Back to articles
Technology Insight

Securing Your Infrastructure: Building an End-to-End Encrypted VPS Backup System with Kopia and Backblaze B2

June 3, 2026

Introduction: The Imperative of Zero-Trust Data Protection

In the modern digital economy, data is the most valuable asset an enterprise possesses. For businesses operating Virtual Private Servers (VPS) to host critical applications, databases, or client management systems, data availability and integrity are paramount. However, infrastructure is constantly under threat from sophisticated ransomware attacks, accidental deletions, hardware failures, and unauthorized third-party access.

Traditional backup methods often fall short in security, either by storing data unencrypted on the target server or relying on transport-only encryption (SSL/TLS). If the storage provider suffers a breach, your sensitive enterprise data becomes compromised. To mitigate this risk, modern infrastructure engineering demands a Zero-Trust architecture. Implementing an End-to-End Encrypted (E2EE) backup strategy ensures that data is encrypted on your local VPS before it ever traverses the network, meaning no one—not even your cloud storage provider—can read your files without your master encryption key.

This article provides a comprehensive, production-ready guide to building an enterprise-grade, automated, and cost-effective E2EE backup pipeline using Kopia, an advanced open-source backup engine, and Backblaze B2, a highly reliable and secure object storage platform.

Why Kopia and Backblaze B2? A Strategic Assessment

Selecting the right components for an enterprise backup stack requires evaluating security, performance, scalability, and cost. The combination of Kopia and Backblaze B2 represents an optimal synergy for modern DevOps and system administration teams.

Kopia: Next-Generation Backup Management

Kopia stands out among open-source backup utilities due to its architecture, speed, and safety features. Unlike legacy tools, Kopia is built from the ground up with security and modern storage abstractions in mind:

  • Client-Side Encryption: Kopia forces end-to-end encryption by design. Data is split into content-addressable blocks, compressed, and encrypted locally using state-of-the-art cryptographic algorithms (such as AES-256-GCM or ChaCha20-Poly1305) before being transmitted.
  • Content-Defined Deduplication: To optimize storage costs and network bandwidth, Kopia identifies duplicate data segments across multiple backups and uploads only unique blocks.
  • Data Compression: Built-in support for algorithms like Zstandard (zstd) significantly reduces the physical storage footprint.
  • Atomic Commits and Integrity Checks: Kopia structures its repositories to prevent data corruption during network dropouts, and features built-in verification mechanisms to guarantee backup health.

Backblaze B2: Enterprise Object Storage at Scale

Backblaze B2 provides S3-compatible cloud object storage with a 99.9% uptime SLA and 11 nines of data durability. From a financial perspective, it costs a fraction of traditional hyperscalers like AWS S3 or Google Cloud Storage, making it highly attractive for scaling businesses looking to control operational expenditures without sacrificing reliability.

Architectural Overview of the E2EE Backup Pipeline

Before proceeding to the technical execution, it is critical to understand how data flows through this secure infrastructure:

  1. Data Selection: The Kopia agent on the VPS identifies the target source directories (e.g., database dumps, web roots, configuration files).
  2. Deduplication and Compression: Data chunks are compressed and matched against existing blocks to avoid redundancy.
  3. Local Cryptographic Envelope: Chunks are encrypted using a master key derived from a secure repository password.
  4. Secure Ingress: The encrypted, non-descript data blocks are pushed via HTTPS to an isolated Backblaze B2 bucket.
Security Note: Under this model, Backblaze only hosts encrypted binary blobs. They do not possess the metadata, file names, directory structures, or keys required to decrypt your data. Your data remains completely opaque to external entities.

Step-by-Step Implementation Guide

Step 1: Provisioning Backblaze B2 Storage

To begin, log into your Backblaze account and configure your remote storage destination:

  1. Navigate to Buckets and click Create a Bucket.
  2. Assign a unique bucket name (e.g., enterprise-vps-backup-prod).
  3. Keep the bucket settings as Private. Do not enable default server-side encryption if you prefer solely relying on client-side Kopia management, though keeping it enabled adds a layer of defense-in-depth.
  4. Go to the App Keys section and generate a new Application Key. Ensure you restrict its permissions exclusively to the newly created bucket to adhere to the principle of least privilege. Save the keyID and applicationKey safely.

Step 2: Installing Kopia on the VPS

Connect to your Linux VPS via SSH. Kopia provides pre-compiled binaries for major distributions. For Ubuntu/Debian systems, install Kopia via the official repository:

sudo apt-get update
sudo apt-get install -y apt-transport-https ca-certificates curl gnupg
curl -s [https://kopia.io/signing-key](https://kopia.io/signing-key) | sudo gpg --dearmor -o /usr/share/keyrings/kopia-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/kopia-keyring.gpg] [https://kopia.io/repo/apt/](https://kopia.io/repo/apt/) stable main" | sudo tee /etc/apt/sources.list.d/kopia.list
sudo apt-get update
sudo apt-get install kopia

Verify the installation by running kopia --version.

Step 3: Initializing the End-to-End Encrypted Repository

With Kopia installed, you must now initialize the remote repository on Backblaze B2. Choose a robust, complex password. If this password is lost, your backups are permanently unrecoverable.

Execute the following initialization command, replacing the placeholders with your actual Backblaze credentials:

export KOPIA_PASSWORD="your_ultra_secure_master_password"
kopia repository create b2 \
  --bucket="enterprise-vps-backup-prod" \
  --key-id="your_backblaze_key_id" \
  --key="your_backblaze_application_key"

During this phase, Kopia establishes the cryptographic parameters, sets up the block index structures, and saves the connection profile locally on your VPS.

Step 4: Automating Backup Snapshots via Cron

To ensure continuous data protection, backup execution must be fully automated. First, create a secure shell script located at /usr/local/bin/run-vps-backup.sh:

#!/bin/bash
set -e

# Set environment variables securely
export KOPIA_PASSWORD="your_ultra_secure_master_password"

# Connect to the repository if disconnected
kopia repository connect b2 \
  --bucket="enterprise-vps-backup-prod" \
  --key-id="your_backblaze_key_id" \
  --key="your_backblaze_application_key"

# Execute snapshots for critical paths
kopia snapshot create /var/www/html
kopia snapshot create /etc/nginx

# Disconnect for security baseline cleanliness
kopia repository disconnect

Make the script executable and restrict permissions so only the root user can access it:

sudo chmod 700 /usr/local/bin/run-vps-backup.sh
sudo chown root:root /usr/local/bin/run-vps-backup.sh

Finally, register the script in the system crontab to run daily at 2:00 AM:

0 2 * * * /usr/local/bin/run-vps-backup.sh > /var/log/kopia-backup.log 2>&1

Retention Policies and Lifecycle Management

Unchecked backup accumulation leads to bloating storage costs. Kopia manages retention profiles gracefully via policies. You can set a global policy to maintain a rolling window of snapshots, automatically purging older blocks that are no longer referenced by active snapshots:

kopia policy set --global --keep-hourly 0 --keep-daily 7 --keep-weekly 4 --keep-monthly 12

This policy configuration ensures you always maintain a historical arc of 7 daily snapshots, 4 weekly snapshots, and 12 monthly snapshots, completely optimizing your storage capacity on Backblaze B2.

Disaster Recovery and Verification Testing

A backup system is only as reliable as its restore capability. System administrators must conduct routine disaster recovery tests. To list available snapshots, run:

kopia snapshot list

To recover a directory to an alternate recovery path during an emergency, execute:

kopia snapshot restore  /tmp/recovery-destination

Conclusion: Resilient Infrastructure with Zero Compromise

Building an end-to-end encrypted backup pipeline using Kopia and Backblaze B2 equips your business with a robust, cloud-native recovery framework. By encrypting data at rest on the client side, leveraging deduplication to control bandwidth, and anchoring storage costs within an affordable ecosystem like Backblaze B2, you establish an ironclad layer of operational resilience. Implement these steps today to guarantee your enterprise assets remain secure, confidential, and instantly restorable against any digital adversity.