Restic: Fast, Encrypted, Deduplicating Backups
Last updated on

Restic: Fast, Encrypted, Deduplicating Backups

Restic is a command-line backup tool that encrypts everything client-side, deduplicates aggressively, and writes to almost any storage backend.

Why it is the common recommendation

Backups fail for boring reasons: the tool is awkward, restores are untested, or the storage is a single disk in the same room. Restic addresses the first two directly. A backup is one command, snapshots are immutable and browsable, and restoring a single file from three months ago does not require restoring everything.

Deduplication is content-based, so daily snapshots of a mostly-unchanged dataset cost very little. Encryption is not optional, which is the correct default when backups go to storage you do not control.

Backends

Local disks, SFTP, S3-compatible object storage including MinIO and Garage, Backblaze B2, Azure, Google Cloud, and anything Rclone can reach, which is effectively everything.

The commands that matter

restic init --repo /srv/backup
restic backup /home/user/documents
restic snapshots
restic restore latest --target /tmp/restore
restic forget --keep-daily 7 --keep-weekly 4 --prune

That last one is the part people skip, and without a retention policy a repository grows forever.

Test your restores

The single most important operational habit: periodically restore something and verify it. restic check validates repository integrity, but only an actual restore proves the backup is useful.

Interfaces

Backrest provides a web UI over Restic with scheduling, which suits people who would rather not maintain cron entries.

Alternatives

Borg is similar in spirit with a different backend model. Duplicati offers a GUI-first approach.

License

Restic is released under the BSD 2-Clause License.