
Restic Backup: Encrypted, Deduplicated Snapshots from the Command Line
Restic is a single-binary backup tool that creates encrypted, deduplicated snapshots of files and directories and saves them to a repository you choose. A repository can live on a local disk, a remote host over SFTP, or object storage such as S3-compatible services, Backblaze B2, Azure Blob, and Google Cloud Storage. The workflow stays deliberately simple: initialize a repository once, run a backup command whenever you want a new snapshot, then list, mount, or restore from any snapshot later. Because each snapshot stores only new data through content-defined chunking, repeat backups finish quickly and consume far less space than whole copies. Every snapshot is self-describing, so it can be inspected or recovered without the original machine present.
Restic differs from file-sync utilities in how it treats history. Instead of mirroring one folder state onto another, it keeps immutable snapshots with timestamps, so an accidental deletion or a ransomware event can be rolled back to an earlier point rather than propagated. Users also appreciate that backups are always encrypted, deduplicated, and checkable through built-in integrity verification, which makes shared cloud storage safe for sensitive data. Teams that want scheduled, interface-driven mirroring alongside snapshot archives often pair it with SyncBackPro, which handles live folder-to-folder jobs on a desktop. Restore options range from pulling a single file out of a snapshot to rebuilding an entire machine after a disk failure.
Benefits of Using Restic
The main benefit of Restic is confidence that a backup will actually restore. Every snapshot is content-addressed and checksummed, so the tool can verify repository integrity on demand and detect damaged or missing data before you need it. Deduplication across snapshots means a nightly job over millions of files transfers only changed chunks, which keeps both upload time and storage bills low. Encryption is not optional, so credentials, source code, and personal documents stay unreadable in a shared bucket. Because the repository is plain files, it can be copied, mirrored, or archived with ordinary tools, and a second copy offsite is straightforward. Retention policies let you keep a sensible history — hourly, daily, weekly, monthly — while pruning older snapshots automatically, which avoids unbounded growth. The result is a backup system that is cheap to run, easy to script into a scheduler, and dependable during an emergency.
Restic Software Information
- Current Version: 0.19.1
- File Size: 10.7 MB
- Language: English / system language
- Downloads: 58.1K
- Platform: Windows Desktop
System Requirements
- Processor: 2-core CPU
- RAM: 2 GB RAM
- Storage: 1 GB available storage
- Graphics / GPU: Not required
Visit the official Restic website
Restic Features
Encrypted Repositories by Default
Every repository is encrypted with AES-256 in counter mode and authenticated with Poly1305, and the master key is derived from your passphrase using scrypt. That means filenames, contents, and snapshot metadata stay unreadable to anyone who gains access to the storage backend, including cloud providers, without any extra configuration.
Content-Defined Deduplication
Data is split into variable-length chunks using a rolling hash, so identical sections of a file are stored only once no matter where they appear or how the file shifts between runs. This makes long-term storage far cheaper and speeds up repeat backups of large, slowly changing datasets.
Immutable Timestamped Snapshots
Each backup run records a new snapshot that references the current state of the chosen paths, rather than overwriting previous data. You can therefore browse a folder exactly as it looked last Tuesday, compare two points in time, and recover a file that was deleted or corrupted months earlier without disturbing anything else.
Flexible Storage Backends
A repository can be local, on a mounted network share, on a remote server reached over SFTP, or in object storage such as Amazon S3, Backblaze B2, Azure Blob Storage, Google Cloud Storage, and any rclone remote. You are not locked into a single vendor or protocol.
Quick Incremental Backups
Because unchanged chunks are already in the repository, a second or third backup of a large dataset only uploads the differences, so nightly jobs over millions of files stay short. A local cache of chunk metadata further reduces the work needed to determine what actually changed since the previous run.
Selective and Full Restores
You can restore an entire snapshot to a new location, restore only a subfolder with the include filter, or pull out a single path using the same command structure. Restores are always read-only against the repository, so recovering files never risks damaging the backups themselves.
Browse Snapshots by Mounting
On systems with FUSE support, the mount command exposes every snapshot as a read-only filesystem, letting you open backups in a file manager, compare directories, or copy files out with normal tools. This is often faster and more intuitive than restoring to a temporary folder just to check what is inside.
Retention Rules and Automatic Pruning
The forget command applies rules such as keep-daily, keep-weekly, keep-monthly, or keep-last to decide which snapshots survive, then prune reclaims the data they leave behind. Automated retention keeps a repository from growing forever, while integrity checks confirm that the remaining data is complete and readable.
Restic Old Versions
Version 0.19.0 Updated: June 9, 2026 Download
Version 0.18.1 Updated: September 21, 2025 Download
Version 0.18.0 Updated: March 27, 2025 Download
Version 0.17.3 Updated: November 8, 2024 Download
Version 0.17.2 Updated: October 27, 2024 Download
Restic FAQs
What is Restic used for?
Restic creates and manages encrypted, deduplicated backups of files and directories. Typical uses include nightly server backups to object storage, protecting a laptop’s documents, archiving project folders before major changes, and maintaining an offsite copy that can be restored after hardware failure, accidental deletion, or ransomware.
Are Restic backups encrypted and deduplicated?
Yes. Data is deduplicated into shared chunks and encrypted before it leaves the machine, and the repository key is derived from your passphrase, so neither file contents nor filenames are readable in the storage backend. Because the encryption applies to the shared chunk data, deduplication and confidentiality work together rather than conflicting.
How does Restic differ from a file synchronization or mirroring tool?
Synchronization tools keep a second location matching the current state of a folder, so a deletion or corrupted file tends to be copied across. Restic instead keeps a series of immutable, timestamped snapshots, which lets you return to an earlier version of a file. Many people run both approaches side by side depending on how quickly they need a live replica.
Which storage locations can Restic save backups to?
Repositories can be created on a local disk, a mounted network share, a remote host accessed over SFTP, an HTTP rest-server, or object storage including Amazon S3, Backblaze B2, Azure Blob Storage, Google Cloud Storage, OpenStack Swift, and any remote exposed through rclone.
How do I remove old snapshots without deleting current data?
Use the forget command with retention rules such as keep-daily 7, keep-weekly 4, and keep-monthly 12 to declare which snapshots should be kept, then run prune to reclaim the space used by data no longer referenced. Pruning only removes chunks that no remaining snapshot needs, so recent backups are unaffected.
Can Restic run unattended from a script or scheduler?
Yes. Commands are non-interactive once the repository password is supplied through an environment variable or a password file, which makes scheduled backups straightforward to automate. Exit codes and the JSON output option let wrapper scripts detect failures, send alerts, and record backup summaries.
