How to back up Proxmox VE virtual machines and containers
Proxmox VE backs up a VM or container with its built-in tool, vzdump: vzdump 101 --mode snapshot --storage backup-nfs --compress zstd writes one full archive of the guest's disks and configuration while it keeps running. Schedule that as a backup job, set retention with prune-backups, and restore with qmrestore (VMs) or pct restore (containers). Then get a copy off the host, to a Proxmox Backup Server or a bucket somewhere else.
What vzdump backs up
Proxmox VE is open-source virtualization software (AGPL v3), built on Debian, for KVM virtual machines and LXC containers. Each vzdump backup is a full copy of one guest, configuration and disks, in one archive named by type, ID and time: vzdump-qemu-101-2026_10_04-02_30_01.vma.zst for a VM, vzdump-lxc-102-2026_10_04-02_31_12.tar.zst for a container.
- VM disks are included unless set to
backup=0. - Containers: the root disk, plus volume mount points whose Backup option is on, never bind or device mounts.
/tmp/?*,/var/tmp/?*and/var/run/?*pidare skipped unless--stdexcludes 0.
Pick a backup mode
| Mode | Virtual machine | Container |
|---|---|---|
snapshot (default) | Copies blocks while the VM runs; with the guest agent, filesystems are frozen for a moment first. | Brief suspend while the storage snapshots the volumes, then archived from the snapshot. Needs snapshot-capable storage. |
suspend | Suspends, then a snapshot backup. Longer pause, no gain; the docs recommend snapshot. | rsync, suspend, second rsync, resume. Needs room for a copy. |
stop | Clean shutdown; the VM restarts as soon as the backup begins. Most consistent. | Stopped for the whole backup. |
A guest that isn't running is always backed up in stop mode. A VM in snapshot mode is only crash-consistent unless the QEMU guest agent runs inside it, letting Proxmox flush and freeze its filesystems. Install it in the guest (Debian, Ubuntu):
sudo apt install qemu-guest-agentEnable it on the host, stop and start the VM from Proxmox (a reboot inside the guest is not enough), and check it answers:
qm set 101 --agent enabled=1qm guest cmd 101 pingThe task log then shows issuing guest-agent 'fs-freeze' command and issuing guest-agent 'fs-thaw' command. A freeze gives clean filesystems, not database dumps: PostgreSQL and MySQL recover from it as after a crash. Also dump them inside the guest (pg_dump, mysqldump).
Add a backup storage
Backups go to a storage with the backup content type. The built-in local (/var/lib/vz/dump) sits on the host's own disks; an NFS share on another machine is better:
pvesm add nfs backup-nfs --server 10.0.0.20 --export /srv/pve-backups --content backup --prune-backups keep-daily=7,keep-weekly=4,keep-monthly=6It mounts at /mnt/pve/backup-nfs, with archives in dump/; pvesm add cifs works the same for SMB. The docs recommend a Proxmox Backup Server on its own host, with NFS as the alternative.
Back up from the command line
vzdump 101 --mode snapshot --storage backup-nfs --compress zstd| Part | What it does |
|---|---|
101 | Guest ID; list several, or --all 1 with --exclude 105,106. |
--storage backup-nfs | Target storage. Without it, the default dump directory, usually /var/lib/vz/dump. |
--compress zstd | 0 (the CLI default), gzip, lzo or zstd, the fastest. --zstd 0 uses half the cores instead of one thread. |
vzdump writes a temporary .dat file and renames it when complete, so a file with its final name is a finished backup.
Schedule backup jobs
Datacenter → Backup → Add in the web interface creates a job. Jobs live in /etc/pve/jobs.cfg, on the cluster filesystem, and the pvescheduler daemon runs them. From the shell:
pvesh create /cluster/backup --schedule "02:30" --storage backup-nfs --all 1 --mode snapshot --compress zstd --repeat-missed 1Schedules are systemd-style calendar events: 02:30 daily, sat 03:00 on Saturdays. --repeat-missed 1 runs a job missed while the host was off; by default it is skipped. List jobs with pvesh get /cluster/backup; change them in the GUI or with pvesh set.
Retention with prune-backups
keep-last, keep-hourly, keep-daily, keep-weekly, keep-monthly and keep-yearly apply in that order, each only to backups older than those already kept. Set them on the storage, as above, or per job to override it. The default, keep-all=1, deletes nothing.
Worked example: daily backups with keep-daily=7,keep-weekly=4,keep-monthly=6 keep at most 17 per guest: 7 daily, then 4 weekly, then 6 monthly, reaching about 7 months back. At 20 GB per compressed backup, that is up to 340 GB for one VM on a file storage. Preview what a policy deletes:
pvesm prune-backups backup-nfs --vmid 101 --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --dry-run 1A protected backup (--protected 1) is never pruned, but only Proxmox enforces that: anyone who can write to the storage can still delete the file.
Restore a VM or a container
qmrestore /mnt/pve/backup-nfs/dump/vzdump-qemu-101-2026_10_04-02_30_01.vma.zst 101 --storage local-lvmpct restore 102 /mnt/pve/backup-nfs/dump/vzdump-lxc-102-2026_10_04-02_31_12.tar.zst --storage local-lvm--storagepicks where disks go; by default, the original storage.- A taken ID stops the restore;
--force 1overwrites that guest. - From PBS, pass the volume ID from
pvesm list pbs-main --vmid 101instead of a path. --live-restore 1(PBS only) starts the VM at once and copies data in the background; if it fails, the VM is left in an undefined state.- A vzdump file restores on another Proxmox VE host the same way.
In the web interface, select the backup in the storage's backup list and click Restore. PBS backups also have File Restore, which browses an archive and downloads single files; from file-storage backups, restore to a spare ID and copy files out.
Proxmox Backup Server
Proxmox Backup Server (PBS) is a separate server, also free and open source (AGPL v3). Add its datastore as a storage and jobs target it like any other:
pvesm add pbs pbs-main --server 10.0.0.30 --datastore main --username backup@pbs --fingerprint <fingerprint> --encryption-key autogen --password- Deduplication. VM disks are split into 4 MiB chunks, containers into variable ones, each stored once. VMs can use dirty bitmaps to send only changed chunks; every backup still restores in full.
- Verify jobs recheck chunks against their SHA-256 checksums. The docs advise a frequent job for new backups and a monthly full reverify.
- Garbage collection frees chunks that pruned backups no longer use; start with weekly.
- Encryption.
--encryption-key autogencreates a client-side AES-256-GCM key at /etc/pve/priv/storage/pbs-main.enc. Without that key the backups can't be read, and a key kept only on the host dies with it.
Print a paper copy (text and QR code) for a safe, and keep one in a password manager:
proxmox-backup-client key paperkey /etc/pve/priv/storage/pbs-main.enc --output-format text > qrkey.txtGet a copy off the host
Backups on local die with the host's disks; an NFS server in the same rack shares the building. The 3-2-1 rule wants a copy elsewhere. With PBS, run a second PBS at another site that pulls: on it, add the main server as a remote, then a sync job:
proxmox-backup-manager remote create pbs-main --host pbs-main.example.com --userid sync@pbs --password 'SECRET' --fingerprint <fingerprint>proxmox-backup-manager sync-job create pull-main --remote pbs-main --remote-store main --store offsite --schedule '04:00'Only new chunks cross the network, and pulling leaves the main site with no login that can delete the off-site copies. Leave remove-vanished off, or deletions on the main server follow; prune off-site with its own policy. --encrypted-only and --verified-only restrict what is synced. Current PBS releases can also keep a datastore in an S3-compatible bucket, with a local cache disk.
Without PBS, upload each archive as it finishes with a vzdump hook script and rclone (remote offsite, set up as that guide shows):
#!/bin/bash
# vzdump hook: copy each finished backup archive to the bucket.
# vzdump runs hooks with an almost empty environment, so set PATH here.
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
if [ "$1" = "backup-end" ] && [ -n "${TARGET:-}" ]; then
rclone copyto "$TARGET" "offsite:my-bucket/pve-01/${TARGET##*/}" \
--config /root/.config/rclone/rclone.conf || exit 1
fi
exit 0- vzdump runs the script at every phase, phase name first;
TARGET, the finished archive, is set only inbackup-end. File storages only. - A non-zero exit fails that guest's backup, so a failed upload reaches the job's notification.
chmod 700it, then addscript: /usr/local/bin/vzdump-offsiteto /etc/vzdump.conf (every backup on the node) or runpvesh set /cluster/backup/<job-id> --script /usr/local/bin/vzdump-offsite(one job).- copyto never deletes: prune the bucket with a lifecycle rule or from cron, such as
rclone delete offsite:my-bucket/pve-01 --min-age 60d --config /root/.config/rclone/rclone.conf.
Back up the host's own configuration
Guest backups don't include the host: storages, users, permissions, firewall, backup jobs, network. /etc/pve is pmxcfs, a FUSE view of the SQLite database /var/lib/pve-cluster/config.db, replicated to every cluster node. Archive both, plus the network and name files:
tar -czf /root/pve-host-$(hostname)-$(date +%F).tar.gz /etc/pve /var/lib/pve-cluster/config.db /etc/network/interfaces /etc/hosts /etc/hostname /etc/vzdump.confThe docs' recovery: on a fresh host with nothing running, stop pve-cluster, put config.db in place (mode 0600), set /etc/hostname and /etc/hosts as on the lost host, reboot. The archive holds /etc/pve/priv (storage passwords, API token secrets, PBS keys), so encrypt it and keep it off the host.
Test a restore to a new VMID
Restore under a spare ID with a new MAC address, cut its network link so it can't take the original's IP, and start it:
qmrestore /mnt/pve/backup-nfs/dump/vzdump-qemu-101-2026_10_04-02_30_01.vma.zst 9101 --storage local-lvm --unique 1qm set 9101 --net0 virtio,bridge=vmbr0,link_down=1qm start 9101On the console, check that services start and data is recent, note how long it took, then qm destroy 9101. Containers: pct restore 9102 <archive> --storage local-lvm --unique 1, pct set 9102 --net0 name=eth0,bridge=vmbr0,link_down=1, pct start 9102. See testing a backup restore.
Common errors and log lines
| Message | Cause | Fix |
|---|---|---|
skipping guest filesystem freeze - agent configured but not running? | The agent option is on, but the service isn't running in the guest. | Install and start qemu-guest-agent, then stop and start the VM. |
skipping guest filesystem freeze - disabled in VM options | Agent disabled, or its freeze option turned off. | qm set 101 --agent enabled=1. |
mode failure - some volumes do not support snapshots, then trying 'suspend' mode instead | A container volume is on storage without snapshots. | Move it to storage with snapshots, exclude that mount point, or accept suspend mode. |
VM is locked (backup) or CT is locked (backup) | A backup is running, or a crashed one left its lock. | Wait. If no backup task is running, qm unlock 101 or pct unlock 102. |
Error: The hook script '/usr/local/bin/vzdump-offsite' is not executable. | Missing execute bit. | chmod 700 the script. |
Frequently asked questions
- Can Proxmox back up a VM while it is running?
- Yes. Snapshot mode, the default, copies a running VM's disks without shutting it down. Install the QEMU guest agent so the guest's filesystems are frozen and clean in the backup.
- Where does Proxmox store backups?
- On the storage you choose. The
localstorage uses /var/lib/vz/dump; an NFS or CIFS storage uses thedumpdirectory under/mnt/pve/<storage>. - Are Proxmox backups incremental?
- On directory, NFS and CIFS storages every backup is a full archive. On Proxmox Backup Server only changed chunks are sent and stored, but each backup still restores as a full one.
- Is Proxmox Backup Server free?
- Yes. It is open source under the AGPL v3 with no limits on storage or clients. Paid subscriptions add the enterprise repository and support.
How this was checked
Commands, limits and prices were checked against these official pages, on October 4, 2026:
- Proxmox VE documentation: Backup and Restore
- Proxmox VE: vzdump(1)
- Proxmox VE: qmrestore(1)
- Proxmox VE: pct(1)
- Proxmox VE: qm(1)
- Proxmox VE: pvesm(1)
- Proxmox VE: Proxmox Cluster File System (pmxcfs)
- Proxmox VE Administration Guide: QEMU Guest Agent, storage backends, pvescheduler, calendar events
- Proxmox VE API viewer: /cluster/backup
- pve-manager source: example vzdump hook script
- pve-manager source: PVE/VZDump.pm (hook environment, mode fallback)
- qemu-server source: guest agent freeze messages
- pve-guest-common source: guest lock message
- Proxmox Backup Server documentation: Introduction
- Proxmox Backup Server: Technical Overview
- Proxmox Backup Server: Maintenance Tasks
- Proxmox Backup Server: Managing Remotes & Sync
- Proxmox Backup Server: Backup Storage (S3 backend)
- Proxmox Backup Server: FAQ
- rclone copyto
- rclone delete