Back to articles
Technology Insight

Immutable Backups: Shielding Your VPS Against Ransomware with Restic and Cloudflare R2

May 27, 2026

The Escalating Threat of Ransomware on Virtual Private Servers

In the modern digital economy, data is the most valuable asset a business possesses. Concurrently, it is also the most targeted. Ransomware attacks have evolved from simple malware infections into sophisticated, highly targeted operations. Today, cybercriminals do not just encrypt your live production data; they actively hunt for and destroy your connected backups to eliminate your leverage and force a ransom payment.

For businesses operating on Virtual Private Servers (VPS), this represents a critical vulnerability. Standard cron-job backups synced to an attached volume or a standard network share are no longer sufficient. If your VPS is compromised, the attacker inherits your backup credentials, leading to total data erasure. To achieve absolute resilience, organizations must adopt an architecture that guarantees data cannot be modified or deleted by anyone—not even an administrator with compromised keys. This is the core principle of Immutable Backups.

Understanding Immutability: The WORM Paradigm

An immutable backup is data that cannot be deleted, modified, or overwritten for a user-defined retention period. Even if a ransomware strain gains root access to your VPS and executes a malicious wipe command, the historical backup blocks remain completely untouched.

This is achieved using the Write Once, Read Many (WORM) model, combined with Object Lock technology. In this architectural blueprint, we leverage two industry-leading open-source and cloud technologies to implement this defense:

  • Restic: A fast, secure, and efficient backup program that utilizes data deduplication, client-side encryption, and native support for various cloud backends.
  • Cloudflare R2: An Amazon S3-compatible object storage service that features zero egress fees and robust Object Lock capabilities, ensuring predictable costs and immutable data security.

Prerequisites and Architectural Design

Before proceeding with the implementation, ensure your environment meets the following baseline requirements:

  1. A VPS running a modern Linux distribution (e.g., Ubuntu 22.04 LTS or Debian 12) with root or sudo access.
  2. A Cloudflare account with R2 storage enabled.
  3. A dedicated dataset or directories on your VPS containing critical business data requiring protection.

Security Principle: The foundation of this setup relies on strict separation of privileges. The API keys configured on your VPS will have write permissions but will be structurally restricted from bypassing the retention locks placed on the cloud storage side.

Step 1: Setting Up Cloudflare R2 with Object Lock

The first critical layer of defense is provisioning the storage bucket with native immutability enforcement. Log in to your Cloudflare dashboard and follow these steps:

Creating the Bucket

Navigate to R2 > Overview and click on Create Bucket. Name your bucket uniquely (e.g., enterprise-immutable-backup). Before finalizing, ensure you enable the Object Lock feature. Note that Object Lock must be enabled during bucket creation and cannot be applied to existing standard buckets.

Configuring the Retention Policy

Once the bucket is created, navigate to its settings tab to configure the default retention guidelines. Set the mode to Compliance Mode rather than Governance Mode. In Compliance Mode, the retention period cannot be shortened, and the lock cannot be bypassed by any user, including the root cloud account. Set your retention period according to your business SLA (e.g., 14 days or 30 days).

Generating API Credentials

Navigate back to the R2 overview page and click Manage R2 API Tokens. Create a new token with Read/Write permissions scoped specifically to your newly created backup bucket. Safeguard the generated Access Key ID, Secret Access Key, and the Jurisdiction-specific Endpoint URL. You will require these variables on your VPS.

Step 2: Installing and Initializing Restic on the VPS

With our immutable cloud destination prepared, we must now configure the client-side backup engine on the VPS. Connect to your server via SSH and execute the installation process.

Installation

On Debian/Ubuntu systems, install Restic utilizing the native package manager:

sudo apt update && sudo apt install restic -y

To ensure optimal performance and security compliance, verify that you are running the latest stable version by running restic version.

Environment Configuration

To prevent sensitive credentials from leaking into process logs, we encapsulate our configuration within a secure environment file. Create a file named /root/.restic.env and restrict its permissions:

sudo touch /root/.restic.env && sudo chmod 600 /root/.restic.env

Open the file and populate it with your specific infrastructure details:

AWS_ACCESS_KEY_ID="your_cloudflare_r2_access_key"
AWS_SECRET_ACCESS_KEY="your_cloudflare_r2_secret_key"
RESTIC_REPOSITORY="s3:https://[.r2.cloudflarestorage.com/enterprise-immutable-backup](https://.r2.cloudflarestorage.com/enterprise-immutable-backup)"
RESTIC_PASSWORD="a_very_strong_random_encryption_password"

Note: Restic utilizes S3-compatible APIs natively, which is why the variable names are prefixed with AWS. The RESTIC_PASSWORD handles client-side encryption; if lost, your cloud data is permanently unrecoverable.

Repository Initialization

Load the environment variables and initialize the secure cryptographic repository:

source /root/.restic.env
restic init

Step 3: Automating the Immutable Backup Execution

To achieve seamless continuity, the backup execution must be fully automated using system cron jobs, handled via an orchestration shell script.

Creating the Backup Script

Create a production-ready deployment script at /usr/local/bin/run_backup.sh:

#!/bin/bash
set -e

# Load Environment Variables
source /root/.restic.env

# Define Backup Targets
TARGET_PATHS="/var/www /etc /var/backups/mysql"

# Execute Restic Backup
echo "Starting cryptographic snapshot..."
restic backup $TARGET_PATHS --exclude-caches --one-file-system

# Apply Pruning with Cloud Compliance Safeguards
echo "Optimizing remote repository via prune..."
restic forget --keep-daily 14 --prune

echo "Backup routine completed successfully."

Make the script executable: sudo chmod +x /usr/local/bin/run_backup.sh.

Understanding the Interplay Between Pruning and Object Lock

When restic forget --prune runs, it attempts to delete older snapshots that exceed your specified retention criteria (e.g., older than 14 days). Here is where the absolute protection occurs: if a ransomware actor compromises your script and attempts to force-delete all snapshots immediately, Cloudflare R2 will reject the deletion requests for any blocks still within their immutable compliance window. Your historical backups remain protected against rogue deletion commands.

Step 4: Scheduling and Disaster Recovery Testing

To schedule your backups to run automatically every night at 2:00 AM, open the system crontab file using sudo crontab -e and append the following configuration line:

0 2 * * * /usr/local/bin/run_backup.sh >> /var/log/restic_backup.log 2>&1

Disaster Recovery Verification

A backup protocol is only as reliable as its recovery verification. To simulate a catastrophic bare-metal recovery scenario, you can check available snapshots and perform a trial restore using these commands:

source /root/.restic.env
restic snapshots
restic restore latest --target /tmp/restore-test

Conclusion: Ultimate Peace of Mind

By marrying the client-side deduplication and zero-trust encryption architecture of Restic with the zero-egress cost, compliance-grade immutability features of Cloudflare R2, you establish a gold-standard disaster recovery pipeline. Even under a worst-case scenario where an adversary achieves total control over your VPS host, your business operations can be fully reconstituted using untouchable, untamperable cloud snapshots. Implement this architecture today to transition your operational security posture from reactive vulnerability to absolute ransomware resilience.

Immutable Backups: Shielding Your VPS Against Ransomware with Restic and Cloudflare R2 | DPTCloud