# Restic Backup for cPanel and DirectAdmin: Files, Databases, Retention

Source: https://srvscripts.com/guides/restic-backup-cpanel-directadmin/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Use restic as a second, off-server backup next to the panel’s own backups. Back up `/home` (sites and mail), stream a dump of every database straight into restic with `--stdin-from-command`, and include the panel’s configuration folders. Keep 7 daily, 4 weekly and 6 monthly snapshots with `restic forget --prune`, run `restic check --read-data-subset` weekly, and do a real test restore every month.

We ran these commands on our lab server (AlmaLinux 9.8, DirectAdmin 1.712, restic 0.19.1) on 6 October 2026, with a test repository on the same server; the `restic dump` selection test used the same restic version on a scratch repository. The cPanel paths were checked on our cPanel lab (cPanel & WHM 11.138). Output below is from that run with names masked.

## Where restic fits on a hosting server

cPanel and DirectAdmin backups are built to recreate an account: they carry the panel’s metadata, DNS zones, mail settings and databases in a format the panel can restore in one click. Restic is built for something else: fast, deduplicated, encrypted file snapshots that you can keep for months on cheap storage (S3-compatible buckets, SFTP, a restic REST server) and restore a single file from in seconds.

That makes them a good pair:

| Need | Use |
| --- | --- |
| Recreate a whole account on a new server | Panel backup (cPanel backups, DirectAdmin Admin Backup/Transfer) |
| Restore one file, folder or mailbox from 3 weeks ago | restic |
| Keep months of history without paying for full copies | restic (deduplication) |
| A copy that ransomware on the server cannot delete | restic to an append-only or object-locked target |

Our [restic offsite backup script](/scripts/restic-offsite-backup/) wraps the commands on this page into one scheduled job.

## What to back up

### Home directories (sites and mail)

Both panels keep sites and mail under `/home/USER`. On cPanel, mail is in `/home/USER/mail`; on DirectAdmin it is in `/home/USER/imap` (with `Maildir` for the account’s own mailbox), and sites are in `/home/USER/domains`. Back up `/home` as a whole, and exclude what you can rebuild:

```
cat > /root/restic-excludes.txt  /root/bob_wp.sql
```

Select database snapshots by `--path`. In our test, `restic dump --tag db latest /bob_wp.sql` failed with `path "/bob_wp.sql" not found in snapshot` as soon as another database had been backed up more recently, because latest picked the newest snapshot with that tag. Load the dump into a new database first and compare before you replace the live one.

Restore into a scratch folder or a new database name, compare, then copy over the live data. Fix ownership after file restores (`chown -R bob:bob` on cPanel; on DirectAdmin check the original owner and group, which vary by folder).

## Schedule it

Run backups nightly from root’s cron or a systemd timer, with forget and prune weekly and a check after that. A minimal cron layout:

```
# /etc/cron.d/restic  (times in server local time)
15 2 * * *  root  /usr/local/sbin/restic-nightly.sh   >> /var/log/restic.log 2>&1
45 4 * * 0  root  /usr/local/sbin/restic-weekly.sh    >> /var/log/restic.log 2>&1
```

Run them at low priority (`nice -n 19 ionice -c3`) so customers do not notice, and alert on failure: restic exits with a non-zero code when a backup fails. Our [backup verify script](/scripts/backup-verify/) can check that the newest snapshot is recent.

## Common problems

- **Backups are huge:** panel backup folders, `/home/virtfs` or cache folders are included. Check the exclude file and `restic stats latest`.

- **Repository locked:** a previous run was interrupted. Make sure no restic process is running, then `restic unlock`.

- **Database dump is empty:** the dump command failed but the snapshot was saved. Check the size in `restic snapshots` and test the dump command by hand.

- **Restore has the wrong owner:** restic restores numeric IDs. On a new server with different UIDs, fix ownership with chown.

**Official documentation:** [restic documentation](https://restic.readthedocs.io/en/stable/) · [restic: Backing up (stdin and commands)](https://restic.readthedocs.io/en/stable/040_backup.html) · [restic: Removing snapshots (forget/prune)](https://restic.readthedocs.io/en/stable/060_forget.html)

**Related:** [Restic Backup Script for Offsite Backups](/scripts/restic-offsite-backup/) · [Backup Verify Script](/scripts/backup-verify/) · [WHM Backups S3: Reliable Remote Backups and Test Restores](/guides/whm-backups-s3-test-restore/) · [DirectAdmin Backups S3: Reliable Admin, Reseller and User Backups](/guides/directadmin-backups-s3/) · [mariadb-dump vs mysqldump: modern backup commands and wildcard database dumps](/guides/mariadb-dump-vs-mysqldump/)

**See also:** [JetBackup 5 Restore in WHM: Accounts, Files, Databases, Email](/guides/jetbackup-5-restore-admin/) · [JetBackup 4 to 5 Migration: The 5.2.11 Stepping Stone](/guides/jetbackup-4-to-5-migration/) · [cPanel restorepkg and pkgacct: Backup and Restore from CLI](/guides/cpanel-restorepkg-pkgacct-cli/)

## Frequently asked questions

### Can restic replace cPanel or DirectAdmin backups?

Not fully. Restic stores files and dumps, not panel accounts. Keep panel backups for whole-account restores and use restic for long history and granular restores.

### How do I back up MySQL databases with restic?

Dump each database with mariadb-dump and stream it in with restic backup –stdin-from-command and –stdin-filename. Do not copy /var/lib/mysql while the server runs.

### What retention should a hosting server use?

A common start is 7 daily, 4 weekly and 6 monthly snapshots. Adjust to your terms of service and storage budget.

### How often should I run restic check?

Weekly with –read-data-subset (for example 10%), plus a real test restore every month.

### Does restic encrypt backups?

Yes. Every repository is encrypted with its password; without the password the data cannot be read or recovered.
