The Options Side by Side
| Aspect | How it works | Good | Watch out for |
|---|---|---|---|
| Borg to an SSH storage box | borg talks to borg serve over SSH | Native, no extra steps, efficient incremental uploads | Needs an SSH target, not a bucket |
| Borg locally, then rclone sync | Back up to a local repo, copy it to S3 | Works with any bucket; Borg unchanged | Needs local disk for the whole repo; sync must not overlap backups |
| restic or Kopia | Encrypted, deduplicated backups straight to S3 | Made for object storage | A different tool and repository format |
| Borg 2 beta | s3: and b2: repositories built in | Native S3 support | Beta: the project says not for production; repos not compatible with 1.x |
Option 1: Borg to an SSH Storage Box
The simplest route keeps Borg exactly as it is designed to run. A storage box accepts Borg over SSH, so the repository lives off the server and only new data is uploaded each night:
borg init --encryption=repokey ssh://USER@HOST:23/./borg
borg create --stats ssh://USER@HOST:23/./borg::{now} /etc /srv /home
borg prune --keep-daily 7 --keep-weekly 4 --keep-monthly 6 ssh://USER@HOST:23/./borgBacking up a Linux server with Borg covers keys, a nightly timer and a test restore.
Option 2: Local Repository, Then rclone
If the copy must end up in S3, Backblaze B2 or Wasabi, back up to a local repository and copy it to the bucket afterwards. Do the steps in order, so the bucket never receives a repository halfway through a write:
borg create --stats /srv/borg-repo::{now} /etc /srv/www /home
borg prune --keep-daily 7 --keep-weekly 4 /srv/borg-repo
borg compact /srv/borg-repo
rclone sync /srv/borg-repo remote:my-bucket/borg-repo --checksumrclone sync makes the bucket match the local repository, including deletions, so a damaged local repository would be copied too. Run borg check regularly, and if the bucket supports versioning or retention locks, turn them on. To restore, copy the repository back with rclone copy and run borg extract as usual. The rclone side is covered in using object storage with rclone.
Option 3: restic or Kopia Straight to S3
restic and Kopia work much like Borg (encrypted, deduplicated snapshots with retention rules) but write to S3-compatible storage directly, with no local copy:
export AWS_ACCESS_KEY_ID=YOUR_KEY AWS_SECRET_ACCESS_KEY=YOUR_SECRET export RESTIC_REPOSITORY=s3:https://S3_ENDPOINT/my-bucket/server1 export RESTIC_PASSWORD_FILE=/root/.restic-password restic init restic backup /etc /srv/www /home restic forget --keep-daily 7 --keep-weekly 4 --prune
Borg vs restic vs Kopia vs rclone compares them in detail.
Option 4: Borg 2
Borg 2 adds repositories on S3, Backblaze B2 and anything rclone supports, through its new storage layer. As of September 2026 it is still in beta (2.0.0b25), and its release notes ask users not to use it for production backups. Its repositories are also a new format that Borg 1.x cannot read. It is worth testing on a spare bucket, not yet worth trusting with the only copy of your data.
Amazon S3, Backblaze B2 and Wasabi are trademarks of their respective owners. Virteche is not affiliated with or endorsed by them. Details about their products come from their public documentation as of the date at the top of this guide.