Announcing the Magic Pages Open House. Quarterly calls with our team!

Skip to the answer

Off-site backups to an SFTP server

Sending your backups to a server you run, over SFTP. What to fill in, the access the user needs, and what the common connection errors mean.

Jannis Fedoruk-Betschki Jannis Fedoruk-Betschki

If you have a server, a NAS or a storage box that accepts SFTP logins, your backups can go there. This article covers what to fill in, what the login needs to be allowed to do, and what the common errors mean.

If you haven't read it yet, Off-site backups to your own storage explains what gets sent and how many copies are kept.

Before you start

  • It has to be SFTP, the file transfer that runs over SSH. Plain FTP and FTPS don't work.
  • The server has to be reachable from the internet, by a public hostname or IP address. Addresses inside a private network, like 192.168.… or 10.…, are refused.
  • Make a separate user for this, with access to the backup folder and nothing else.

Filling in the form

In the Off-Site Backups tab, click Configure Destination (or Edit Configuration), pick SFTP Server, and fill in:

  • Host: the server's hostname or IP address, without sftp://.
  • Port: usually 22.
  • Username.
  • Authentication: a password, or a private key. For a key, paste the whole thing, including the -----BEGIN … and -----END … lines. If the key has a passphrase, enter it under Passphrase.
  • Remote Path: the folder for the backups, for example /backups/ghost. If it doesn't exist yet, we create it.
  • Backup retention (days): how many copies of each backup to keep. 0 keeps all of them.

Then click Test Connection, and Save once it passes.

For key logins, make a key pair just for this, and add the public half to the user's ~/.ssh/authorized_keys on your server.

What the user needs to be allowed to do

The connection test logs in, creates the folder if needed, writes a small file called .magic-pages-connection-test-…, checks that it's there, and deletes it.

Every copy after that:

  • uploads each file under a temporary name ending in .partial, and renames it when the upload is complete, so you never find a half-written backup under the real name,
  • lists the folder and deletes your site's oldest backups, unless retention is 0.

So the user needs to be able to create folders, write, rename and delete files in the remote path. A chroot or a jailed user is fine, as long as the path you enter is the path the user sees after logging in.

When the test fails

The message starts with "Failed to connect to SFTP server host:port", followed by the reason the server gave. The common ones:

  • Timed out, or connection refused: the host or port is wrong, or a firewall is blocking us. If your server only lets in specific IP addresses, email us and we'll tell you which ones to allow.
  • All configured authentication methods failed: wrong password, or the server doesn't accept the key. Check that the public key is in authorized_keys for this user, and that the server allows password logins if you're using one.
  • Cannot parse privateKey, or a message about the passphrase: the key wasn't pasted in full, or the passphrase is wrong.
  • Permission denied: the login works, but the user can't create the folder or write to it.

"SFTP connection rejected: host resolves to blocked address" means the hostname points at a private network address. It has to be one we can reach over the internet.

If none of that fits, email help@magicpages.co with the host and port. Never send the password or the private key.

More in this section

Jannis, founder of Magic Pages

Didn't find your answer?

Ask us anything — a real person reads every message, usually the same day.

Email support