Backing up to S3-compatible cloud storage
Amazon S3, Wasabi, Backblaze B2, MinIO or any S3-compatible bucket: the profile, the folder in the bucket, the storage class, and the limits to know.
On this page
A Cloud destination is your own bucket at a storage provider you pay directly; Genie9 never holds your data. Anything that speaks the S3 protocol works: Amazon S3, Wasabi, Backblaze B2, MinIO on a server of your own, and most others. Cloud destinations are part of Pro.
Before you start#
From your provider you need the bucket name, its region, the endpoint (Amazon S3 needs none), and an access key ID and secret access key that can list, read, write and delete in that bucket.
Step 1: Create an S3 profile#
A profile holds the keys, so several jobs can share one account.
- Open Settings ▸ Network & credentials, and under S3 profiles click Add profile. (Or click New profile… on the wizard's Where step.)
- Profile name: anything, for example Wasabi EU.
- Endpoint: leave it empty for Amazon S3. Otherwise type the service host, for example
s3.eu-central-1.wasabisys.com. - Fill in Region, Access key ID and Secret access key. The secret is sent to the agent once and stored encrypted on this PC; it is never shown again.
- Click Test. Signed in (210 ms) means the keys work.
- Click Save.
S3 profile dialog - a Wasabi account
Step 2: The Cloud destination in the wizard#
- On the Where step choose Cloud (S3-compatible).
- S3 profile: pick the profile you made.
- Bucket: the bucket's name.
- Folder in the bucket: it starts as the job's name. Leave it unless you share the bucket. The full
s3://address is shown under it. - Storage class: see the table below.
- Server-side encryption: The bucket’s default, S3-managed keys (SSE-S3) or AWS KMS key (SSE-KMS). This is the provider encrypting at rest, separate from the job's own AES-256 password; you can use both.
- Bandwidth limit: in Mbit/s, 0 for unlimited.
- Click Test destination. It checks the bucket, writes a small probe object and deletes it. Reachable and writable (180 ms) means the job is ready.
| Storage class | The app's hint |
|---|---|
| Standard (the bucket’s default) | Whatever the bucket is set to. Restores are immediate. |
| Infrequent Access | Cheaper to keep, a small fee per read. Restores are immediate; best for sets you rarely open. |
| Glacier Instant Retrieval | Cheapest to keep, a higher fee per read, a 90-day minimum charge per object. Restores are still immediate. |
What is different in the cloud#
- Files are uploaded one by one as the backup runs. The set's manifest and catalogue are kept on this PC and copied into the bucket beside the files.
- Small files are packed (on by default): files under 256 KB are stored together in pack files, so thousands of small files cost dozens of requests, not thousands.
- Verification reads everything back. Verify files after each run downloads every stored object and checks it against the manifest, as for any destination. Providers that charge for reads or downloads charge for that too. For a large cloud job where that matters, turn Verify files after each run off on the Settings step.
- Restores download from the bucket, at your provider's download price if it has one. Find keeps working from the index on this PC.
- Watch the cost. A job with long retention on Standard storage grows steadily. Standard for the daily job and Infrequent Access for a weekly archive job is a reasonable split.
Important
A cloud job's sets are listed from the copy of their index kept on the PC that made them. This version cannot open a bucket's backups on a different PC. If the PC itself might be lost, keep a local or NAS copy as well.
Providers, briefly#
| Provider | Endpoint | Note |
|---|---|---|
| Amazon S3 | leave empty | choose the region |
| Wasabi | s3.<region>.wasabisys.com | use the endpoint of the bucket's region |
| Backblaze B2 | s3.<region>.backblazeb2.com | use an application key made for S3 access |
| MinIO and other own servers | your server's host and port | path-style addressing is used automatically for any custom endpoint |
Not supported: SFTP, WebDAV, Backblaze's own (non-S3) API, Azure Blob Storage and Google Cloud Storage.
Troubleshooting#
"The service refused the keys"#
The key ID or secret is wrong, or the key has no rights on this bucket. Make a new key with list, read, write and delete on that bucket.
E-DEST-006 when a job runs#
The S3 profile this job uses isn't on this PC. The job was imported, or its profile removed. Open the job and pick or create the profile that holds the keys for its bucket.