restic 0.19.1
restic is a fast, secure backup program with deduplication and authenticated encryption by default, supporting local disks, SFTP, S3, Backblaze B2, and many other backends.
Download BZ2 Project website ↗Download Mirrors
restic is a backup program that gets the defaults right: everything is encrypted, everything is deduplicated, and the repository format is verifiable.
What makes it a good default
Encryption is not optional. Every repository is encrypted with authenticated encryption, which means an untrusted backup destination is fine. You can back up to a cheap object store without trusting the operator.
Deduplication is content-defined. restic splits files into variable-length chunks based on content, so a large file that changed slightly stores only the new chunks. Moving a file costs nothing. Duplicate data across different machines backing up to the same repository is stored once.
Snapshots are cheap and complete. Every backup is a full snapshot conceptually, with incremental storage underneath.
A single static binary. No daemon, no database, no runtime dependencies.
The commands
# Initialize a repository
restic init --repo /srv/backups
# Back up
restic -r /srv/backups backup /home/user /etc
# List snapshots
restic -r /srv/backups snapshots
# Restore
restic -r /srv/backups restore latest --target /tmp/restore
# Browse a backup as a filesystem
restic -r /srv/backups mount /mnt/backup
# Prune old snapshots by policy
restic -r /srv/backups forget --keep-daily 7 --keep-weekly 4 --keep-monthly 12 --prune
# Verify integrity
restic -r /srv/backups check --read-data-subset 5%
The mount command is genuinely useful. It exposes every snapshot as a FUSE filesystem, so recovering one file means browsing to it rather than running a restore.
restic or Borg
Both are excellent and the choice usually comes down to backends. restic speaks S3, B2, Azure, Google Cloud Storage, SFTP, and more natively. Borg requires the repository to be on a filesystem or reachable over SSH with Borg installed at the far end.
If you are backing up to object storage, restic is the straightforward answer. If you are backing up to a server you control, either works and Borg’s compression is often better.
The rule that matters
Test your restores. A backup you have never restored from is a hypothesis, not a backup. restic check --read-data actually reads and verifies the data rather than just the metadata.
Our automated backups guide covers scheduling this properly with systemd timers.
Verify Your Download
Release binaries are published with SHA-256 checksums and GPG signatures on GitHub.