Welcome to Implementing Incremental Backups with BorgBackup on Linux VPS. Managing terabytes of VPS data requires a backup solution that is fast, space-efficient, and secure. BorgBackup (Borg) is a powerful deduplicating backup program that perfectly fits this need.

1. Why Choose BorgBackup?

BorgBackup provides space-efficient storage by deduplicating data at the block level. This means if you change a few lines in a massive database dump or append to a log file, Borg only stores the new bytes. It also offers authenticated encryption, ensuring your data is secure both in transit and at rest on the backup server.

2. Initializing the Repository

After installing Borg (sudo apt install borgbackup), the first step is to initialize a repository on a remote storage server (or a secondary block storage volume). Use the command: borg init --encryption=repokey user@backupserver:/path/to/repo. You will be prompted to create a passphrase.

3. Creating the First Archive

To create your first backup (called an archive in Borg), run: borg create --stats --progress user@backupserver:/path/to/repo::"{hostname}-{now}" /var/www /etc /home. The first run will take some time as it transfers all data, but subsequent runs will be lightning fast.

4. Automating with Cron and Bash

To automate this, create a bash script that exports your BORG_PASSPHRASE, runs the borg create command, and then runs borg prune to keep the repository size manageable. A typical prune command looks like: borg prune --keep-daily=7 --keep-weekly=4 --keep-monthly=6.

5. Mounting Archives for File Restoration

Borg makes restoring individual files incredibly easy. You can mount a remote repository locally using FUSE: borg mount user@backupserver:/path/to/repo /mnt/borg. You can then browse the backup history just like a regular filesystem and use cp to restore specific files before running borg umount /mnt/borg.

Conclusion

By leveraging BorgBackup, VPS administrators can maintain months of historical backups with minimal storage overhead. It's a reliable, cryptographically secure way to ensure business continuity.