Backup VPS Otomatis dengan restic
Cara menjadwalkan backup VPS terenkripsi dengan restic ke S3-compatible, Backblaze B2, atau server lain: inisialisasi repositori, cron, retensi, dan uji restore.
4 Oktober 2026 · 7 menit baca · Tim VPS Indonesia
Kami belum menyediakan backup otomatis, dan backup yang disimpan di server yang sama bukan backup. Panduan ini memakai restic — gratis, terenkripsi, dedup — untuk mengirim salinan ke penyimpanan terpisah.
1. Pilih tujuan backup
- S3-compatible (object storage mana pun), Backblaze B2, Wasabi, atau Cloudflare R2.
- Server lain via SFTP — misalnya VPS Nano kedua sebagai penampung.
- rclone remote (Google Drive, dll.) — restic mendukung backend rclone.
2. Instal restic
apt install -y restic # Debian/Ubuntu
restic self-update # ambil versi terbaru
3. Inisialisasi repositori (contoh S3)
Buat /root/.restic.env:
export AWS_ACCESS_KEY_ID=...
export AWS_SECRET_ACCESS_KEY=...
export RESTIC_REPOSITORY=s3:https://ENDPOINT/NAMA-BUCKET/vps-utama
export RESTIC_PASSWORD=PASSWORD_ENKRIPSI_PANJANG
chmod 600 /root/.restic.env
source /root/.restic.env
restic init
Simpan RESTIC_PASSWORD di tempat aman — tanpa itu backup tidak bisa dibuka.
4. Skrip backup
/usr/local/bin/backup.sh:
#!/usr/bin/env bash
set -euo pipefail
source /root/.restic.env
# dump database sebelum backup file (sesuaikan)
mkdir -p /var/backups/db
docker compose -f /home/deploy/apps/n8n/compose.yml exec -T postgres \
pg_dump -U n8n n8n | gzip > /var/backups/db/n8n.sql.gz || true
# mysqldump --all-databases | gzip > /var/backups/db/mysql.sql.gz
restic backup /etc /home /var/www /var/backups/db /root/.restic.env \
--exclude-caches --exclude '*/node_modules' --exclude '*/.cache' \
--tag harian
restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --prune
restic check --read-data-subset=5%
chmod +x /usr/local/bin/backup.sh
/usr/local/bin/backup.sh # uji manual
5. Jadwalkan dengan systemd timer
/etc/systemd/system/backup.service:
[Unit]
Description=Backup restic
[Service]
Type=oneshot
ExecStart=/usr/local/bin/backup.sh
/etc/systemd/system/backup.timer:
[Unit]
Description=Backup harian 02.30 WIB
[Timer]
OnCalendar=*-*-* 02:30:00
Persistent=true
[Install]
WantedBy=timers.target
systemctl daemon-reload && systemctl enable --now backup.timer
systemctl list-timers | grep backup
6. Uji restore (wajib, minimal sebulan sekali)
source /root/.restic.env
restic snapshots
restic restore latest --target /tmp/restore --include /var/www
ls /tmp/restore/var/www
Backup yang belum pernah di-restore belum terbukti bekerja.
7. Notifikasi gagal
Tambahkan di akhir backup.sh pemanggilan webhook Telegram/n8n bila perintah gagal (trap 'curl ...' ERR). Dengan n8n self-host, kamu bisa menerima laporan harian di WhatsApp.
Catatan untuk database besar
Untuk PostgreSQL/MySQL puluhan GB di paket Pro ke atas, gunakan pg_basebackup/WAL archiving atau mariabackup daripada dump logis agar restore lebih cepat.