Hardware can be replaced in hours. Data can't be replaced at all. The 3-2-1 rule is the industry-standard answer: 3 copies of your data, on 2 different media, with 1 copy off-site. Here's how to implement it on any Linux server in 20 minutes using restic — free, encrypted and deduplicating.
Server snapshots are great for quick rollbacks, but they live on the same platform as the server. A deleted account, ransomware with root access, or fat-fingered rm -rf at the wrong layer can take both. Off-site backups are your independent safety net.
apt install restic -y
Any SFTP-capable target works — for example a NetVO Atlas storage server or a second cloud instance in a different region (Germany → Finland gives you true geographic separation):
restic -r sftp:[email protected]:/backups/app01 init
Store the repository password in /root/.restic-pw (chmod 600) — without it, backups are unreadable. Keep a copy of this password OUTSIDE the server.
restic -r sftp:[email protected]:/backups/app01 \
--password-file /root/.restic-pw \
backup /etc /var/www /home --exclude /var/www/**/cache
Databases need a dump first — never back up live datafiles:
mysqldump --all-databases --single-transaction | gzip > /var/backups/mysql.sql.gz
0 3 * * * /usr/local/bin/backup.sh >> /var/log/backup.log 2>&1
Your script: dump databases → restic backup → restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --prune.
restic -r ... snapshots
restic -r ... restore latest --target /tmp/restore-test --include /etc/nginx
An untested backup is a hope, not a backup. Put a monthly restore test in your calendar.