Setting up Backups#
Setting up backups takes three steps: prepare a destination, add it to SynergyCP as a Backup Destination, and run a first backup to confirm everything works.
Four destination types are supported:
- Secure Copy via SSH — any Linux server or NAS that SynergyCP can reach over SSH.
- Backblaze B2 — a Backblaze B2 cloud storage bucket (requires package version 2.2.0 or later).
- Cloudflare R2 — a Cloudflare R2 cloud storage bucket (requires package version 2.3.0 or later).
- Google Drive — a folder in a Google account’s Drive (requires package version 2.5.0 or later). Setup is more involved than the other types.
The destination form in SynergyCP links straight to the matching section of this page for whichever destination type you select.
Secure Copy via SSH#
1. Prepare the destination server#
Any Linux server (or NAS with SSH access) that SynergyCP can reach over the network will work.
-
Create a standard user on the destination server. We will use
backupsas an example — any username works. -
In SynergyCP, go to System > SSH Keys and generate an SSH key if you have not already. Copy the public key.
-
On the destination server, add the public key to the user’s
~/.ssh/authorized_keysfile:mkdir -p ~/.ssh chmod 700 ~/.ssh echo '<paste the public key here>' >> ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys -
Create a directory for the backups and make sure the user can write to it. We will use
/home/backups/scp-dbas an example.
SynergyCP only ever authenticates with its SSH key — it will never try a password. If key authentication fails, the backup fails immediately instead of hanging on a password prompt.
2. Add the destination in SynergyCP#
Go to System > Backup Destinations and create a new destination:
| Field | Value |
|---|---|
| Name | A label of your choice, e.g. Off-site NAS. |
| Handler | Secure Copy (SSH). |
| Host | The destination server’s hostname or IP address. |
| User | The user you created, e.g. backups. |
| Folder | The directory you created, e.g. /home/backups/scp-db. |
| Backups to keep | Optional — see retention. Leave empty to keep everything. |
The Host field accepts several formats:
backups.example.org— hostname or IPv4 address, default port 22backups.example.org:2222— custom SSH port2001:db8::1— bare IPv6 address, default port 22[2001:db8::1]:2222— IPv6 address with a custom port
The Folder may be an absolute path (/home/backups/scp-db) or relative to the user’s home directory (scp-db). Missing folders are created automatically on the first backup, as long as the user has permission to create them.
On the first connection, SynergyCP records the destination server’s SSH host key and refuses to connect if it ever changes. If you rebuild the destination server later, see Troubleshooting.
Backblaze B2#
1. Prepare the bucket and application key#
- In your Backblaze account, create a private bucket for the backups, e.g.
scp-backups. - Under Application Keys, create a new application key:
- Allow access to: the bucket you just created (recommended — the key then cannot touch anything else on your account).
- Type of access: Read and Write.
- Leave “Allow List All Bucket Names” and file name prefix restrictions off.
- Note the keyID and applicationKey shown after creation — the applicationKey is only displayed once.
2. Add the destination in SynergyCP#
Go to System > Backup Destinations and create a new destination with the Backblaze B2 handler:
| Field | Value |
|---|---|
| Name | A label of your choice, e.g. Backblaze B2. |
| Handler | Backblaze B2. |
| key_id | The application key’s keyID. |
| application_key | The applicationKey secret. |
| bucket | The bucket name, e.g. scp-backups. |
| folder | A path prefix inside the bucket, e.g. panel1 — or / for the bucket root. |
The key_id and application_key are stored encrypted with your panel’s secret key, the same way other sensitive credentials in SynergyCP are protected.
A single backup file can be at most 5 GB (Backblaze’s single-file upload limit) — far beyond a typical compressed database backup. If your backups approach that size, use a Secure Copy destination instead and contact support.
Cloudflare R2#
1. Prepare the bucket and API token#
- In the Cloudflare dashboard, go to R2 and create a bucket for the backups, e.g.
scp-backups. - Under R2 > Manage API Tokens, create an API token:
- Permissions: Object Read & Write.
- Specify bucket(s): the bucket you just created (recommended).
- Note the Access Key ID and Secret Access Key shown after creation — the secret is only displayed once.
- Note your Account ID (shown on the R2 overview page and in the S3 endpoint,
https://<account id>.r2.cloudflarestorage.com).
2. Add the destination in SynergyCP#
Go to System > Backup Destinations and create a new destination with the Cloudflare R2 handler:
| Field | Value |
|---|---|
| Name | A label of your choice, e.g. Cloudflare R2. |
| Handler | Cloudflare R2. |
| account_id | Your Cloudflare account ID. |
| access_key_id | The API token’s Access Key ID. |
| secret_access_key | The API token’s Secret Access Key. |
| bucket | The bucket name, e.g. scp-backups. |
| folder | A path prefix inside the bucket, e.g. panel1 — or / for the bucket root. |
The access_key_id and secret_access_key are stored encrypted with your panel’s secret key, the same way other sensitive credentials in SynergyCP are protected.
A single backup file can be at most 5 GB (the single-request upload limit) — far beyond a typical compressed database backup. If your backups approach that size, use a Secure Copy destination instead and contact support.
Google Drive#
Google Drive support stores backups in a folder of a Google account’s Drive. It works with both personal Google accounts and Google Workspace accounts.
Google only allows software to access a Drive through an OAuth client registered in the Google Cloud Console. SynergyCP does not ship a shared client; you create one in your own Google Cloud account, so no third party ever sits between your panel and your Drive. This makes the setup longer than the other destination types — plan for about 15 minutes, and follow the steps in order.
Skipping the Publish app step below is the most common mistake. If the OAuth app stays in Testing, Google silently expires the sign-in after seven days and every backup after that fails until you reconnect.
1. Create a Google Cloud project#
- Go to the Google Cloud Console and sign in. Any Google account can own the project — it does not have to be the account that will hold the backups.
- Open the project selector at the top of the page and click New project. Name it, e.g.
SynergyCP Backups, and click Create. Make sure the new project is selected before continuing. - In the left menu, go to APIs & Services > Library, search for Google Drive API, open it, and click Enable.
2. Configure the OAuth consent screen#
-
Go to APIs & Services > OAuth consent screen (Google also labels this area Google Auth Platform). If prompted, click Get started.
-
Fill in the app information:
- App name: e.g.
SynergyCP Backups— this name is shown when you sign in later. - User support email: your email address.
- Audience (or User type): External. (Choose Internal only if you use Google Workspace and the account holding the backups belongs to your organization — Internal apps skip the publishing step below.)
- Developer contact information: your email address.
- App name: e.g.
-
Agree to the policies and click Create (or Save and continue through the remaining pages). You do not need to add any scopes or test users — the panel asks only for permission to manage the files it creates itself.
-
Publish the app. Under Audience (older layout: at the bottom of the consent screen page), the Publishing status reads Testing. Click Publish app and confirm.
Google may mention that verification is required for some scopes. It is not needed here: the panel uses only the non-sensitive
drive.filescope, which lets it see and manage files it created and nothing else in the Drive. You can ignore the verification prompt.
3. Create the OAuth client#
- Go to APIs & Services > Credentials (or Google Auth Platform > Clients).
- Click Create credentials > OAuth client ID (or Create client).
- Application type: TVs and Limited Input devices. This type is required — it is what lets SynergyCP connect without a public callback address. Other types will not work.
- Name: e.g.
SynergyCP panel. Click Create. - Copy the Client ID and Client secret shown. You can come back to them later under Credentials.
4. Add the destination in SynergyCP#
Go to System > Backup Destinations and create a new destination with the Google Drive handler:
| Field | Value |
|---|---|
| Name | A label of your choice, e.g. Google Drive. |
| Handler | Google Drive. |
| client_id | The OAuth client’s Client ID (ends in .apps.googleusercontent.com). |
| client_secret | The OAuth client’s Client secret. |
| folder | The name of the folder to keep backups in, e.g. SynergyCP Backups. The panel creates it in the connected account’s My Drive on the first backup. |
| Google account | Connected through the sign-in below. |
| Backups to keep | Recommended — see retention. Backups count against the Google account’s storage quota (15 GB on a free account). |
The panel can only see folders it created itself, so it will not reuse an existing folder that happens to have the same name. Change the folder name on the destination if you want a fresh folder.
Then connect the Google account:
-
With the client_id and client_secret filled in, click Connect Google account. The form shows a web address and a short code such as
ABCD-EFGH. -
Open the address (normally google.com/device) in any browser, on any device.
-
Sign in to the Google account whose Drive should hold the backups. It can be any Google account; it does not need to own the Cloud project.
-
Enter the code and click Next, then Allow when asked to let the app see, edit, create and delete only the specific Google Drive files you use with this app.
If Google shows a Google hasn’t verified this app warning, the app is the one you created in step 2 — click Advanced, then Go to … (unsafe) to continue. The warning does not appear for correctly published apps that use only the
drive.filescope. -
Back in SynergyCP, the form changes to Connected within a few seconds. The code is valid for about 30 minutes; if it expires, click Connect Google account again for a new one.
-
Save the destination. The connection is only stored when the destination is saved.
The client_secret and the Google sign-in token are stored encrypted with your panel’s secret key, the same way other sensitive credentials in SynergyCP are protected. To revoke the panel’s access at any time, remove the app under Third-party apps & services in the Google account.
Google occasionally invalidates the sign-in — for example if the Google account’s password is changed, if the connection goes unused for six months, or if the consent screen is still in Testing. Backups then fail with an authorization failed error until you edit the destination and click Reconnect. Keep an eye on the backup health indicator.
Run a test backup#
- Go to System > Backups and click View All Backups in the Latest Backup box.
- At the bottom of the page, select Main Database as the Source and your new destination as the Destination.
- Click Create archive and refresh the list after a minute (longer for large installations).
When the backup shows Finished, verify the file arrived. For an SSH destination:
ls -lh /home/backups/scp-db
# main-database.1.gz.encThe file is encrypted with your panel’s secret key, so it cannot be inspected with gunzip directly — see Restoring from a Backup for how it is decrypted.
For a Backblaze B2 or Cloudflare R2 destination, open the bucket in the provider’s web console and confirm the file is listed under your folder prefix.
For a Google Drive destination, open drive.google.com signed in as the connected account and look for the folder named on the destination (the panel creates it on the first backup) in My Drive.
If the backup shows Failed, click into it to see the error, and consult Troubleshooting.
Once the test backup succeeds, set up a recurring backup so backups run automatically.
Also make a one-time configuration backup and store it in a separate, secure location (for example your password manager). Without it, database backups cannot be fully restored.