Guideschevron_rightStorage

Storage · 8 min read · Updated

How to Back Up TrueNAS to S3-Compatible Object Storage

On TrueNAS, an off-site backup to S3-compatible object storage is a Cloud Sync task. First add the bucket as a cloud credential, using the Amazon S3 provider with your provider's Endpoint URL and Region. Then create a task that pushes a dataset every night, with Remote Encryption and Take Snapshot turned on. Do a dry run first, then test a restore. Cloud Sync keeps one copy of each file, not a history; for versions, TrueNAS can also run a versioned backup task from the shell (step 6). We tested every step on TrueNAS 25.10.

1. Create a Bucket and an Access Key

In the Virteche dashboard, open your object storage, create a bucket (for example nas-backup), and copy the access key ID and secret access key into a password manager. The secret is shown once.

2. Add the Bucket as a Cloud Credential

Go to Credentials → Backup Credentials → Cloud Credentials and press Add. Choose the Amazon S3 provider; it works with any S3-compatible service once you set the endpoint:

Provider:            Amazon S3
Access Key ID:       your access key ID
Secret Access Key:   your secret access key
Endpoint URL:        https://s3.us-west.virteche.com
Region:              us-west

Leave Disable Endpoint Region off, and the other options as they are. Press Verify Credential: it should come back valid before you save. If it fails, check that the endpoint starts with https:// and that the region is exactly us-west.

3. Create the Cloud Sync Task

Go to Data Protection → Cloud Sync Tasks and press Add to open the Cloud Sync Task Wizard. Choose the credential, then:

  • Direction: Push, from TrueNAS to the bucket.
  • Directory/Files: the dataset to back up, for example /mnt/tank/documents.
  • Bucket and Folder: your bucket, and a folder per dataset, such as documents.
  • Transfer Mode: see below.
Transfer ModeWhat it does
SyncMakes the bucket match the dataset, deleting remote files you deleted. The bucket stays the same size as the data.
CopyUploads new and changed files and never deletes anything remote. Deleted files stay in the bucket until you remove them.
MoveUploads, then deletes the files from TrueNAS. For archiving, not for backups.

Copy is the safer choice for a backup: something deleted on the NAS by mistake is still in the bucket. Choose Sync when you want the bucket to stay the size of the data and you keep ZFS snapshots on the NAS for history.

4. Turn On Encryption and Snapshots

  • Remote Encryption: TrueNAS encrypts files before uploading. Set a long Encryption Password and Encryption Salt, and keep both off the NAS: a restore needs exactly the same two values.
  • Filename Encryption: TrueNAS marks it “not recommended”. Leave it off unless the file and folder names themselves are sensitive. We tested both ways.
  • Take Snapshot: the task uploads from a ZFS snapshot taken at the start, so files that change during a long upload are still copied consistently.
  • Schedule: daily, at a quiet hour such as 2:00.

5. Dry Run, First Run, and a Test Restore

Use Dry Run to check the settings without uploading anything, then Run Now. In our test, 200 MB in 51 files uploaded in a few seconds. Later runs only send what changed.

Then prove it can come back. Create an empty dataset, for example tank/restore-test, open the task's menu, choose Restore, and pick the new dataset as the destination. Restore always into an empty dataset, never over the live one, then open a few files. Our restore matched the originals checksum for checksum.

6. Versioned Backups from the Shell

TrueNAS also has TrueCloud Backup Tasks. They are based on restic, and keep a series of snapshots in the bucket, so you can restore a file as it was last week. In TrueNAS 25.10 the web form only offers Storj credentials for them, but the system accepts an S3 credential from the shell. Find the credential's id, then create the task (System → Shell, or SSH as an admin):

sudo midclt call cloudsync.credentials.query | python3 -m json.tool | grep -E '"(id|name)"'

sudo midclt call cloud_backup.create '{
  "description": "documents (versioned)",
  "path": "/mnt/tank/documents",
  "credentials": 1,
  "attributes": {"bucket": "nas-backup", "folder": "documents-versioned"},
  "password": "a long repository password",
  "keep_last": 30,
  "snapshot": true,
  "schedule": {"minute": "0", "hour": "1", "dom": "*", "month": "*", "dow": "*"}
}'

It prints the task, including its id. Run it once by hand, list its snapshots, and restore one into an empty dataset:

sudo midclt call --job cloud_backup.sync 1
sudo midclt call cloud_backup.list_snapshots 1 | python3 -m json.tool | grep '"id"'
sudo midclt call --job cloud_backup.restore 1 SNAPSHOT_ID / /mnt/tank/restore-test '{}'

keep_last is how many snapshots it keeps. Store the repository password with the others: without it the snapshots cannot be read. Restic encrypts everything, so no separate encryption setting is needed. For more on how restic works, see Borg vs restic vs Kopia vs rclone.

One Copy Off-Site, Others at Home

A NAS with a mirror or RAIDZ survives a failed drive; an off-site copy survives losing the NAS. See the 3-2-1 backup rule for how the copies fit together, and Using object storage for the same bucket with rclone or the AWS CLI.

Common Questions

  • Is a Cloud Sync task a real backup?

    It is an off-site copy, which protects against fire, theft and a failed pool. It keeps one version of each file, though: if a file is changed or encrypted by ransomware, the next run uploads that version. Keep local ZFS snapshots for history, or use the versioned task in step 6.

  • What happens if I lose the encryption password or salt?

    The files in the bucket cannot be decrypted, by you or by anyone else. Store both in a password manager, away from the NAS, before the first run.

  • Can I back up to a storage box instead?

    Yes. Cloud Sync also supports SFTP, and a storage box answers on port 23. Its scheduled snapshots then keep older versions on our side, out of reach of anything that compromises the NAS. This guide covers object storage.

  • How long does the first backup take?

    As long as your upload speed needs to send the data once. Later runs only send what changed. Turning on Take Snapshot means a long first run still uploads a consistent copy.

S3-compatible object storage from 1 TB at a flat monthly price with transfer included, so a full restore is not billed per gigabyte.

See object storage

Keep Reading

All guides
Back Up TrueNAS to S3-Compatible Storage | Virteche Cloud