Unraid · rsync / restic

    Move your Unraid server backups offsite

    Unraid has no native enterprise backup target: we lean on what your stack already exposes. rsync via User Scripts or a restic / rclone container push your shares, over a dedicated VPN, to the Nimbus Backup Gateway — then protected by PBS, AirGap and LTO.

    User Scripts rsync restic SFTP / S3 Dedicated VPN Multi-PBS AirGap LTO

    The method depends on your container

    On Unraid there is no single enforced backup tool: the flexibility comes from Community Apps. The User Scripts plugin lets you schedule an rsync task with nothing else to install; to target SFTP, FTP, WebDAV or S3, you go through a restic or rclone container. So the available path depends on what you already run. The Gateway accepts both and saves you from maintaining a second remote Unraid box. Not sure which path? See the choose the right backup method guide and the protocols matrix. On a different source? See offsite backup for a QNAP NAS or offsite Linux server backup.

    rsync (User Scripts) restic → SFTP / S3 rclone SMB / NFS (local)

    Recommended protocol

    Two clean options, depending on whether you want a simple mirror or encrypted deduplication.

    rsync via User Scripts

    The lightest path: a task scheduled by the User Scripts plugin, no extra container. Ideal for a file mirror of your shares to the Gateway. rsync preserves the tree and only transfers deltas.

    restic → SFTP / S3

    The most robust path: a restic (or rclone) container writing over SFTP or S3 to the Gateway, with deduplication, versioned snapshots and source-side encryption. Prefer it as soon as volume or retention matters.

    Shared doctrine: everything flows through a dedicated VPN (zero inbound ports), the Gateway buffers, then Nimbus replicates to immutable PBS, AirGap PBS and LTO. The Gateway multiplexes your non-Proxmox sources; your Proxmox VMs go straight from PVE → PBS.

    How it works, step by step

    Four steps, without touching the array or your production containers.

    1

    Dedicated VPN

    We set up an encrypted tunnel (WireGuard or OpenVPN) between your Unraid server and the Gateway. Nothing is exposed in clear text: your server opens an outbound tunnel, no inbound ports to open.

    2

    rsync (User Scripts) or restic

    An rsync task scheduled by the User Scripts plugin pushes your shares to the Gateway, or a restic/rclone container writes over SFTP/S3 with dedup and encryption. Your array stays untouched.

    3

    Nimbus replicates multi-PBS + AirGap

    The Gateway buffers the backup, then Nimbus protects it to a Primary PBS — and optionally a disconnected AirGap PBS and an LTO tape in a vault. Retention and immutability on the PBS side.

    4

    Restore test

    We validate a real restore from the Nimbus chain to guarantee your Unraid shares are recoverable, then sign off the go-live.

    From your Unraid to the air-gap

    A single backup can be replicated to several PBS, then archived to tape, depending on the PBS plan you subscribe to.

    Unraid server (rsync / restic)
    Nimbus Backup Gateway
    Primary PBS
    AirGap PBSoptional
    LTO in a vaultoptional

    Pricing and plans

    The Gateway Cloud starts at 150EUR excl. tax/month (2 TB included, 99EUR setup); the full six plans, the Appliance option, the antivirus scan and the PBS tiers are on the offsite NAS backup hub.

    Get a quote

    Frequently asked questions — Unraid

    Two paths depending on your stack. The simplest: an rsync task scheduled by the User Scripts plugin, pushing your shares to the Nimbus Backup Gateway. The most robust: a restic (or rclone) container writing over SFTP or S3 to the Gateway, with deduplication and application-side encryption. Either way, everything flows through a dedicated VPN and the Gateway then protects the backup to PBS.

    rsync via User Scripts is enough if you want a simple file mirror of your shares with no container dependency. Prefer restic (to SFTP or S3) when you want deduplication, source-side encryption and versioned snapshots. Since restic and rclone run as Docker containers on Unraid, the choice comes down to what you are willing to maintain. To compare paths, see the protocols matrix.

    For rsync: the User Scripts plugin (Community Apps) is enough to schedule the task, since rsync is already present. For SFTP/FTP/WebDAV/S3: you install a restic or rclone container depending on the target. An SMB/NFS mount of the Gateway is also possible but we keep it for local transfer cases. The available method therefore depends on the container you run.

    No. Access to the Gateway is exclusively through a dedicated VPN (WireGuard or OpenVPN). In client mode, your Unraid server opens an outbound tunnel to Nimbus: no inbound ports to open on your router or firewall, and the Gateway never exposes its services in clear text on the internet.

    Yes. Once the backup is ingested by the Gateway, Nimbus protects it on Proxmox Backup Server with retention and immutability, then optionally to a disconnected AirGap PBS and an LTO tape in a vault. Even if your Unraid server or its array is compromised by ransomware, the offsite copy stays intact and restorable.

    Move your Unraid offsite with confidence

    We wire rsync (User Scripts) or restic to the Gateway, protect to PBS and validate a restore. A 15-minute tech chat, no commitment.