cPanel Remote Incremental Backups to S3 & Wasabi (2026)

Configure automated incremental cPanel backups to S3-compatible cloud storage (Wasabi/MinIO). Optimize bandwidth throttling and disaster recovery in Pakistan.

cPanel Remote Incremental Backups to S3 & Wasabi (2026)

Storing full server backups on the local disk of your cPanel server violates the foundational rule of disaster recovery: never store your backup on the same physical failure domain as your production data. If a catastrophic hardware failure strikes (such as an unrecoverable NVMe controller death or motherboard failure), both your live websites and your local backup archives are destroyed simultaneously.

Furthermore, traditional full daily backups (tar.gz) force the server to compress gigabytes of static media every night, causing severe CPU spikes, disk I/O thrashing, and saturating uplink bandwidth.

The industry-standard solution is remote incremental backups to S3-compatible object storage (such as Wasabi Hot Cloud Storage, AWS S3, or a self-hosted MinIO cluster). With incremental synchronization, cPanel uploads only newly modified files and database dumps via multi-part S3 APIs, reducing nightly backup durations from hours to minutes.

In this operational manual, we configure S3 remote backup destinations in WHM, implement network bandwidth throttling to protect customer traffic in Pakistan, and execute bare-metal disaster recovery restores.


1. Remote Backup Topologies: Local vs. S3 Incremental

Traditional Full Backup (Heavy Overhead):
[Production SSD] ──(CPU Compress: tar.gz)──> [Local Disk] ──(100GB Upload)──> [Slow Transit]
    └── Bottlenecks: 100% CPU spike, disk thrashing, saturates datacenter uplink

Remote Incremental S3 Backup (Optimized):
[Production SSD] ──(Hardlink Metadata Check)──> [Only Modified Files] ──(S3 API)──> [Wasabi / S3]
    └── Benefits: Near-zero CPU overhead, incremental delta sync, air-gapped protection

By offloading backups to S3-compatible cloud storage like Wasabi, Pakistani hosting providers eliminate egress fees, achieve 99.999999999% (11 9’s) data durability, and maintain complete compliance with local corporate auditing standards.


2. Configuring an S3-Compatible Remote Destination in WHM

  1. Log into WHM as root.
  2. Navigate to: Backup >> Backup Configuration.
  3. Under the Global Settings tab:
    • Check Enable Backups.
    • Set Backup Type to Compressed or Incremental (Incremental requires an uncompressed local directory or direct rsync/S3 support).
  4. Navigate to the Additional Destinations tab:
    • In the Destination Type dropdown, select S3 Compatible.
    • Click Create new destination.

Configuration Parameters:

  • Destination Name: Wasabi-Disaster-Recovery
  • S3 Endpoint: s3.eu-central-1.wasabisys.com (or your regional Wasabi/AWS S3 endpoint)
  • Bucket Name: nextgen-cpanel-backups-pk
  • Access Key ID & Secret Key: Insert your secure IAM API credentials.
  • Timeout: 120 seconds.

Click Save and Validate Destination. WHM will initiate an automated TLS handshake, write a temporary test file (cpanel-test-...), read it back, and confirm validation.


3. Managing Nightly Bandwidth Throttling via cpbackup-transport

In Pakistan, where corporate internet uplinks or colocation bandwidth might be capped during peak evening traffic, scheduling an unthrottled backup transfer can saturate the network interface, causing packet loss for live website visitors.

cPanel manages remote transfers using the internal cpbackup-transport binary. You can rate-limit outbound S3 transfer speeds using Linux traffic control (tc) or by configuring I/O nice priorities on the backup process:

# 1. Inspect active backup transport processes
ps aux | grep cpbackup-transport

# 2. Lower CPU and I/O scheduling priority of backup tasks in /etc/cron.d/cpanel_backup
# Wrap the backup cron with ionice (Idle priority class) and nice:
0 2 * * * root ionice -c 3 nice -n 19 /usr/local/cpanel/bin/backup --allow-override

By assigning the Idle I/O priority (ionice -c 3), the Linux kernel guarantees that the backup daemon will only access the NVMe drive when no active web server or database process is requesting I/O.


4. Multi-Tenant Retention & Pruning Policies

Retaining daily backups indefinitely leads to astronomical storage billing. Configure a sliding-window grandfather-father-son (GFS) retention schedule in WHM:

- Daily Backups   : Retain 7 snapshots (Monday through Sunday)
- Weekly Backups  : Retain 4 snapshots (Captured every Sunday)
- Monthly Backups : Retain 3 snapshots (Captured on the 1st of each month)

WHM automatically issues DeleteObject API calls to prune expired daily snapshots from the S3 bucket after the weekly retention threshold is met.


5. Bare-Metal Disaster Recovery: Restoring an Account from S3

If a dedicated server suffers a total hardware loss, spin up a fresh server and restore client accounts directly from the remote S3 repository via SSH:

# 1. Install AWS CLI or s3cmd on the replacement server
dnf install -y awscli

# 2. Download the target cPanel backup archive from S3
aws s3 cp s3://nextgen-cpanel-backups-pk/daily/2026-10-04/accounts/usmanpk.tar.gz /home/

# 3. Restore the full account via cPanel native scripts
/scripts/restorepkg /home/usmanpk.tar.gz

The /scripts/restorepkg utility automatically:

  • Recreates the Linux user account and cPanel metadata.
  • Rebuilds virtual host configurations in Apache/LiteSpeed.
  • Restores all MySQL/MariaDB databases and grants permissions.
  • Restores mailboxes, forwarders, autoresponders, and SSL certificates.

6. Backup Solution Comparison

Metric Local Disk Backup Remote FTP/SFTP Server S3-Compatible Object Storage
Disaster Recovery Isolation Zero (Same hardware) High (Separate VM/Server) Maximum (Geographically Air-Gapped)
Durability SLA Single Drive/RAID limits Dependent on remote hardware 99.999999999% (11 9’s)
Storage Scalability Fixed to local drive size Limited by remote disk Virtually Infinite (Pay-as-you-grow)
Immutability (Ransomware Proof) No (Can be wiped by hacker) Rarely supported Yes (S3 Object Lock / WORM)

Pairing remote S3 incremental backups with cPanel PHP APCu Cache Tuning, cPanel PHP realpath_cache Tuning, and cPanel Custom ModSecurity Rules on Dedicated Servers in Pakistan provides the ultimate combination of speed, security, and ironclad resilience.

Explore our enterprise Dedicated Servers for bare-metal performance backed by redundant off-site disaster recovery.

ZERO DATA-LOSS HOSTING

Protect Your Business with Automated S3 Cloud Backups

Never fear hardware failure again. Deploy bare-metal dedicated servers in Pakistan backed by automated, immutable off-site S3 disaster recovery.