S3 entry point · Nimbus Backup Gateway

    Back up over S3 into an offsite PBS chain

    restic, rclone, Hyper Backup, HBS 3, TrueNAS: S3 is the protocol all your tools can speak. The Nimbus Backup Gateway gives them an S3-compatible target, reachable over VPN only, then replicates your backups to Proxmox Backup Server — with an offline copy if you choose one. It is not an object storage offer: it is a way in.

    S3-compatible restic / rclone Hyper Backup / HBS 3 Dedicated VPN PBS downstream Optional offline copy

    S3, the protocol every backup tool can speak

    restic, rclone, Synology and QNAP NAS, TrueNAS, your applications' exports: almost everything can write to an S3-compatible target. It is the Gateway's most versatile entry path, especially when a source speaks neither rsync nor a NAS protocol. You keep your tool; the Gateway provides the target and forwards to PBS. Not sure S3 is the right path for your source? See the guide choosing the right backup method.

    restic → S3 rclone Hyper Backup HBS 3 TrueNAS Cloud Sync aws-cli S3-compatible apps

    What the Gateway does with your objects

    The Gateway exposes an S3-compatible endpoint through a MinIO backend. It is an entry target reachable through the S3 API — not multi-region production object storage, and we do not advertise S3 features beyond what has been validated. Protection is built behind it.

    Dedicated access keys

    One S3 key set per source, revocable, restricted to its own bucket.

    Buffer zone

    Your objects land as-is in the buffer zone, sized on your working set. Deduplication happens afterwards, on the PBS side.

    Downstream protection

    One or more PBS, each with an optional offline or LTO copy: that is where immutability is decided.

    How it works, step by step

    Four steps, without changing your backup tool.

    1

    Dedicated VPN

    We set up an encrypted tunnel (WireGuard or OpenVPN) between your source and the Gateway. The S3 endpoint is only reachable inside that tunnel: no inbound port, no public exposure of the bucket.

    2

    Your tool writes to the Gateway over S3

    restic, rclone, Hyper Backup, HBS 3 or your S3-compatible application simply change destination. You keep your tool and its settings; we provide the target.

    3

    The Gateway replicates to your PBS

    The buffer zone's content goes to one or more PBS, depending on the plan. For each PBS: optional offline disk copy, LTO or offline LTO.

    4

    Tested restore

    We run a real restore from the Nimbus chain with you before going live. You get the measured duration: that is what serves as the estimate.

    From S3 PUT to offline copy

    The Gateway buffers your objects, then replicates them to one or more PBS — all optional and composable. Each PBS then gets its own protection options, depending on the plan.

    Your S3 tool (restic / rclone / NAS / app)
    Nimbus Backup Gateway (S3 endpoint / MinIO, buffer)
    1 or more PBSoptional

    For each PBS, composable options:

    Offline disk (air-gap)LTOOffline LTO

    Multi-PBS architectures are detailed on the PBS plans and AirGap PBS pages. Why two sites? See the OVH Strasbourg fire case study.

    Object bucket or Gateway: two different jobs

    The protocol is the same. What changes is what sits behind it — and the price.

    An object bucket (Backblaze B2, Wasabi…) fits if you want

    • The lowest per-TB price, billed on usage
    • Native Object Lock on the bucket
    • Direct Internet access, no VPN
    • To handle retention and restore tests yourself

    The Nimbus Gateway fits if you want

    • The backup to end up in a PBS chain, not in a single service
    • An offline copy, out of reach of a compromised key
    • An endpoint never exposed to the Internet (dedicated VPN)
    • Someone who supervises and tests the restore with you

    What the S3 endpoint is — and is not

    It is

    • An S3-compatible entry target (MinIO backend, S3 API)
    • One of the Gateway's entry protocols, with rsync, SMB or WebDAV
    • Reachable only through a dedicated VPN

    It is not

    • A pay-as-you-go object storage offer
    • A bucket with Object Lock: immutability comes from the PBS downstream
    • Multi-region production object storage, nor a CDN
    • A promise of full feature parity with the AWS S3 API

    Full plans, pricing (Cloud from 150EUR excl. tax/month, 2 TB included), capacity and options are on the offsite NAS backup hub. To compare S3 against the other paths for your source, see the protocols matrix. Is the source a NAS? See offsite backup for a Synology NAS or offsite Unraid backup.

    Frequently asked questions — backup over S3

    No. Nimbus does not sell a pay-as-you-go bucket. Here S3 is one of the Nimbus Backup Gateway's ingestion protocols, alongside rsync, SMB and WebDAV: your tools drop their backups on it, then the Gateway replicates them to the Proxmox Backup Server chain of your choice. The Gateway is priced as such (Cloud from 150EUR excl. tax/month, 2 TB included) — details on the offsite NAS backup hub.

    An S3-compatible target served by a MinIO backend, reachable only through the S3 API (no file-sharing interface). Your tools — restic, rclone, aws-cli, Hyper Backup, HBS 3, TrueNAS Cloud Sync or any S3-compatible application — write to it through the dedicated VPN. It is a backup entry point, not multi-region production object storage.

    From what you put behind the Gateway. The S3 endpoint does not advertise Object Lock: protection comes from one or more PBS, which keep their own backup versions, and optionally from a copy on an offline disk or on LTO tape. A compromised S3 key can delete objects in the Gateway's buffer zone; it gives access neither to the PBS backups nor to a disconnected copy.

    If all you need is a per-TB bucket, with native Object Lock and usage-based billing, object storage such as Backblaze B2 or Wasabi costs less per TB and needs no VPN. The Gateway makes sense when you want the backup to end up in a supervised PBS chain, with an offline copy, and someone who tests the restore with you.

    Any client speaking the S3 API: restic (S3 repository), rclone (sync or crypt), aws-cli, Synology Hyper Backup and QNAP HBS 3 (S3-compatible target), TrueNAS Cloud Sync, or any application with an S3 target. For a Synology or QNAP NAS, rsync remains the recommended path (it preserves the native backup format); S3 is the fallback when rsync is not an option. The NAS backup protocols matrix compares the paths by source.

    No. The S3 endpoint is never published on the Internet: it is reachable only through a dedicated VPN (WireGuard or OpenVPN), with no inbound port opened on your firewall. Your S3 access keys and objects only travel inside the encrypted tunnel.

    Plug your S3 tools into the Gateway

    We connect your S3 tool to the Gateway, replicate to your PBS and test a restore with you. A 15-minute technical call, no commitment.