Home › Articles › VPS Backup Strategy

VPS Backup Strategy: The 3-2-1 Rule and Best Tools

Updated: September 25, 2026 · 9 min read · Category: VPS
VPS Backup Strategy using 3-2-1 Rule for Linux Server

Table of Contents

  1. Why You Need a Clear Backup Strategy
  2. What Is the 3-2-1 Backup Rule?
  3. Backup Types: Full, Incremental, Differential
  4. Recommended VPS Backup Tools
  5. Setting Up Backup with rsync + cron
  6. BorgBackup: Deduplication Backup for VPS
  7. Backup Frequency Best Practices
  8. Restore Testing: What Most People Skip
  9. Frequently Asked Questions
  10. Summary
Key Takeaway: A good backup isn't just about having files somewhere — it's about having a strategy: multiple copies, multiple locations, multiple media types, and actually testing restore before disaster strikes.

1. Why You Need a Clear Backup Strategy

Data loss on a VPS can come from many sources — both preventable and unpreventable: hardware failure, ransomware, human error (accidental deletion), or OS corruption after a failed upgrade.

Sobering statistics from data security research:

AsiaGB VPS includes twice-monthly automated backups (on the 1st and 15th of each month) as a provider-level safety net. But for data that changes daily, you need your own backup strategy on top of that.

2. What Is the 3-2-1 Backup Rule?

The 3-2-1 Rule is an industry-standard approach used worldwide:

NumberMeaningExample
33 copies of your dataLive data + local backup + remote backup
22 different media typesSSD (VPS) + Object Storage (S3/R2)
11 copy offsiteCloudflare R2, Backblaze B2, or another VPS
Why 3-2-1 Works: The probability of all 3 copies failing simultaneously is near zero. Even in a datacenter fire or ransomware attack, your offsite copy survives.

3-2-1 in Practice for Your VPS

3. Backup Types: Full, Incremental, Differential

TypeHow It WorksStorageRestore SpeedBest For
Full BackupCopies every file each timeHighFastWeekly backup, initial baseline
IncrementalCopies only what changed since the last backupVery lowSlower (chain needed)Daily backup
DifferentialCopies everything changed since the last FullMediumMediumWhen fast restore matters
For most VPS setups: Weekly Full + Daily Incremental is the sweet spot. Tools like BorgBackup handle chaining automatically with deduplication built in.

4. Recommended VPS Backup Tools

ToolStrengthsBest ForDifficulty
rsyncShips with Linux, no install needed, SSH supportBeginners, simple backups⭐ Easy
BorgBackupDeduplication, encryption, compressionProduction VPS, storage efficiency⭐⭐ Medium
ResticNative S3/B2/R2 support, fast, cross-platformCloud Storage backends⭐⭐ Medium
DuplicatiGUI, encrypted, cloud-readyUsers who prefer a web UI⭐ Easy
mysqldump / pg_dumpBuilt-in database toolsDatabase-specific backup⭐ Easy

5. Setting Up Backup with rsync + cron

rsync is the best starting point — no dependencies, and easy to understand.

Step 1: Set Up SSH Key Authentication

# On your VPS, create a key pair
ssh-keygen -t ed25519 -C "backup-key" -f ~/.ssh/backup_key -N ""

# Copy public key to backup server
ssh-copy-id -i ~/.ssh/backup_key.pub user@backup-server

Step 2: Create a Backup Script

#!/bin/bash
# /usr/local/bin/vps-backup.sh
DATE=$(date +%Y-%m-%d)
BACKUP_USER="backup"
BACKUP_HOST="backup-server.example.com"
BACKUP_PATH="/backups/myvps/$DATE"
LOG="/var/log/backup.log"

echo "[$DATE] Starting backup..." >> $LOG

rsync -avz --delete \
  -e "ssh -i /root/.ssh/backup_key -o StrictHostKeyChecking=no" \
  /var/www/ /etc/ /home/ \
  $BACKUP_USER@$BACKUP_HOST:$BACKUP_PATH/ >> $LOG 2>&1

if [ $? -eq 0 ]; then
  echo "[$DATE] Backup completed successfully" >> $LOG
else
  echo "[$DATE] Backup FAILED!" >> $LOG
fi

Step 3: Schedule with cron

# crontab -e
# Run every night at 2:00 AM
0 2 * * * /usr/local/bin/vps-backup.sh
Tip: Add --exclude='/proc' --exclude='/sys' --exclude='/dev' --exclude='/tmp' to skip virtual filesystems and keep backup size lean.

6. BorgBackup: Deduplication Backup for VPS

BorgBackup is ideal for VPS servers that need long backup history without ballooning storage costs. Its deduplication system stores identical data only once, typically saving 40–60% on storage.

Install and Use BorgBackup

# Install
apt install borgbackup -y

# Initialize repository (once)
borg init --encryption=repokey user@backup-server:/backups/borg-repo

# Create backup
borg create --stats --progress \
  user@backup-server:/backups/borg-repo::$(date +%Y-%m-%d) \
  /var/www /etc /home

# List all archives
borg list user@backup-server:/backups/borg-repo

# Restore a single file from specific date
borg extract user@backup-server:/backups/borg-repo::2026-09-20 \
  var/www/html/important.php

Automatic Pruning of Old Archives

# Keep 7 daily, 4 weekly, 6 monthly archives
borg prune --keep-daily=7 --keep-weekly=4 --keep-monthly=6 \
  user@backup-server:/backups/borg-repo

7. Backup Frequency Best Practices

Data TypeRecommended FrequencyBest Method
Database (MySQL/PostgreSQL)Every 4–6 hours or dailymysqldump + cron
File uploads / user contentDailyrsync incremental or Restic
Config files (/etc)Before every change + weeklygit + rsync
Application codeEvery deployGit repository is the primary backup
System snapshotWeeklyVPS Snapshot from provider
⚠️ Database Warning: Always use mysqldump --single-transaction for InnoDB tables to get a consistent snapshot without table locks. Never copy raw .ibd files while MySQL is running.

8. Restore Testing: What Most People Skip

Having a backup without testing restore is like buying insurance without reading the policy — you don't know if it actually works until disaster strikes.

Restore Testing Checklist (Every 3 Months)

RTO and RPO: Define your RTO (Recovery Time Objective — how fast must you be back online?) and RPO (Recovery Point Objective — how much data loss is acceptable?). Design your backup schedule to meet both targets.

9. Frequently Asked Questions

Q: AsiaGB VPS already includes automatic backups. Do I still need my own?
AsiaGB includes twice-monthly backups (1st and 15th) for provider-level disaster recovery. If your data changes daily (e-commerce, blog, database), you should set up daily backups yourself to keep your RPO within 24 hours.
Q: How long should I keep backups?
A common approach: Daily backups for 7 days, weekly for 4 weeks, monthly for 6–12 months. For regulated data (financial, medical), retention requirements may be 5–7 years.
Q: Is backing up to Cloud Storage (S3/R2) secure?
Yes, if you encrypt before uploading. Both BorgBackup and Restic include client-side encryption — data is encrypted on your VPS before it ever leaves for the cloud. The storage provider cannot read it.
Q: Can I back up a live database without corrupting it?
Yes. For MySQL InnoDB, use mysqldump --single-transaction for a consistent, lock-free snapshot. For PostgreSQL, pg_dump is safe by design. Both work safely on live production databases.
Q: Restic vs BorgBackup — which should I choose?
Restic is better if you want to backup directly to Cloud Storage (S3, R2, B2) and supports multiple clients concurrently. BorgBackup shines for SSH-based backups to a dedicated server, with excellent deduplication for similar data sets. Both offer encryption and compression.

Summary: A Solid VPS Backup Strategy

Ready for a Reliable VPS?
AsiaGB VPS offers Thailand and Singapore VPS with twice-monthly automated backups and fast SSD storage.

View All VPS Plans