# Backups

> Full and incremental backups, encrypted S3 copies, database backups and customer schedules, plus how to restore an account, a file or a database.

Source: https://zopanel.net/docs/backups  
Updated: 2026-10-07

ZoPanel has several kinds of backups that work together. Full account backups give you a complete archive you can move to any ZoPanel server. Incremental snapshots (restic) are small nightly copies you can restore one file at a time. Database backups can run as often as every hour. Every archive can also be copied, encrypted, to S3-compatible storage. This page covers the setup, the safety checks and every way to restore.

## Overview

| Kind | Contents | Schedule | Where |
| --- | --- | --- | --- |
| Full account backup | Websites and databases of one account | Manual, or daily/weekly at 02:00 | `~/backups` of the account, plus S3 |
| Incremental snapshot (restic) | Files, databases and mail of every account | Nightly at 01:00 | `/var/backups` on the server, or S3 |
| Database backup | One database | Every hour, every 6 hours or daily | `backups/db` of the account, plus S3 |
| Customer schedule | Files, databases and mail, as the customer chooses | Daily or weekly, at a chosen hour | The account, and optionally the customer's own S3 |
| Configuration backup (`.zpb`) | Panel settings and database | Daily | S3 (see [Disaster recovery](/docs/disaster-recovery)) |

## Full account backups

On the **Backups** page, choose an account and click **Create backup**. All websites and databases of the account are archived into `~/backups`.

To back up every account automatically, open **Settings → General**:

- **Automatic backups:** **Off**, **Daily** or **Weekly (Sunday)**. Backups run at 02:00 server time.
- **Backups to keep per account:** 1 to 90 (default 7).

Before a backup starts, ZoPanel checks the free disk space. It refuses to start when less than 1 GB, or less than 5% of the disk, is free, so a backup can never fill the disk and take the websites down. Each finished archive gets a SHA-256 checksum, which is checked again before any restore.

## Remote backups to S3

Remote backups need a Pro license. Open **Settings → Remote backups**, turn the switch on and fill in:

| Field | Notes |
| --- | --- |
| **Provider presets** | AWS, Cloudflare R2, Backblaze B2, Wasabi, MinIO and others |
| Endpoint, Region, Bucket | From your storage provider |
| **Folder prefix** | Defaults to `zopanel` |
| Access key, Secret key | Use a key limited to this bucket |
| **Remote copies to keep per account** | 1 to 365 (default 14) |
| **Path-style URLs (R2, MinIO)** | Required by some providers |
| **Plain HTTP (private MinIO only)** | Only for a MinIO server on a private network |

Click **Test connection**, then **Save**. From then on, every account backup and database backup is uploaded after it finishes.

### Encryption and the recovery key

Copies are encrypted on the server before they are uploaded, with XChaCha20-Poly1305 and a key derived from the panel's **recovery key**. The storage provider, or anyone who gets the bucket's access key, sees only encrypted data. Encrypted files are split into authenticated chunks, so a truncated or modified file fails to open instead of restoring damaged data.

To see the key, open **Backups → Disaster recovery → Show key**. **Write it down and keep it off the server**, for example in a password manager. Without it, nothing in the bucket can be read on another server.

## Incremental backups (restic)

Incremental backups are set up by the administrator on the **Backups** page, in the **Incremental backups** card:

1. Turn on **Snapshot every account each night (01:00)**.
2. Choose the **Destination**: **This server (/var/backups)**, or S3. S3 uses the bucket from **Settings → Remote backups**, which must be set up first.
3. Set the retention: **Daily** (default 7), **Weekly** (default 4) and **Monthly** (default 6).
4. Click **Show recovery key** and store this key as well. The restic repository is encrypted with it.

Each snapshot stores only what changed since the last one, so it is deduplicated, compressed and encrypted. Every Saturday at 05:00, ZoPanel checks the repository structure and reads back 2% of the data. If the check fails, administrators get the **Backup failed** alert.

## Database backups

Open **Databases**, then **Backups** for a database:

- **Automatic backup:** **Off**, **Every hour**, **Every 6 hours** or **Every day**, with the number of copies to **Keep**.
- **Back up now** for a manual copy.

When remote backups are on, these copies are also sent to S3, encrypted the same way.

## Customers' own schedules and S3 storage

Customers can set up their own schedule on their **Backups** page, in the **Automatic backups** card:

- **Schedule**: daily or weekly, with the **Day** and **Time (server)**.
- What to include: **Website files**, **Databases**, **Email**.
- **Copies on server**: 1 to 30 (default 3).
- **Copy to my storage**: any S3-compatible storage (Amazon S3, Cloudflare R2, Backblaze B2, Wasabi, Google Cloud Storage with HMAC keys), with **Copies in storage** from 1 to 365.

Customer storage must be a public HTTPS endpoint. Addresses on the server's own network are refused. **Test connection** checks that the bucket can be written.

## Restoring

### A whole account

- **From a backup on the server:** **Backups → Restore**. Files and databases are overwritten with the backup's contents.
- **From a file made on any ZoPanel server:** **Backups → Restore from file**. The account, websites and databases are recreated with the same names, users and passwords. Websites or databases that already exist with the same names are refused.
- **From S3:** **Backups → Disaster recovery → Browse S3**, then open server → account and click **Restore** on a backup. If the account does not exist, it is created. This also works for backups of servers that no longer exist.

### Single files, folders and mail

In the **Snapshots (incremental)** card on the **Backups** page, choose a snapshot, browse it and click **Restore** on a file or folder. Files go back in place, and newer files with the same name are replaced. Mail is merged into the mailboxes. Customers can do this themselves for their own account, and they can click **Snapshot now** before a risky change.

### Databases

- In a database's **Backups** list, click **Restore**. The current data is backed up first (type **before restore**), so the restore can be undone.
- From a snapshot, a restored database is added to that database's backup list, ready to restore.

## Good practice

- Turn on remote backups. Security Center warns when **Backups leave the server** is not met, and when no backup has succeeded in 48 hours.
- Keep the recovery key and the incremental key outside the server.
- Test a restore on a spare server from time to time. A backup that was never restored is not proven.
