Mr.PlanB Logo
    Production Runbook

    Proxmox Backup Strategy: The Complete Operator Guide

    Taking backups is the easy part. An architecture passes or fails on fast, reliable restores under production stress. This guide compares Proxmox Backup Server, Veeam and offsite strategies for recovery, whether you run a homelab cluster or hundreds of enterprise nodes.

    Core metric

    RTO (Recovery Time Objective)

    Architecture

    3-2-1-1-0 Immutability

    Rule of thumb

    Weekly automated verify drills

    Community software reviews

    Detailed scoring and benchmark telemetry for PBS, Veeam, built-in VZDump, and hosted cloud PBS providers.

    Comparing the main approaches

    Best for 90% of Proxmox deployments

    Proxmox Backup Server (PBS)

    Built for PVE. It splits VM and container disks into deduplicated 4MB blocks, which allows fast incremental snapshots and verified restores.

    Strengths

    • Near-instant incremental backups
    • Block-level deduplication across VMs
    • Client-side encryption with key validation

    Trade-offs

    • Requires dedicated SSD/NVMe datastore for chunk index IOPS
    • Linux/Proxmox-centric only
    Best for mixed VMware / Windows enterprise fleets

    Veeam Backup & Replication

    Supports Proxmox alongside ESXi, Hyper-V, and physical Windows servers with enterprise compliance and centralized tape archiving.

    Strengths

    • One console for mixed hypervisors
    • Enterprise SLA reporting and support
    • Granular application-aware item restores

    Trade-offs

    • Licensing costs per socket/instance
    • Heavier infrastructure footprint
    Best for compliance & air-gapped security

    Acronis Cyber Protect

    Combines image-level agent backups with built-in ransomware heuristics and immutable cloud targets.

    Strengths

    • Integrated anti-malware and vulnerability scanning
    • Cloud-native immutability
    • Direct failover capabilities

    Trade-offs

    • Agent-based overhead on guest OS
    • Subscription pricing model
    Best for simple homelabs & remote offsite files

    Built-in VZDump + Duplicati/Restic

    Uses Proxmox's built-in `vzdump` snapshots to an NFS share, then pushes compressed archives offsite with Restic or Duplicati.

    Strengths

    • No licensing cost, runs anywhere
    • Direct S3 / B2 cloud object targets
    • No dedicated appliance needed

    Trade-offs

    • No deduplication across snapshots with raw vzdump
    • Full backup IO load during dumps

    Three gotchas in Proxmox backup design

    PBS chunk storage needs IOPS

    PBS splits everything into 4MB deduplicated chunks. Random I/O on spinning HDDs slows verification and garbage collection jobs, so use fast SSDs/NVMe for the datastore or metadata cache.

    Client-side encryption keys

    If you enable client-side encryption in PBS, store your encryption key and master paper key outside the cluster. If your PVE node dies and you lose that key, you cannot decrypt or recover your backup data.

    Verify jobs vs. real restore tests

    PBS verification jobs check chunk sha256 checksums to confirm data hasn't corrupted on disk. They don't show that your guest OS will boot after an unclean kernel panic, so schedule periodic test restores into an isolated VLAN.

    What about the Proxmox host configuration?

    Don't spend time imaging the entire hypervisor root drive, since Proxmox VE can be reinstalled in under 10 minutes. Back up the configuration files that define your cluster state instead:

    Paths to back up:

    • /etc/pve/ (Cluster config & VM defs)
    • /etc/network/interfaces (SDN & bridges)
    • /etc/vzdump.conf
    • /etc/hosts & /etc/resolv.conf

    Storage & Pass-through:

    • /etc/pve/storage.cfg
    • /etc/modprobe.d/ (VFIO configs)
    • /etc/cron* and systemd unit files
    • /root/.ssh/ (authorized_keys)

    Frequently asked questions

    Can I run Proxmox Backup Server as a VM on the same cluster?

    You can for testing. In production, a backup target running inside the hypervisor it protects creates a circular failure dependency. Run PBS on dedicated bare-metal hardware, a separate mini-PC, or a remote cloud instance.

    How does PBS achieve 90%+ storage savings?

    PBS deduplicates at the block level across your entire cluster. If you run 20 Debian or Windows VMs sharing the same base OS files, those identical chunks are stored only once on the backup datastore.

    How do I implement offsite 3-2-1 backups with PBS?

    The recommended pattern has two parts: (1) a local PBS server on your LAN for high-speed nightly backups, and (2) a remote PBS instance (cloud or secondary office) that pulls synchronized snapshots through an encrypted remote sync job with prune retention.

    Want someone to review your backup architecture?

    Our storage guides cover topics from multi-terabyte ZFS pool sizing to air-gapped disaster recovery testing, or you can get in touch.