restic is a fast, secure, efficient backup program written in Go for Linux, macOS, Windows, FreeBSD and OpenBSD users who want verifiable, encrypted backups stored to a backend of their choosing.
What it is
restic is an open-source backup program implemented in Go and released under the BSD-2-Clause licence. It runs on the three major operating systems — Linux, macOS and Windows — as well as FreeBSD and OpenBSD, and it stores backups in a repository that can live almost anywhere, from a local directory to a remote object store. The project is developed openly on GitHub, with documentation hosted on Read the Docs and a community Discourse forum for questions.
The concrete problem restic addresses is that a backup kept on the same machine is not a real backup strategy. restic solves this by supporting native backends for a local directory, an sftp server accessed over SSH, an HTTP REST server, Amazon S3 and any other S3-compatible storage, OpenStack Swift, Backblaze B2, Microsoft Azure Blob Storage, Google Cloud Storage, and many other services through the rclone backend — so backup data can live off the machine that holds the originals. Because the storage location is assumed not to be a trusted environment, restic applies cryptography to guarantee the confidentiality and integrity of the data rather than trusting the repository host.
Key capabilities
- Stores backups to a local directory, an sftp server via SSH, an HTTP REST server, Amazon S3 (or any other S3-compatible storage), OpenStack Swift, Backblaze B2, Microsoft Azure Blob Storage, Google Cloud Storage, and other services through the rclone backend.
- Creates repositories and snapshots from the command line with commands such as
restic init --repo, restic backup, restic restore and restic mount.
- Mounts a repository over FUSE with
restic mount so files from previous snapshots can be browsed directly.
- Restores only the data that is actually needed for the requested files, so restoring does not transfer the entire repository.
- Verifies that all stored data can be read back, reflecting the design principle that restore matters more than backup.
- Deduplicates data across backups, as indicated by the project's dedupe and deduplication focus.
- Guards access to a repository with a password, where knowledge of that password is required to access the repository and losing it means the data is irrecoverably lost.
Who uses it and how
- Developers and system administrators backing up working directories such as
~/work, monitoring progress through per-directory and per-file scan output and throughput figures.
- Users who keep backups off-machine on cloud object storage such as Amazon S3, Backblaze B2, Microsoft Azure Blob Storage or Google Cloud Storage.
- Operators with an SSH-accessible host who prefer the sftp backend over SSH, or who run their own HTTP REST server.
- Homelab and multi-OS users who need the same tool on Linux, macOS, Windows, FreeBSD and OpenBSD.
- People recovering data by restoring specific files or by mounting the repository over FUSE and browsing snapshots.
Getting started
Install restic following the installation guide at https://restic.readthedocs.io/en/latest/020_installation.html, then run restic init --repo /tmp/backup to create a repository and restic --repo /tmp/backup backup ~/work to add data.
How it compares
Among similar tools named in these facts, restic is a Go project under the BSD-2-Clause licence that integrates with rclone for additional storage services rather than requiring a specific provider. Its documentation, Discourse forum and Read the Docs publication distinguish it by putting usage guidance and community support alongside the code. No paid products are listed as replacements in the available facts, so no licence or cost comparison against them can be drawn here.
When to use it — and when not
A self-hoster must choose and operate a backend — a local directory, an sftp server, an HTTP REST server, or a cloud store — and must guard the repository password, since losing it means the data is irrecoverably lost. It should not be picked by anyone unwilling to manage repository access credentials or who cannot tolerate a CLI-driven workflow around init, backup, restore and mount. The repository currently carries 622 open issues, and the design principle that the storage location is untrusted means the cryptography, not the host, is what protects the data.
project readme (upstream, from github) — read inline

Introduction
restic is a backup program that is fast, efficient and secure. It supports the three major operating systems (Linux, macOS, Windows) and a few smaller ones (FreeBSD, OpenBSD).
For detailed usage and installation instructions check out the documentation.
You can ask questions in our Discourse forum.
Quick start
Once you've installed restic, start
off with creating a repository for your backups:
$ restic init --repo /tmp/backup
enter password for new backend:
enter password again:
created restic backend 085b3c76b9 at /tmp/backup
Please note that knowledge of your password is required to access the repository.
Losing your password means that your data is irrecoverably lost.
and add some data:
$ restic --repo /tmp/backup backup ~/work
enter password for repository:
scan [/home/user/work]
scanned 764 directories, 1816 files in 0:00
[0:29] 100.00% 54.732 MiB/s 1.582 GiB / 1.582 GiB 2580 / 2580 items 0 errors ETA 0:00
duration: 0:29, 54.47MiB/s
snapshot 40dc1520 saved
Next you can either use restic restore to restore files or use restic mount to mount the repository via fuse and browse the files from previous
snapshots.
For more options check out the online documentation.
Backends
Saving a backup on the same machine is nice but not a real backup strategy.
Therefore, restic supports the following backends for storing backups natively:
Design Principles
Restic is a program that does backups right and was designed with the
following principles in mind:
Easy: Doing backups should be a frictionless process, otherwise
you might be tempted to skip it. Restic should be easy to configure
and use, so that, in the event of a data loss, you can just restore
it. Likewise, restoring data should not be complicated.
Fast: Backing up your data with restic should only be limited by
your network or hard disk bandwidth so that you can backup your files
every day. Nobody does backups if it takes too much time. Restoring
backups should only transfer data that is needed for the files that
are to be restored, so that this process is also fast.
Verifiable: Much more important than backup is restore, so restic
enables you to easily verify that all data can be restored.
Secure: Restic uses cryptography to guarantee confidentiality and
integrity of your data. The location the backup data is stored is
assumed not to be a trusted environment (e.g. a shared space where
others like system administrators are able to access your backups).
Restic is built to secure your data against such attackers.
Efficient: With the growth of data, additional snapshots should
only take the storage of the actual increment. Even more, duplicate
data should be de-duplicated before it is actually written to the
storage back end to save precious backup space.
Reproducible Builds
The binaries released with each restic version starting at 0.6.1 are
reproducible, which means that you can
reproduce a byte identical version from the source code for that
release. Instructions on how to do that are contained in the
builder repository.
News
You can follow the restic project on Mastodon @restic or subscribe to
the project blog.
License
Restic is licensed under BSD 2-Clause License. You can find the
complete text in LICENSE.
Sponsorship
Backend integration tests for Google Cloud Storage and Microsoft Azure Blob
Storage are sponsored by AppsCode!
