1. Create a Bucket and an Access Key
In the Virteche dashboard, open your object storage, create a bucket (for example nas-backup), and copy the access key ID and secret access key into a password manager. The secret is shown once.
2. Add the Bucket as a Cloud Credential
Go to Credentials → Backup Credentials → Cloud Credentials and press Add. Choose the Amazon S3 provider; it works with any S3-compatible service once you set the endpoint:
Provider: Amazon S3 Access Key ID: your access key ID Secret Access Key: your secret access key Endpoint URL: https://s3.us-west.virteche.com Region: us-west
Leave Disable Endpoint Region off, and the other options as they are. Press Verify Credential: it should come back valid before you save. If it fails, check that the endpoint starts with https:// and that the region is exactly us-west.
3. Create the Cloud Sync Task
Go to Data Protection → Cloud Sync Tasks and press Add to open the Cloud Sync Task Wizard. Choose the credential, then:
- Direction: Push, from TrueNAS to the bucket.
- Directory/Files: the dataset to back up, for example
/mnt/tank/documents. - Bucket and Folder: your bucket, and a folder per dataset, such as
documents. - Transfer Mode: see below.
| Transfer Mode | What it does |
|---|---|
| Sync | Makes the bucket match the dataset, deleting remote files you deleted. The bucket stays the same size as the data. |
| Copy | Uploads new and changed files and never deletes anything remote. Deleted files stay in the bucket until you remove them. |
| Move | Uploads, then deletes the files from TrueNAS. For archiving, not for backups. |
Copy is the safer choice for a backup: something deleted on the NAS by mistake is still in the bucket. Choose Sync when you want the bucket to stay the size of the data and you keep ZFS snapshots on the NAS for history.
4. Turn On Encryption and Snapshots
- Remote Encryption: TrueNAS encrypts files before uploading. Set a long Encryption Password and Encryption Salt, and keep both off the NAS: a restore needs exactly the same two values.
- Filename Encryption: TrueNAS marks it “not recommended”. Leave it off unless the file and folder names themselves are sensitive. We tested both ways.
- Take Snapshot: the task uploads from a ZFS snapshot taken at the start, so files that change during a long upload are still copied consistently.
- Schedule: daily, at a quiet hour such as 2:00.
5. Dry Run, First Run, and a Test Restore
Use Dry Run to check the settings without uploading anything, then Run Now. In our test, 200 MB in 51 files uploaded in a few seconds. Later runs only send what changed.
Then prove it can come back. Create an empty dataset, for example tank/restore-test, open the task's menu, choose Restore, and pick the new dataset as the destination. Restore always into an empty dataset, never over the live one, then open a few files. Our restore matched the originals checksum for checksum.
6. Versioned Backups from the Shell
TrueNAS also has TrueCloud Backup Tasks. They are based on restic, and keep a series of snapshots in the bucket, so you can restore a file as it was last week. In TrueNAS 25.10 the web form only offers Storj credentials for them, but the system accepts an S3 credential from the shell. Find the credential's id, then create the task (System → Shell, or SSH as an admin):
sudo midclt call cloudsync.credentials.query | python3 -m json.tool | grep -E '"(id|name)"'
sudo midclt call cloud_backup.create '{
"description": "documents (versioned)",
"path": "/mnt/tank/documents",
"credentials": 1,
"attributes": {"bucket": "nas-backup", "folder": "documents-versioned"},
"password": "a long repository password",
"keep_last": 30,
"snapshot": true,
"schedule": {"minute": "0", "hour": "1", "dom": "*", "month": "*", "dow": "*"}
}'It prints the task, including its id. Run it once by hand, list its snapshots, and restore one into an empty dataset:
sudo midclt call --job cloud_backup.sync 1
sudo midclt call cloud_backup.list_snapshots 1 | python3 -m json.tool | grep '"id"'
sudo midclt call --job cloud_backup.restore 1 SNAPSHOT_ID / /mnt/tank/restore-test '{}'keep_last is how many snapshots it keeps. Store the repository password with the others: without it the snapshots cannot be read. Restic encrypts everything, so no separate encryption setting is needed. For more on how restic works, see Borg vs restic vs Kopia vs rclone.
One Copy Off-Site, Others at Home
A NAS with a mirror or RAIDZ survives a failed drive; an off-site copy survives losing the NAS. See the 3-2-1 backup rule for how the copies fit together, and Using object storage for the same bucket with rclone or the AWS CLI.