Hi!
First post on this forum. I did some search on the forum, but couldn’t really find a suting topic.
I’m planning to set up a TrueNAS Scale at home, and am also looking to secure my data physically outside of our house. I therefor imagine having a seperate TrueNAS at another location.
From the 4 different ways to backup I’ve found described, I can’t say they seem to fit my user case.
I’m concidering a RaidZ1 on the “main” NAS at home, and a RAID 0 on the external one.
But how do I transfer/backup to the external NAS?
The different solutions will dictate the firmware I’m buying/rigging.
I can just mention, I’m also contemplating an older Synology for my external backup. And just now redundancy on this one to use the capacity to a maximum - since I would be employing a level of security with RAIDZ1.
It depends on what exactly you need to backup. There are:
file data - the actual file contents
file metadata: owner, group, timestamps
access rights, permissions
For my home NAS the raw file data is enough - metadata is nice. Permissions - don’t have any.
At work the TrueNAs systems are part of an Active Directory domain. 60 active users, many acl entries. I need to backup everything. And the safest way to do so is moving zfs snapshots via a 40GBit/s fiber optics line to an identical spare server located in another building. It’s a business environment, so downtime and protection matters. And TrueNAS has ZFS snapshot replication built-in. Source and destination need not have to have the same size or Raid level, but you ned to have a TrueNAS on the other side, preferrably with the same version.
You might get away with rsync tasks. These will work with anything that has a posix filesystem, so any Linux box or a Synology or QNAP or UGreen will work - no Windows system. But you will loose some metadata and acl entries etc.
Yes, I forgot to mention. It is mostly media - movies, tv-shows, audiobooks and photos.
I have around 20 TB of this. But also a smal fraction of documents. At the moment all is on an external hard-drive, which I backup to another external hard-drive. Both via USB.
Since TrueNAS has ZFS, and if I use RAIDZ1 on the TrueNAS, with possibly some snapshots. I figured that gave some safety on the “main” NAS.
And then a figured a “mirror” of all of the data files on an external storage. And no parity or RAID else on that end. Since that would be the fail safe if the other measurements fails on the main NAS.
That’s also why I also figured a simple and older Synology would work on the external one.
I figured I almost had the 3-2-1 principle with this setup. (I just won’t use something other than spinners, no SSD’s)
I didn’t realize that there was an explanation of Rsync until after my posts. Since I read to the bottom of the page which describes backups under the documentation - which lists the other methods. But when I scrolled through again and understood that the 4th method was only explained on a completely other page, I realized that Rsync was probably the way to go.
ZFS replication is very efficient. Once the data is transferred it only transferres the changed data between snapshots and for doing this it doesnt have to painstakingly go through all folders like rsync to look for changes. It also preserves rights and permissions. So in case of a restore everything is as you left it.
Thanks!
Yes, that’s what I figured. But I want to protect the data from a complete disk failure, fire in our house, theft, etc. So I want a complete backup elsewhere as well.
That is what ZFS snapshots do. They transfer only diffs after the first complete sync. But on restore you always get a complete image back. And with ZFS snapshots you can also store different versions on a single dataset. On restore you could choose to restore the most recent snapshot or skip to a snapshot that is 3 months old if you decide that something has corrupted your NAS 2 mounts ago. And crypto ransomware can get hold of your primary files but can’t reach the snapshots.
I bought a UGREEN NASync DXP2800 for my offsite backup and installed TrueNAS CE on a NVMe drive in one of the two slots intended for that purpose. It is possible to boot from these NVMe slots if you configure the UGREEN NAS BIOS correctly.
I also added two WD Red drives for the actual backup data.
This offsite TrueNAS instance retrieves data from my primary TrueNAS instance using pull-based ZFS replication. A prerequisite is that ZFS snapshots are configured for the datasets on your primary TrueNAS instance.
I performed the initial ZFS replication on-site due to the large volume of data. After that, each subsequent replication only transfers the changed data (delta), which makes the process very efficient and fast.
The connection is secured using a site-to-site VPN (UniFi Site-to-Site VPN). There are also other options available, such as a WireGuard site-to-site VPN running in Docker on the offsite TrueNAS system.
The part nobody has covered yet is how the two boxes reach each other. TrueNAS replication runs over SSH, so the offsite NAS has to be reachable from the main one, and at a second house that normally means port forwarding on someone else’s router plus a DDNS name that follows their ISP address around.
A VPN between the two machines avoids all of that. Each box sees the other at a fixed private address, and no ports are opened at either house. Tailscale or Netrinos VPN both work for this with little setup, and plain WireGuard does too if you would rather configure it by hand. If CGNAT is involved, then forget vanilla WireGuard… I am with Netrinos.
You can setup and use Tailscale. Membes in the Tailscale network can connect to each other. It is easy to setup and Truenas even has a Tailscale app to make it easier.
There are a couple of aspects to this that haven’t been mentioned. The first is the desirability of dividing your data into different pools, or different datasets. Setting photos aside, your media probably doesn’t change much and also is not really critical. You might get away with the USB drive being its own pool for the media, backing up to the other USB drive as its own pool. Replication over a VPN, no matter how slow, will probably take a matter of seconds, and you might do it once a month.
Documents and photos are different. Those might change frequently and you may want to snapshot that daily or more often, and replicate daily. For that purpose I use a mirror at Site 1, a Z2 at a second Truenas servers at Site 1, and a mirror at Site 2. Replicating takes a minute or so.
The second thing is that 20TB can take a long time for the initial copying/replicating/anything. I have a crappy Spectrum upload of 20mbps typical in the US, and the initial load might take a year. So doing it at Site 1 as its own pool, exporting it, physically taking it to Site 2, and importing it there is a real time saver.
The third is to note that at Site 2, following replication, what you have is exactly the same thing as at Site 1 but you only want to read from it, not write to it.