ransomware is Object Locking (WORM - Write Once, Read Many). Garage HQ supports S3 Object Locking, allowing you to enforce data immutability policies on your backup buckets.

When immutability is enabled, files written to the backup node cannot be deleted, overwritten, or modified by any user—including the root administrator account—for a predetermined retention period (e.g., 30 days). If ransomware infects your primary system and attempts to issue a command to wipe your remote backups, the decentralized Garage cluster will explicitly reject the deletion request based on the immutable policy enforced at the API layer.

---

Conclusion and Continuous Monitoring

By shifting away from fragile centralized storage methodologies and deploying an encrypted, decentralized backup node with Garage HQ, you erect an incredibly resilient barrier against sophisticated ransomware schemes. Your data is geographically distributed, zero-knowledge encrypted, and cryptographically protected against premature deletion.

To maintain enterprise-grade compliance and reliability, ensure that you set up automated monitoring alerts for cluster health, disk utilization, and replication delays. Regularly test your restoration workflows to guarantee that when disaster strikes, your decentralized recovery path is seamless, verified, and rapidly operational.

Building an Encrypted Decentralized Backup Node on a VPS with Garage HQ: Comprehensive Ransomware Protection | DPTCloud