How to Back Up to Quake AI Object Storage
Coming from another cloud?
▸AWS·Amazon S3
This Quake AI feature maps to AWS’s Amazon S3.
▸Azure·Blob Storage
This Quake AI feature maps to Azure’s Blob Storage.
▸Google Cloud·Storage
This Quake AI feature maps to Google Cloud’s Storage.
How to back up to Quake AI object storage
Use Quake AI object storage as an off-site backup target in a 3-2-1 strategy: three copies of your data, on two different media, with one copy off-site. This guide covers file-level backups with rclone, encrypted backups with restic, database backups, and cron-based automation.
You do not need to migrate your primary storage to Quake AI to use this guide. Quake AI works as a standalone backup destination alongside any primary provider.
Prerequisites#
- A Quake AI account with S3 credentials
- A dedicated backup bucket on Quake AI (see create a bucket)
- rclone installed (v1.65+) for file-level backups
- restic installed (v0.16+) for encrypted, deduplicated backups
- A Linux server, macOS workstation, or VM with cron or systemd available
Configure rclone for Quake AI#
Add Quake AI as an rclone remote. Edit ~/.config/rclone/rclone.conf:
[quakeai]
type = s3
provider = Ceph
access_key_id = YOUR_ACCESS_KEY
secret_access_key = YOUR_SECRET_KEY
endpoint = object.us-east-2.rumble.cloud
acl = privateReplace the endpoint with your region. Verify the connection:
rclone lsd quakeai:See tools comparison for detailed rclone configuration.
Copy from an SFTP source#
Some providers expose file storage over SFTP instead of S3. Hetzner Storage Box is one example: it speaks SFTP, FTP, SMB, and WebDAV, not S3. Add an SFTP remote as the source alongside your existing rumble remote:
[storagebox]
type = sftp
host = u123456.your-storagebox.de
user = u123456
pass = YOUR_PASSWORDReplace the host and user with the values from your Storage Box settings. For key-based auth, use key_file instead of pass. Run rclone config if you prefer an interactive setup.
Copy from the SFTP remote to Quake AI:
rclone copy storagebox:backup-path quakeai:my-backup-bucket/storagebox \
--transfers 8 \
--progressUse copy, not sync, so deletions on the source do not propagate to your backup bucket.
File-level backup with rclone#
One-time backup#
Copy a local directory to Quake AI. Use copy, not sync: copy only adds and updates files on the destination and never deletes, which protects against propagating local deletions to your backup.
rclone copy /path/to/data quakeai:my-backup-bucket/daily \
--transfers 8 \
--progressExclude temporary files#
rclone copy /path/to/data quakeai:my-backup-bucket/daily \
--exclude "*.tmp" \
--exclude ".cache/**" \
--exclude "node_modules/**" \
--transfers 8 \
--progressVerify the backup#
rclone check /path/to/data quakeai:my-backup-bucket/daily --one-wayThis compares every local file against the remote copy and reports mismatches.
Encrypted backup with restic#
restic provides built-in AES-256 encryption, content-defined deduplication, and retention policy management. Backups are encrypted before leaving your machine.
Initialize the repository#
export AWS_ACCESS_KEY_ID="YOUR_ACCESS_KEY"
export AWS_SECRET_ACCESS_KEY="YOUR_SECRET_KEY"
export RESTIC_REPOSITORY="s3:https://object.us-east-2.rumble.cloud/my-backup-repo"
export RESTIC_PASSWORD="YOUR_ENCRYPTION_PASSWORD"
restic initRun a backup#
restic backup /path/to/data \
--exclude ".cache" \
--exclude "node_modules" \
--verboserestic deduplicates at the chunk level; subsequent backups transfer only changed blocks, saving bandwidth and storage.
Apply a retention policy#
restic forget \
--keep-daily 7 \
--keep-weekly 4 \
--keep-monthly 12 \
--pruneThis keeps 7 daily, 4 weekly, and 12 monthly snapshots, then removes unreferenced data with --prune.
Verify backup integrity#
restic checkRun this periodically (monthly) to verify that all data in the repository is intact and readable.
Restore from backup#
List available snapshots:
restic snapshotsRestore the latest snapshot to a local directory:
restic restore latest --target /path/to/restoreRestore a specific file or directory:
restic restore latest --target /tmp/restore --include "/path/to/specific/file"Database backups#
Object storage is a natural destination for database dumps. The pattern is: dump → compress → upload → manage retention.
PostgreSQL#
#!/bin/bash
TIMESTAMP=$(date +%Y%m%d-%H%M%S)
BACKUP_DIR="/tmp/db-backups"
BUCKET="quakeai:my-backup-bucket/postgres"
mkdir -p "$BACKUP_DIR"
pg_dump -U postgres -h localhost my_database \
| gzip > "${BACKUP_DIR}/my_database-${TIMESTAMP}.sql.gz"
rclone copy "${BACKUP_DIR}/" "${BUCKET}/" --progress
rm -f "${BACKUP_DIR}/my_database-${TIMESTAMP}.sql.gz"MySQL / MariaDB#
#!/bin/bash
TIMESTAMP=$(date +%Y%m%d-%H%M%S)
BACKUP_DIR="/tmp/db-backups"
BUCKET="quakeai:my-backup-bucket/mysql"
mkdir -p "$BACKUP_DIR"
mysqldump -u root --single-transaction --quick my_database \
| gzip > "${BACKUP_DIR}/my_database-${TIMESTAMP}.sql.gz"
rclone copy "${BACKUP_DIR}/" "${BUCKET}/" --progress
rm -f "${BACKUP_DIR}/my_database-${TIMESTAMP}.sql.gz"SQLite#
SQLite databases are single files. Use the .backup command for a consistent copy, then upload:
#!/bin/bash
TIMESTAMP=$(date +%Y%m%d-%H%M%S)
BACKUP_DIR="/tmp/db-backups"
BUCKET="quakeai:my-backup-bucket/sqlite"
mkdir -p "$BACKUP_DIR"
sqlite3 /path/to/database.db ".backup '${BACKUP_DIR}/database-${TIMESTAMP}.db'"
gzip "${BACKUP_DIR}/database-${TIMESTAMP}.db"
rclone copy "${BACKUP_DIR}/" "${BUCKET}/" --progress
rm -f "${BACKUP_DIR}/database-${TIMESTAMP}.db.gz"Database backup retention#
Delete database dumps older than your retention period:
rclone delete quakeai:my-backup-bucket/postgres --min-age 90d
rclone delete quakeai:my-backup-bucket/mysql --min-age 90dAutomate with cron#
rclone nightly backup#
Edit your crontab with crontab -e:
# File backup: nightly at 02:00
0 2 * * * /usr/bin/rclone copy /path/to/data quakeai:my-backup-bucket/daily --transfers 8 --log-file /var/log/rclone-backup.log --log-level INFO
# Database backup: nightly at 02:30
30 2 * * * /usr/local/bin/backup-postgres.sh >> /var/log/db-backup.log 2>&1
# Retention cleanup: weekly on Sunday at 04:00
0 4 * * 0 /usr/bin/rclone delete quakeai:my-backup-bucket/daily --min-age 90d --log-file /var/log/rclone-cleanup.log --log-level INFOrestic nightly backup#
# Encrypted backup: nightly at 02:00
0 2 * * * /usr/bin/restic backup /path/to/data --exclude ".cache" --quiet >> /var/log/restic-backup.log 2>&1
# Retention policy: weekly on Sunday at 04:00
0 4 * * 0 /usr/bin/restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 12 --prune --quiet >> /var/log/restic-forget.log 2>&1
# Integrity check: first of the month at 05:00
0 5 1 * * /usr/bin/restic check --quiet >> /var/log/restic-check.log 2>&1systemd timer alternative#
For systems using systemd, create a service and timer pair instead of cron. This provides better logging via journalctl and automatic retry on failure.
/etc/systemd/system/rclone-backup.service:
[Unit]
Description=Rclone backup to Quake AI
[Service]
Type=oneshot
ExecStart=/usr/bin/rclone copy /path/to/data quakeai:my-backup-bucket/daily --transfers 8 --log-level INFO/etc/systemd/system/rclone-backup.timer:
[Unit]
Description=Run rclone backup nightly
[Timer]
OnCalendar=*-*-* 02:00:00
Persistent=true
[Install]
WantedBy=timers.targetEnable and start:
sudo systemctl enable --now rclone-backup.timerEnable versioning and encryption#
For additional protection on your backup bucket:
- Versioning preserves previous versions of overwritten objects. Enable it so accidental overwrites do not destroy backup data. See enable versioning.
- Server-side encryption encrypts data at rest on Quake AI's storage layer. See server-side encryption. If using restic, data is already encrypted client-side before upload; server-side encryption is an additional layer.
Monitor and test#
- Check logs after each automated run. Both rclone and restic write structured logs. Monitor for errors, especially auth failures and network timeouts.
- Test restores quarterly. A backup you have never restored from is a backup you cannot trust. Download a sample of files and verify integrity.
- Alert on failure. Wrap your cron jobs in a script that sends a notification (email, Slack webhook, or monitoring system alert) if the exit code is non-zero.
Cost estimation#
Object storage on Quake AI is a per-TB add-on, and each dedicated vCPU subscription includes 1 TB at no additional cost. Backup sets that fit within the included 1 TB do not add to the bill; sets that exceed the allowance scale per additional TB. For current rates, see the canonical Quake AI pricing page.
restic's deduplication typically reduces stored data to 30-60% of the source size after multiple backup cycles, lowering effective storage requirements.
See also#
- Plan your migration: S3 compatibility matrix and feature gap workarounds
- Migration tools comparison: rclone vs restic vs other tools
- Multi-cloud sync: continuous replication between Quake AI and other providers
- Enable versioning
- Server-side encryption
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 08.09.2026
Quick answers
- What is the S3-compatible endpoint hostname?CLIAPI
- Where do I set CORS rules, lifecycle policies, or bucket policies in the Console?Console
- Why do Object Storage API curl examples fail before the first request?API
- Why does my public bucket URL return 404 from the browser after I apply a public-read policy?APIConsole