Back to articles
Technology Insight

Securing Docker VPS Against Ransomware: A Guide to Append-Only Immutable Backups with Kopia

May 30, 2026

The Escalating Threat: Ransomware in Dockerized Environments

As modern enterprises increasingly rely on containerized infrastructure, Virtual Private Servers (VPS) running Docker have become prime targets for cybercriminals. Ransomware tactics have evolved beyond simple data encryption; attackers now actively seek out, compromise, and delete backup files before executing their payload. In a standard Docker setup, if an attacker gains root access to the host or the Docker socket, every mounted volume and connected network share is at risk.

Traditional backup strategies that rely on simple replication or network file shares (like NFS or SMB) are no longer sufficient. If the live server has write and delete permissions on the backup repository, so does the attacker. To mitigate this catastrophic risk, enterprises must adopt a zero-trust backup strategy: Append-Only Immutable Backup Architecture. This guide explores how to implement this architecture effectively using Kopia, an open-source fast and secure backup engine.

Understanding the 'Append-Only Immutable' Architecture

The core philosophy of an append-only immutable backup is simple yet powerful: data can be written and read, but it can never be modified or deleted by the source server. Even if a malicious actor gains total control of your Docker VPS, they cannot destroy historical backup snapshots.

How It Works

In a standard backup model, the client server connects to a storage destination with full read-write-delete privileges to prune old backups and save space. In contrast, an append-only architecture splits these responsibilities:

  • The Client (Docker VPS): Granted "append-only" or "write-once" permissions. It can upload new data chunks but lacks the authorization to overwrite or delete existing blocks.
  • The Repository/Server Gateway: A separate, isolated environment (or a specialized cloud object storage bucket with Object Lock enabled) that enforces retention policies. Only this isolated layer can prune expired backups.
Key Benefit: If ransomware infects the Docker host, encrypts the local database volumes, and attempts to purge the backups, the cloud storage provider or backup gateway will reject the deletion requests, preserving your recovery points intact.

Why Choose Kopia for Docker VPS Security?

Kopia has emerged as an industry-favorite tool for secure backups due to its unique architectural advantages:

  1. Content-Addressable Deduplication: Kopia breaks data into chunks and deduplicates them securely before upload, minimizing storage costs and bandwidth.
  2. Client-Side Encryption: All data is encrypted end-to-end using robust algorithms (such as AES-256 or ChaCha20) before leaving your VPS. The cloud provider never sees your raw data.
  3. Flexible Repository Models: Kopia natively supports cloud object storage with immutability (like AWS S3 Object Lock, Backblaze B2, or Wasabi) and features a dedicated kopia server mode to establish a secure, isolated gateway.

Step-by-Step Implementation Guide

Let us walk through setting up a secure, immutable backup pipeline for a production Docker VPS hosting critical services like databases and web applications.

Step 1: Preparing Docker Volumes for Backup

To back up stateful applications reliably, you must identify where your Docker volumes are stored. Instead of backing up the raw /var/lib/docker/volumes directory directly (which can lead to file corruption), it is best practice to pause database writes or use a sidecar container pattern to stream data cleanly.

For example, if you run a PostgreSQL container alongside your application, your backup script should trigger a native dump into a dedicated maintenance volume before Kopia initializes its snapshot sequence.

Step 2: Configuring the Immutable Cloud Repository

For true append-only behavior using cloud object storage (e.g., AWS S3 or Backblaze B2), you must enable Object Lock during bucket creation. Configure the bucket with the following specifications:

  • Compliance Mode: This ensures that no one—including the root account—can delete the files during the retention period.
  • Retention Period: Set a reasonable window based on your business compliance requirements (e.g., 30 days).

Next, generate an IAM policy for your Docker VPS that explicitly allows PutObject and GetObject, but strictly denies DeleteObject and DeleteObjectVersion.

Step 3: Deploying Kopia via Docker Compose

To seamlessly integrate Kopia into your Docker ecosystem, deploy it as an isolated service. Below is a secure docker-compose.yml snippet configured to run the Kopia client container:

version: '3.8'
services:
  kopia:
    image: kopia/kopia:latest
    container_name: kopia_backup
    environment:
      - KOPIA_PASSWORD=your_secure_master_passphrase
    volumes:
      - /var/lib/docker/volumes:/data:ro
      - /etc/kopia:/app/config
      - /var/cache/kopia:/app/cache
    restart: unless-stopped
    command: repository connect s3 --bucket=my-immutable-backup-bucket --endpoint=s3.amazonaws.com

Notice that the host data volume is mounted as read-only (ro). This enforces a secondary layer of security inside your system architecture, preventing the backup tool itself from modifying live application data.

Step 4: Executing Scheduled Snapshots

With the repository connected, automate your snapshots using a cron job or an orchestrator. A typical execution command within the container looks like this:

kopia snapshot create /data

Kopia will scan the volume, deduplicate changes against previous snapshots, encrypt the new chunks locally, and push them securely to your immutable bucket.

Handling Maintenance and Retention Safely

Because the client VPS does not possess deletion capabilities, it cannot execute the standard kopia maintenance routine to prune old snapshots. Attempting to do so from the VPS will result in an access denied error from your storage provider.

To safely manage storage growth, you must set up an isolated **Maintenance Worker**. This can be an internal management server or a completely separate, highly secure VPS that has exclusive Delete rights to the storage bucket. This worker runs a automated task weekly to purge expired data chunks that have outlived the bucket's Object Lock retention matrix.

Conclusion and Strategic Takeaways

Ransomware resilience is not achieved by simply having a backup; it is achieved by ensuring that your backups are structurally indestructible from the perspective of an compromised server. By combining the speed and encryption capabilities of Kopia with an Append-Only Immutable Backup architecture, you effectively neutralize the threat of ransom demands targeting your infrastructure. Even in a worst-case scenario where your Docker VPS is completely compromised, recovery is merely a matter of provisioning a clean instance and pulling down your uncorrupted, authenticated snapshots.

Securing Docker VPS Against Ransomware: A Guide to Append-Only Immutable Backups with Kopia | DPTCloud