Restic: Fast, Encrypted, Deduplicating Backups
Restic is a command-line backup tool that encrypts everything client-side, deduplicates aggressively, and writes to almost any storage backend.
Why it is the common recommendation
Backups fail for boring reasons: the tool is awkward, restores are untested, or the storage is a single disk in the same room. Restic addresses the first two directly. A backup is one command, snapshots are immutable and browsable, and restoring a single file from three months ago does not require restoring everything.
Deduplication is content-based, so daily snapshots of a mostly-unchanged dataset cost very little. Encryption is not optional, which is the correct default when backups go to storage you do not control.
Backends
Local disks, SFTP, S3-compatible object storage including MinIO and Garage, Backblaze B2, Azure, Google Cloud, and anything Rclone can reach, which is effectively everything.
The commands that matter
restic init --repo /srv/backup
restic backup /home/user/documents
restic snapshots
restic restore latest --target /tmp/restore
restic forget --keep-daily 7 --keep-weekly 4 --prune
That last one is the part people skip, and without a retention policy a repository grows forever.
Test your restores
The single most important operational habit: periodically restore something and verify it. restic check validates repository integrity, but only an actual restore proves the backup is useful.
Interfaces
Backrest provides a web UI over Restic with scheduling, which suits people who would rather not maintain cron entries.
Alternatives
Borg is similar in spirit with a different backend model. Duplicati offers a GUI-first approach.
License
Restic is released under the BSD 2-Clause License.