Synology offsite backup
with Restic, encrypted on the NAS.
Run Restic in Synology Container Manager and send encrypted snapshots of your shared folders to a ServerCrate vault. Your NAS encrypts everything first, we store ciphertext, and restores carry no egress fees. Free to test, paid plans from $2 a month.
Why offsite
RAID keeps the NAS running. It is not a backup.
A Synology with two or four drives in SHR or RAID survives a failed disk. It does not survive a deleted folder that syncs everywhere, ransomware that encrypts a mapped drive, a power surge, a burst pipe or a break-in. Snapshots on the same box help with the first two and not the rest. The rule of thumb is simple: keep at least one copy somewhere else, encrypted, that the NAS itself does not control.
Restic is a strong fit for that copy. It deduplicates at the chunk level, so a renamed folder or a reorganized photo library does not get uploaded twice. It encrypts and authenticates every piece of data before it leaves the machine. And it can verify the whole repository, so you know the backup is readable before you need it.
A note on Hyper Backup
Hyper Backup is Synology's built-in backup app, and it is the first thing most owners try. Hyper Backup targets are not supported by our vaults: our endpoint speaks the Restic REST protocol. The supported path is Restic running in Container Manager, which takes about fifteen minutes to set up and gives you a portable repository any Restic install can read, on any operating system.
Set it up in Container Manager.
Install Container Manager from Package Center. Create a folder for the configuration, for example /volume1/docker/restic, and save your repository password in a file called pass inside it. Store a second copy of that password somewhere off the NAS, such as a password manager: without it, nobody can decrypt the backup, including us. Then enable SSH under Control Panel, Terminal and SNMP, and connect as an administrator.
Schedule it
Open Control Panel, Task Scheduler, and create a user-defined script that runs as root. Paste the backup command, without sudo, and set it to run daily at a quiet hour. Turn on email notifications in the task settings so a failed run reaches you. Setting --hostname keeps every snapshot tagged with the same host name, which makes the snapshot list easy to read.
Verify it
Once a month, swap backup /data for check --read-data-subset=10% to read back a tenth of the repository and confirm it decrypts cleanly. Downloads carry no fees on our plans, so you can check as often as you like. To restore, mount an empty folder such as /volume1/restore into the container and run restore latest --target /restore. Our recovery drill walks through a full restore end to end.
What to send offsite.
Start with what you would not be able to replace: photos, documents, home folders, and any shared folder that holds business records. Media you could download again, such as a film library, can usually stay local unless you have room to spare. Exclude the #recycle folders and @eaDir thumbnail folders that DSM creates, since they add size without value.
Plan for your upload speed. The first backup sends everything once, and a few hundred gigabytes over a typical home connection can take a day or more. After that, Restic sends only changed chunks, so nightly runs are usually short. Run the first backup over a weekend and leave the NAS to it.
The same approach works on other systems. See our guides for NAS offsite backup in general and TrueNAS offsite backup, and the setup guide for Restic on Linux, macOS and Windows.
Vault plans for your NAS.
Flat monthly prices, no egress or restore fees. Yearly billing is 10 times monthly, two months free. Renewal is always your signup price.
- 100 GB storage
- 3 devices
- 14-day history
- Restic over HTTPS
- No egress or restore fees
- $20/yr billed yearly, 2 months free
- 250 GB storage
- 10 devices
- 30-day history
- Restic over HTTPS
- No egress or restore fees
- $30/yr billed yearly, 2 months free
- 1 TB storage
- 25 devices
- 60-day history
- Restic over HTTPS
- No egress or restore fees
- $90/yr billed yearly, 2 months free
- 2 TB storage
- 50 devices
- 90-day history
- Restic over HTTPS
- No egress or restore fees
- $170/yr billed yearly, 2 months free
Vaults are ZFS-backed and reached over Restic REST with post-quantum TLS on our edge. Read how we run them on our security page and compare every product on pricing. Pay by card, PayPal or Bitcoin, with a 30-day money-back guarantee. Need a server too? See cloud servers.
Synology backup questions.
Can I use Hyper Backup with ServerCrate?
No. Hyper Backup targets are not supported by our vaults. Our endpoint speaks the Restic REST protocol, so the supported path on a Synology is Restic running in Container Manager.
Does my Synology model support Container Manager?
Many current models do. Open Package Center on your NAS and search for Container Manager. If it is listed for your model, you can follow this guide as written.
Is my data encrypted before it leaves the NAS?
Yes. Restic encrypts every file inside the container on your NAS before upload. The repository password stays with you, and we store only ciphertext.
How long will the first backup take?
It depends on how much data you have and your home or office upload speed. After the first run, Restic only sends changed chunks, so daily runs are usually much shorter.
How do I restore a single folder?
Run restic restore with an include filter, for example restic restore latest --target /restore --include /data/photos/2024. You can also mount the repository and copy files out by hand.
Which plan should I pick?
Add up the shared folders you want offsite and choose the plan with room to grow: Lite for 100 GB, Starter for 250 GB, Standard for 1 TB or Pro for 2 TB. The Free plan gives you 10 GB to test the whole setup first.