Backblaze B2
Backblaze B2 is inexpensive and works through its S3-compatible endpoint.
1. Set up the storage
- Sign in to Backblaze and open B2 Cloud Storage.
- Create a Bucket - set it Private. Create it now, before the key: a key restricted to one bucket has no permission to create buckets, so the bucket has to exist first.
- Open Application Keys > Add a New Application Key. Restrict it to the bucket you just made, with read and write access.
- Copy the keyID and the applicationKey (shown once).
- Note the bucket’s S3 endpoint, shown on the bucket details - for example
s3.us-west-004.backblazeb2.com.
2. Connect it in Nyx Backup
New backup set > destination Backblaze B2, then enter:
- Bucket - the bucket name. If your key is restricted to a single bucket, this must be that bucket, spelled exactly as B2 shows it. Nyx Backup checks this and refuses a mismatch, naming both buckets so you can see which is which.
- Key ID and Application key - from step 4.
- Endpoint / Region - use the bucket’s S3 endpoint or region from step 5 if prompted.
Once Test connection succeeds, set a schedule and retention, save the set, and choose Run now. Nyx Backup encrypts everything on your machine before upload, so this destination only ever holds encrypted blobs. Give each machine its own bucket or folder - see Connecting storage.
Tip: create a key scoped to the single bucket rather than a master application key. A scoped key limits what a leaked credential can reach, and B2 shows the master key’s secret only once at account creation - if you no longer have it, make a new application key rather than trying to recover it.
One thing to get right: a bucket-restricted key can only ever reach its own bucket. That is the point of it, but it means the bucket name in Nyx Backup and the bucket the key is scoped to must be the same. If you plan to keep several buckets, use a separate key for each and pair each key with its own backup set.