Off-site backups: sending a copy to cloud storage, an S3 bucket or Google Drive

An off-site copy is the one that survives losing the account. There are five ways to get one out: a WordPress backup plugin with a cloud destination, a backup program running on your computer or a VPS (rclone is the best known), the remote-destination option of the full cPanel backup where it exists, a script with rsync or SFTP, or simply downloading and uploading by hand. This is the mechanics; prices and conditions are those of the storage provider you choose.

Where to send it

Destination What it is What you need to know
S3-compatible object storage A “bucket” in a provider’s account, used by programs. Four details: the service address (endpoint), the region, the access key and the secret key, plus the bucket name.
Google Drive and similar file services A folder in a personal or company account. Authorisation is done by a one-time sign-in that gives the program renewable access. See saving files to Google Drive automatically.
Another server, over SFTP A disk of yours, on another machine. The address, the user and an SSH key. See automatic file transfers with SFTP and rsync.
An external disk or the computer The local copy, not truly “off-site” if it is in the same room. A disk kept at another address counts as off-site.

Step by step

1 Choose the destination and create the account or bucket. If the provider allows it, turn on keeping old versions: it protects you from a damaged copy overwriting the good one.
2 Create a key just for this. Give it permission only on that bucket or folder, and never use the account’s main key.
3 Test with a small file before automating. See that it arrived, that it opens and that the size matches.
4 Automate. With a plugin, it is the plugin’s own “destination” option. With rclone, a command scheduled in cron (cron jobs). Pick a quiet hour.
5 Check every week, for the first few weeks, that the day’s file shows up at the destination. It is the commonest silent failure.
6 Add an alert in case the copy fails, so you do not find out only when you need it. See getting an alert when something fails.

An example with rclone

rclone is a free, open-source third-party program; we do not sell it and support does not install or repair it (how far our support goes). It runs on your computer or on a VPS. First you set the destination up interactively, then you copy:rclone config
rclone copy /path/to/backups remote:bucket-name/site --dry-run
rclone copy /path/to/backups remote:bucket-name/site --progress

The first line creates a destination under a name you choose (here, “remote”). The second, with --dry-run, only shows what it would do. The third copies. To read the backups from your shared account, rclone connects over SFTP; use the SSH address and port your panel shows.

“Copy” and “sync” are not the same. rclone copy adds to the destination. rclone sync makes the destination match the source, deleting there whatever no longer exists here. If you delete a file by mistake and sync, it is deleted from the copy too. For backups, use copy.
Access keys are worth money and data. Keep them in a file with permission 600, outside public_html, and never in a public repository. If one gets exposed, delete it at the provider and create another.
Think about where the data sits. If the copy holds customers’ personal data, the storage provider’s country is a privacy decision, not just a price one. See data protection on your website.

Have the destination but the copy does not arrive, or not sure where to start? Tell us what you use.

Open a support ticket

SEE ALSO

The 3-2-1 backup rule for a website

Copying files to another server with rsync, safely

Saving files to Google Drive automatically

Automatic backups of your own application: cron and mysqldump

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?