BorgBackup 1.4.5
BorgBackup is a deduplicating backup program with compression and authenticated encryption, designed for efficient daily backups to local or SSH-reachable repositories.
Download TAR.GZ Project website ↗Download Mirrors
BorgBackup deduplicates, compresses, and encrypts backups, and it is very good at all three. The 1.4 series is the current stable line; Borg 2.0 has been in beta for a long time and remains marked as testing only.
Deduplication that actually works
Borg splits data into content-defined chunks and stores each unique chunk once. The practical consequence is that a daily backup of a mostly-unchanged system costs almost nothing in storage, and that identical data across multiple machines backing up to the same repository is stored a single time.
Combined with compression, the ratios on real systems are often dramatic. A repository holding months of daily snapshots of a server frequently occupies less space than a single uncompressed copy.
The commands
# Initialize with encryption
borg init --encryption=repokey /srv/borg
# Create an archive, with compression
borg create --stats --progress \
--compression zstd,3 \
/srv/borg::'{hostname}-{now:%Y-%m-%d}' \
/home /etc
# List archives and contents
borg list /srv/borg
borg list /srv/borg::archive-name
# Extract
cd /tmp && borg extract /srv/borg::archive-name
# Mount an archive as a filesystem
borg mount /srv/borg::archive-name /mnt/borg
# Retention policy, then reclaim space
borg prune -v --list --keep-daily=7 --keep-weekly=4 --keep-monthly=6 /srv/borg
borg compact /srv/borg
Note that prune marks archives for removal but compact is what actually reclaims disk space in recent versions. Forgetting the second command is a common source of “why is my repository not shrinking.”
Remote repositories
Borg over SSH requires Borg installed on the far end, because the remote side runs a Borg process rather than just accepting files.
borg create ssh://backup@server/./repo::archive /home
That requirement is Borg’s main limitation relative to restic, which talks to object storage directly. It is also why Borg can be more efficient: both ends understand the format.
For unattended backups, use an SSH key restricted with command= in authorized_keys and Borg’s --append-only repository mode, so a compromised client cannot delete its own backup history. That combination is what makes Borg genuinely resistant to ransomware scenarios.
The rule that matters
Test your restores, and run borg check periodically. Our automated backups guide covers scheduling.
Verify Your Download
Releases are published with checksums and GPG signatures on GitHub.