A twelve-line backup habit
Every clever backup system I built, I eventually stopped feeding. What stuck is a dumb script and a calendar entry:
#!/bin/sh
# weekly.sh — runs on the backup box, pulls from the VPS
set -eu
box="me@myvps.example"
dest="vps/$(date -u +%F)"
rsync -a --dry-run "$box:/var/www/" "vps/current/www/" # look first
rsync -a "$box:/var/www/" "vps/current/www/"
rsync -a "$box:/etc/caddy/" "vps/current/caddy/"
rsync -a "vps/current/" "$dest/" # dated snapshot
Four rules made it survive where the clever versions didn't:
- Pull, don't push. The script runs on the backup machine. If the VPS is ever compromised, the backups are not on it to be found or deleted.
- Dry-run first, every time. That one flag has caught a wrong path more than once.
- The off-machine copy beats the tool. Plain rsync to another box outperforms any elaborate scheme that lives only on the machine it protects.
- Restore once a quarter. A backup that has never been restored is a hope, not a backup. I test by diffing a restored tree against the live one.
No personal data lives on this box, so /var/www plus a
couple of /etc directories really is the whole estate. Small
estate, small script.