Linux Sysadmin · Lesson 8 · 25 min

Backups: tar, rsync & cron

Disks die. People type rm -rf in the wrong folder. Laptops get stolen. The only question is whether you had a backup when it happened. This final lesson uses almost everything you've learned: files, permissions, SSH keys, scripts and cron.

You will learn

  • The 3-2-1 backup rule
  • Packing files into archives with tar, and restoring them
  • gzip, zip/unzip, and checksums with sha256sum
  • Copying smartly with rsync (and its famous trailing-slash rule), plus scp
  • Automating backups with a script, cron and SSH keys

The 3-2-1 rule

Professionals keep 3 copies of important data, on 2 different kinds of storage, with 1 copy somewhere else (another building, or the cloud). And they test restoring. A backup you've never restored is just a hope.

tar: pack a folder into one file

tar (from “tape archive”) bundles many files into one. With z it also compresses them, like a .zip. The letters look scary, but there are only a few:

tar-ccreatezgzipvverboseffile name next docs-2026-09-27.tar.gzthe archiveDocumentswhat to pack
Same on both
tar -czvf docs-$(date +%F).tar.gz Documents    # create (date in the name!)
tar -tzf docs-2026-09-27.tar.gz                # t = list what's inside
tar -xzf docs-2026-09-27.tar.gz -C /tmp/restore # x = extract, -C = into this folder

$(date +%F) runs date and pastes its output (like 2026-09-27) into the file name, so every day's backup gets its own name. Tip: create, extract, list. The f always comes right before the archive name.

Remember permissions (Linux Basics, lesson 10): as a normal user, tar can only pack files you can read. System backups (/etc, other users' homes) need sudo.

Other ways to squeeze files

Rocky / RHEL
gzip big.log            # becomes big.log.gz (the original is replaced!)
zcat big.log.gz | less  # read it without unpacking
gunzip big.log.gz       # back to big.log
sudo dnf install zip unzip
zip -r project.zip project/
unzip -l project.zip    # look inside first
unzip project.zip -d restored
Ubuntu / Debian
gzip big.log
zcat big.log.gz | less
gunzip big.log.gz
sudo apt install zip unzip
zip -r project.zip project/
unzip -l project.zip
unzip project.zip -d restored

gzip squeezes one file. That's why tar bundles first and then gzips (.tar.gz). Old logs in /var/log end in .gz for the same reason. Use .zip when the archive is going to someone on Windows or Mac. Linux people expect .tar.gz.

Is my backup any good? Checksums

Same on both
sha256sum backups/*.tar.gz > backups/SHA256SUMS   # record fingerprints
sha256sum -c backups/SHA256SUMS                   # later: still identical?
backups/docs-2026-09-27.tar.gz: OK

A backup you've never tested is just a hope. Checksums prove the file hasn't been damaged since you made it, and a practice restore (tar -xzf … -C /tmp/restore) proves you can actually get your files back.

rsync: copy only what changed

rsync compares source and destination and only sends the differences. The second backup of a 50 GB folder might take a few seconds. It works locally and over SSH.

Rocky / RHEL
sudo dnf install rsync

Minimal Rocky installs may not include rsync. It must be installed on both ends when copying between machines.

Ubuntu / Debian
rsync --version

Already installed on Ubuntu Server.

Same on both
rsync -av Documents/ /backup/Documents/          # local mirror
rsync -av Documents student@192.168.1.50:backups/  # over SSH to a server
rsync -avn --delete Documents/ /backup/Documents/  # -n = DRY RUN: show, don't do

-a (“archive”) copies folders recursively and keeps permissions and times. -v lists each file.

The trailing-slash rule

rsync -a Documents /backup/ → creates /backup/Documents/… (the folder itself)
rsync -a Documents/ /backup/ → copies the contents straight into /backup/…

And --delete removes files from the destination that are gone from the source. Combine it with the wrong slash and you can wipe a backup. Always do a -n dry run first.

For a quick one-off copy of a file, scp is simpler: scp notes.txt student@192.168.1.50: (the : means “in my home folder over there”).

Automate it: script + cron

Put the backup steps in a script. It's easier to test, and it avoids cron's % trap (lesson 5):

~/backup.sh (same on both)
#!/bin/bash
# Nightly backup of my Documents
mkdir -p /home/student/backups
tar -czf /home/student/backups/docs-$(date +%F).tar.gz -C /home/student Documents
echo "backup done $(date)" >> /home/student/backups/backup.log
Then
chmod +x ~/backup.sh           # make it runnable
~/backup.sh                    # TEST IT BY HAND FIRST
crontab -e                     # add:  0 2 * * * /home/student/backup.sh

Notice the full paths everywhere, because cron has a tiny PATH. And -C /home/student tells tar to work from that folder, so the archive holds Documents/… instead of home/student/Documents/….

To copy backups to another machine automatically, cron can't type a password, so you use SSH keys from Linux Basics, lesson 3: ssh-keygen, then ssh-copy-id. After that, rsync … user@server: works with no password prompt. The second terminal below walks through it.

Keep it tidy

Nightly backups pile up. A common trick is to delete archives older than 14 days: find /home/student/backups -name '*.tar.gz' -mtime +14 -delete. (That's a real command. The playground doesn't run -delete, so try it on a real machine.)

Try it 1: nightly backups on the server

Try it 2: back up your laptop to the server

This terminal starts on your laptop. Set up a key so backups can run without a password, then push your Documents to the server with rsync.

Quick check

1. Which command lists what's inside site.tar.gz without extracting it?

2. What's the difference between rsync -a photos /mnt/usb/ and rsync -a photos/ /mnt/usb/?

3. Your cron backup copies to a server with rsync, but it never works. By hand it asks for a password. Fix?

Finished the missions and the quiz? Mark it done to track your progress.