Skip to content

Self-host Kopia

updated Sep 2026prices checked · Jul 2026Install verified on Ubuntu 26.04 · Sep 2026 · how we test
We earn commissions when you shop through the links below. Full disclosure →

A backup tool with a CLI, a desktop GUI (KopiaUI) and a server mode with a web UI: encrypted, deduplicated snapshots with per-path policies for retention, scheduling and compression (zstd, s2, pgzip; off by default), stored on S3-compatible storage, B2, Azure, Google Cloud, SFTP, WebDAV, rclone or a local disk. Repository maintenance runs automatically, and a repository server can take backups from many machines, each user seeing only its own snapshots.

Key facts

CategoryBackup
LicenseApache-2.0
StackGo
Min RAM512 MB
Official imageyes
Measured idle RAM7 MB
Difficulty
Our recommendation

Pick Kopia when you want the backup tool to do the bookkeeping: per-path policies for retention, scheduling and compression, automatic quick (hourly) and full (daily) maintenance, and a GUI, either the KopiaUI desktop app or the web UI of `kopia server`. It is Apache-2.0, encrypts everything with AES-256-GCM or ChaCha20-Poly1305, and writes to S3-compatible storage, B2, Azure, Google Cloud, SFTP, WebDAV, rclone or a local disk. Its repository server lets many machines back up through per-user logins without ever holding the storage credentials. If you would rather drive a plain binary from cron with the policy spelled out as flags, restic is the simpler fit.

What you need

  • Any VPS with at least 512 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • Under an hour if you've used Docker before
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# Kopia — official kopia/kopia image in server mode with the web UI, after kopia.io/docs/installation (Docker Images)
mkdir -p ~/kopia/config ~/kopia/cache ~/kopia/logs && cd ~/kopia
printf 'UI_PASSWORD=%s\nREPO_PASSWORD=%s\n' "$(openssl rand -hex 16)" "$(openssl rand -hex 24)" > .env && chmod 600 .env
cat > compose.yaml <<'EOF'
services:
  kopia:
    image: kopia/kopia:0.23.1
    hostname: backup-host
    restart: unless-stopped
    ports: ["127.0.0.1:51515:51515"]
    command: [server, start, --insecure, --address=0.0.0.0:51515, --server-username=admin, "--server-password=${UI_PASSWORD}"]
    environment: { KOPIA_PASSWORD: "${REPO_PASSWORD}", USER: admin }
    volumes: [./config:/app/config, ./cache:/app/cache, ./logs:/app/logs, /srv:/data:ro]
EOF
docker compose up -d
# UI: ssh -L 51515:127.0.0.1:51515 user@SERVER_IP, open http://localhost:51515, log in as admin / UI_PASSWORD,
# then create the repository (S3, B2, SFTP...) with REPO_PASSWORD from .env so the container can reopen it after a restart
# --insecure means no TLS: keep it on loopback. Remote kopia clients need a TLS server (see the Repository Server docs)

What you take on

Kopia takes on more for you, and four things in its docs matter before you trust it with a VPS:

non-negotiableCompression is off by default. Kopia's FAQ says it is "disabled by default" and set per policy. Run kopia policy set --global --compression=zstd (or set it in the UI) before the first snapshot, because a change only applies to data uploaded afterwards.
non-negotiableOne password per repository, and no recovery: the docs say there is "no way to recover a forgotten password". In the Docker image the password comes from KOPIA_PASSWORD, so keep it in a root-only .env and back that value up somewhere other than this server.
non-negotiable--insecure in the web-UI example means plain HTTP, so bind the UI to loopback and reach it over an SSH tunnel. Remote Kopia clients need a TLS server: the Repository Server docs say --insecure does not work because gRPC needs TLS, and a reverse proxy has to use grpc_pass.
non-negotiableFull maintenance is deliberately slow to delete. It relies on time passing so that concurrent clients stay consistent, and upstream says freeing space "may take several hours and/or multiple maintenance cycles". Only one user@hostname, the maintenance owner, runs it. The 512 MB RAM floor is our estimate; Kopia publishes none, and its FAQ names compression and parallelism as the main causes of high memory use.

Head-to-head

More self-hosted tools

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.