Backups: tar, rsync & cron
Disks die. People type rm -rf in the wrong folder. Laptops get stolen. The only question is whether you had a backup when it happened. This final lesson uses almost everything you've learned: files, permissions, SSH keys, scripts and cron.
You will learn
- The 3-2-1 backup rule
- Packing files into archives with
tar, and restoring them gzip,zip/unzip, and checksums withsha256sum- Copying smartly with
rsync(and its famous trailing-slash rule), plusscp - Automating backups with a script, cron and SSH keys
The 3-2-1 rule
Professionals keep 3 copies of important data, on 2 different kinds of storage, with 1 copy somewhere else (another building, or the cloud). And they test restoring. A backup you've never restored is just a hope.
tar: pack a folder into one file
tar (from “tape archive”) bundles many files into one. With z it also compresses them, like a .zip. The letters look scary, but there are only a few:
tar -czvf docs-$(date +%F).tar.gz Documents # create (date in the name!) tar -tzf docs-2026-09-27.tar.gz # t = list what's inside tar -xzf docs-2026-09-27.tar.gz -C /tmp/restore # x = extract, -C = into this folder
$(date +%F) runs date and pastes its output (like 2026-09-27) into the file name, so every day's backup gets its own name. Tip: create, extract, list. The f always comes right before the archive name.
Remember permissions (Linux Basics, lesson 10): as a normal user, tar can only pack files you can read. System backups (/etc, other users' homes) need sudo.
Other ways to squeeze files
gzip big.log # becomes big.log.gz (the original is replaced!) zcat big.log.gz | less # read it without unpacking gunzip big.log.gz # back to big.log sudo dnf install zip unzip zip -r project.zip project/ unzip -l project.zip # look inside first unzip project.zip -d restored
gzip big.log zcat big.log.gz | less gunzip big.log.gz sudo apt install zip unzip zip -r project.zip project/ unzip -l project.zip unzip project.zip -d restored
gzip squeezes one file. That's why tar bundles first and then gzips (.tar.gz). Old logs in /var/log end in .gz for the same reason. Use .zip when the archive is going to someone on Windows or Mac. Linux people expect .tar.gz.
Is my backup any good? Checksums
sha256sum backups/*.tar.gz > backups/SHA256SUMS # record fingerprints sha256sum -c backups/SHA256SUMS # later: still identical?
backups/docs-2026-09-27.tar.gz: OK
A backup you've never tested is just a hope. Checksums prove the file hasn't been damaged since you made it, and a practice restore (tar -xzf … -C /tmp/restore) proves you can actually get your files back.
rsync: copy only what changed
rsync compares source and destination and only sends the differences. The second backup of a 50 GB folder might take a few seconds. It works locally and over SSH.
sudo dnf install rsync
Minimal Rocky installs may not include rsync. It must be installed on both ends when copying between machines.
rsync --version
Already installed on Ubuntu Server.
rsync -av Documents/ /backup/Documents/ # local mirror rsync -av Documents student@192.168.1.50:backups/ # over SSH to a server rsync -avn --delete Documents/ /backup/Documents/ # -n = DRY RUN: show, don't do
-a (“archive”) copies folders recursively and keeps permissions and times. -v lists each file.
rsync -a Documents /backup/ → creates /backup/Documents/… (the folder itself)
rsync -a Documents/ /backup/ → copies the contents straight into /backup/…
And --delete removes files from the destination that are gone from the source. Combine it with the wrong slash and you can wipe a backup. Always do a -n dry run first.
For a quick one-off copy of a file, scp is simpler: scp notes.txt student@192.168.1.50: (the : means “in my home folder over there”).
Automate it: script + cron
Put the backup steps in a script. It's easier to test, and it avoids cron's % trap (lesson 5):
#!/bin/bash # Nightly backup of my Documents mkdir -p /home/student/backups tar -czf /home/student/backups/docs-$(date +%F).tar.gz -C /home/student Documents echo "backup done $(date)" >> /home/student/backups/backup.log
chmod +x ~/backup.sh # make it runnable ~/backup.sh # TEST IT BY HAND FIRST crontab -e # add: 0 2 * * * /home/student/backup.sh
Notice the full paths everywhere, because cron has a tiny PATH. And -C /home/student tells tar to work from that folder, so the archive holds Documents/… instead of home/student/Documents/….
To copy backups to another machine automatically, cron can't type a password, so you use SSH keys from Linux Basics, lesson 3: ssh-keygen, then ssh-copy-id. After that, rsync … user@server: works with no password prompt. The second terminal below walks through it.
Nightly backups pile up. A common trick is to delete archives older than 14 days: find /home/student/backups -name '*.tar.gz' -mtime +14 -delete. (That's a real command. The playground doesn't run -delete, so try it on a real machine.)
Try it 1: nightly backups on the server
Try it 2: back up your laptop to the server
This terminal starts on your laptop. Set up a key so backups can run without a password, then push your Documents to the server with rsync.
Quick check
1. Which command lists what's inside site.tar.gz without extracting it?
✓ t = list. x would extract everything into your current folder.
2. What's the difference between rsync -a photos /mnt/usb/ and rsync -a photos/ /mnt/usb/?
✓ The trailing slash means “the contents of.”
3. Your cron backup copies to a server with rsync, but it never works. By hand it asks for a password. Fix?
✓ Never store passwords in scripts or crontabs. Keys were made for exactly this.