How to use Vultr Object Storage for server backups
Vultr Object Storage is S3-compatible storage sold as subscriptions: as of October 2026, the Standard tier is $18.00 a month and includes 1,000 GB of storage and 1,000 GB of outbound transfer. Each subscription sits in one location with an endpoint such as https://ewr1.vultrobjects.com and has a single access key that reaches every bucket in it, so the subscription is your unit of isolation. Create one in a location away from your servers, upload with the AWS CLI or s3cmd, and expire old backups with a lifecycle rule.
Choose a tier
A subscription keeps its tier for good; to change it, Vultr says to create a new subscription and move the buckets. As of October 2026, Vultr's billing docs list:
| Tier | Storage | Per month | Extra storage |
|---|---|---|---|
| Standard | HDD, indexed on SSD | $18.00 | $0.018 per GB |
| Premium | HDD, indexed on SSD | $36.00 | $0.036 per GB |
| Performance | NVMe | $50.00 | $0.050 per GB |
| Accelerated | NVMe | $100.00 | $0.100 per GB |
Every tier includes 1,000 GB of storage and 1,000 GB of outbound transfer a month; inbound is free and extra outbound is $0.01 per GB. Faster tiers buy operations per second and throughput, mostly for Vultr servers in the same data center. A few large backup files a night need only Standard.
Archive is a fifth tier: $6 a month for 1,000 GB archived, 100 GB unarchived and 1 TB of transfer. Its lifecycle policy, which you can't change, moves objects to archive, where they show as 0 bytes and larger ones need a restore request before download. It suits archives kept for months, not tonight's restore.
Pick a location and its endpoint
A subscription lives in one location, and its hostname is the S3 endpoint for all its buckets. Vultr's FAQ lists:
| Location | Endpoint |
|---|---|
| Amsterdam | ams1.vultrobjects.com, ams2.vultrobjects.com |
| Atlanta | atl1.vultrobjects.com, atl2.vultrobjects.com |
| Bangalore | blr1.vultrobjects.com, blr2.vultrobjects.com |
| Chicago | chi3.vultrobjects.com |
| London | lhr1.vultrobjects.com |
| Los Angeles | lax1.vultrobjects.com |
| New Delhi | del1.vultrobjects.com |
| New Jersey | ewr1.vultrobjects.com, ewr2.vultrobjects.com |
| Seattle | sea1.vultrobjects.com |
| Silicon Valley | sjc1.vultrobjects.com |
| Singapore | sgp1.vultrobjects.com, sgp2.vultrobjects.com |
| Sydney | syd1.vultrobjects.com |
| Tokyo | nrt1.vultrobjects.com |
Where a location has two hostnames, use the one your subscription shows. Keep backups in a different location from the servers they protect. The examples use a Standard subscription in New Jersey, ewr1.vultrobjects.com, and a bucket named acme-backups.
Create the subscription and a bucket
- In the Vultr Console, go to Products, click Cloud Storage, select Object Storage and click Create Object Storage.
- Select the tier, enter a name, select the location and click Create Object Storage.
- Open the subscription, go to Buckets and click Create Bucket.
- Enter a name of 3 to 63 characters, unique across all of Vultr Object Storage; 53 or fewer if you might enable Archival Storage on it.
- Set Bucket Versioning and Object Lock, covered below, and click Create Bucket.
Uploads are private by default. Never add --acl public-read (AWS CLI) or -P (s3cmd) to a backup upload.
One key for the whole subscription
The subscription's Overview shows its S3 Credentials: hostname, access key and secret key. vultr-cli object-storage list and the API's s3_access_key and s3_secret_key fields return the same pair.
Vultr scopes keys to the subscription, and its docs show one pair per subscription. That pair can read, write and delete every bucket in it, change lifecycle rules and delete buckets; Vultr documents no per-bucket or read-only keys. Every server you give it can delete every backup in the subscription.
So isolate by subscription: servers that shouldn't reach each other's backups get separate ones, each $18.00 a month at Standard with its own 1,000 GB. If a key leaks, Vultr's advice is to regenerate it at once, with Regenerate Keys or vultr-cli object-storage regenerate-keys <id>, and every server using it then needs the new pair. Since the server's key can delete, keep a copy it can't reach; see protecting backups from ransomware.
Configure the AWS CLI
[profile vultr]
region = us-east-1
endpoint_url = https://ewr1.vultrobjects.com
retry_mode = standard
max_attempts = 5[vultr]
aws_access_key_id = <access_key>
aws_secret_access_key = <secret_key>endpoint_urlis the subscription's hostname withhttps://, which Vultr requires.- Vultr ignores the region; its Terraform guide uses
us-east-1. - Vultr returns
429when a subscription exceeds its tier's request rate and asks clients to back off.retry_mode = standardretries throttling error codes such asSlowDown, timeouts, and HTTP 500, 502, 503 and 504, with exponential backoff, andmax_attempts = 5allows five attempts instead of three. A bare HTTP 429 is on the AWS CLI's documented list forretry_mode = legacy, not standard: if the CLI gives up on Vultr's 429s, switch to legacy.
Run chmod 600 on both files, then list the bucket. No output means it's empty and the key works:
aws s3 ls s3://acme-backups/ --profile vultrOr use s3cmd
Vultr's guides use s3cmd 2.0.0 or later, and so do its lifecycle examples. Keep Vultr's settings in their own file:
s3cmd --configure -c ~/.s3cfg-vultr- Access Key and Secret Key: the subscription's pair. Default Region: keep
US; Vultr ignores it. - S3 Endpoint:
ewr1.vultrobjects.com. DNS-style bucket+hostname:port template:%(bucket)s.ewr1.vultrobjects.com. - Encryption password: optional; only uploads with
-euse it, encrypting the file with GPG first. Use HTTPS protocol:Yes.
s3cmd -c ~/.s3cfg-vultr put /var/backups/web-01-2026-10-04.tar.gz s3://acme-backups/web-01/-c picks the Vultr config file, and the trailing slash keeps the file's name. For many files at once, Vultr suggests s5cmd, which runs transfers in parallel.
Upload backups on a schedule
Name each backup by date, keep each server under its own prefix, and store a checksum beside it. This script archives two directories with tar and uploads both files:
#!/bin/sh
set -eu
NAME="web-01-$(date +%F).tar.gz"
cd /var/backups
tar -czf "$NAME" /etc /var/www
sha256sum "$NAME" > "$NAME.sha256"
for f in "$NAME" "$NAME.sha256"; do
aws s3 cp "$f" "s3://acme-backups/web-01/$f" --profile vultr --only-show-errors
done
rm "$NAME" "$NAME.sha256"set -eu stops at the first error, so a failed upload never reaches the rm. Make it executable with chmod 700 and schedule it:
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
30 3 * * * root /usr/local/bin/vultr-backup.shThe PATH line lets cron find aws in /usr/local/bin; see scheduling backups with cron. rclone works too, with provider = Other and the same endpoint, as in Vultr's migration guide.
Expire old backups with a lifecycle rule
Vultr documents lifecycle rules in S3's XML format, applied with s3cmd. This one deletes backups under web-01/ 30 days after upload:
<LifecycleConfiguration>
<Rule>
<ID>expire-web-01</ID>
<Filter><Prefix>web-01/</Prefix></Filter>
<Status>Enabled</Status>
<Expiration><Days>30</Days></Expiration>
</Rule>
</LifecycleConfiguration>s3cmd -c ~/.s3cfg-vultr setlifecycle lifecycle.xml s3://acme-backupsFilterwithPrefixlimits the rule to one server's backups. Put aRuleper prefix in one file: as on S3, a new configuration replaces the old one.Expirationdeletes each object 30 days after it was created. Vultr's limits page says lifecycle policies run daily at 00:00 UTC, so a backup can outlive that by up to a day.s3cmd -c ~/.s3cfg-vultr getlifecycle s3://acme-backupsreads the rule back.
Vultr documents expiration, but not rules that remove older versions or unfinished multipart uploads. On S3, expiring an object in a versioned bucket only adds a delete marker and keeps the data as a billed older version. Leave versioning off on a bucket pruned this way, or check aws s3api list-object-versions after the first month.
Versioning and Object Lock
The bucket form has Bucket Versioning and Object Lock switches, and the API's bucket call takes enable_bucket_versioning and enable_object_lock. As of October 2026 Vultr's docs stop there: they don't describe retention modes or default retention, Object Lock isn't on the S3 compatibility list, and a bucket that has ever had versioning can never use Archival Storage.
With one key doing everything, versioning guards against mistakes, not against whoever holds the key, who can delete old versions too. Object Lock in compliance mode is what could stop that key, so test it on a throwaway bucket created with the switch on before relying on it:
aws s3api get-object-lock-configuration --bucket acme-lock-test --profile vultrIf it reports "ObjectLockEnabled": "Enabled", set a 1-day default retention with aws s3api put-object-lock-configuration, upload a file, find its version ID with aws s3api list-object-versions, and run aws s3api delete-object with that --version-id. Only an AccessDenied shows the lock holds.
Verify a backup
aws s3 ls s3://acme-backups/web-01/ --recursive --human-readable --summarize --profile vultr--summarize adds the object count and total size. To prove a backup restores, download it with its checksum file and check both:
mkdir -p /tmp/restore-test && cd /tmp/restore-test && aws s3 cp s3://acme-backups/web-01/ . --recursive --exclude "*" --include "web-01-2026-10-04.tar.gz*" --profile vultrsha256sum -c web-01-2026-10-04.tar.gz.sha256 && tar -tzf web-01-2026-10-04.tar.gz > /dev/null && echo OKTrust your own checksum over response headers: Vultr notes that a download's Content-Length can differ from the file's size because responses are gzip-compressed, and that a multipart upload's ETag isn't an MD5 of the file. Then extract the archive, as in testing a restore.
What it costs
From the October 2026 prices above, per subscription and month:
| Usage | Working | Cost |
|---|---|---|
| Standard, 600 GB stored, 50 GB restored | Inside the included 1,000 GB of each | $18.00 |
| Standard, 2,500 GB stored | $18.00 + 1,500 GB × $0.018 | $45.00 |
| The same, plus a 1,500 GB restore | $45.00 + 500 GB × $0.01 | $50.00 |
| Three servers, a Standard subscription each, 300 GB apiece | 3 × $18.00 | $54.00 |
Isolation has a price: the last row costs three times one shared subscription holding the same 900 GB. Weigh that against one key that can delete every server's backups.
Limits and common errors
- 100 buckets per subscription by default; support can raise it. Each tier caps operations per second and throughput for the whole subscription.
- Not supported: bucket replication, access logging, inventory, notifications and website hosting.
- Deleting a subscription deletes everything in it, irreversibly, and blocks its bucket names for at least 48 hours.
- The console can't delete a bucket holding more than 50,000 objects; empty it with
s3cmd del --recursive --forcefirst.
- HTTP
429: over the tier's rate limit. Retries with backoff handle it; for rclone, Vultr suggests--retries-sleep. InvalidAccessKeyIdorSignatureDoesNotMatch: the keys were regenerated, or the endpoint is for another location than the subscription's.Missing required header for this request: Content-MD5or checksum errors: newer AWS CLI versions add checksums by default, which not every S3-compatible service accepts. Addrequest_checksum_calculation = when_requiredandresponse_checksum_validation = when_requiredto the profile.
A Vultr bucket for a Vultr server
For a Vultr server, a bucket in another location covers a destroyed instance, a broken upgrade or trouble in one location, and unlike Vultr's snapshots, its files restore anywhere. It doesn't cover the account: the server, the bucket and its one key share a login and a bill. Vultr's own guidance is to keep backups somewhere separate, such as another region or an independent subscription under a different account. Keep a further copy with another provider, per the 3-2-1 rule. Vultr encrypts data at rest on its side; encrypt backups before upload if only you should be able to read them.
Frequently asked questions
- What is the S3 endpoint for Vultr Object Storage?
- The subscription's hostname, such as
https://ewr1.vultrobjects.comin New Jersey orhttps://ams1.vultrobjects.comin Amsterdam. Vultr ignores the region setting, sous-east-1works. - Can I create a Vultr Object Storage key for one bucket?
- Not as of October 2026. A subscription has one key pair with access to all its buckets, so use a separate subscription for each set of buckets that needs its own key.
- How much does Vultr Object Storage cost?
- As of October 2026, Standard is $18.00 a month with 1,000 GB of storage and 1,000 GB of outbound transfer, then $0.018 per GB stored and $0.01 per GB transferred.
- Does Vultr Object Storage support Object Lock?
- The bucket form has an Object Lock switch, but as of October 2026 Vultr doesn't document retention modes or defaults. Check that a locked version refuses deletion before relying on it.
- Can I change a Vultr Object Storage tier?
- No. Create a subscription with the new tier and move the buckets to it.
How this was checked
Commands, limits and prices were checked against these official pages, on October 4, 2026:
- Vultr Docs: Provision a Vultr Object Storage subscription (tiers)
- Vultr Docs: Manage buckets
- Vultr Docs: Manage S3 credentials
- Vultr Docs: Delete a Vultr Object Storage subscription
- Vultr Docs: S3 Compatibility Matrix
- Vultr Docs: Object Storage limits
- Vultr Docs: Object Storage FAQ (locations and hostnames, tier changes, bucket names)
- Vultr Docs: Storage performance for Vultr Object Storage (rate limits, 429)
- Vultr Docs: How is Object Storage billed?
- Vultr Docs: How is Vultr Archival Object Storage billed?
- Vultr Docs: Manage lifecycle policies for Archival Storage
- Vultr Docs: Restore archived objects
- Vultr Docs: Security best practices for Vultr Object Storage (keys, lifecycle, integrity)
- Vultr Docs: How to use s3cmd with Vultr Object Storage
- Vultr Docs: Store Terraform state in Vultr Object Storage (region value)
- Vultr Docs: Migrate Amazon S3 storage to Vultr Object Storage (rclone with provider = Other)
- Vultr Docs: Server-side encryption (SSE-C) with Vultr Object Storage (AWS CLI usage)
- govultr (Vultr's Go API client): object storage bucket fields
- s3cmd usage reference (s3tools.org)
- AWS CLI User Guide: Configuration and credential file settings
- AWS CLI User Guide: Retries
- AWS SDKs and Tools Reference Guide: Data integrity protections for Amazon S3
- AWS CLI reference: s3api get-object-lock-configuration
- AWS CLI reference: s3api delete-object
- AWS CLI reference: s3api put-object-lock-configuration
- AWS CLI reference: s3api list-object-versions
- AWS CLI reference: s3api put-bucket-lifecycle-configuration (replaces an existing configuration)
- AWS CLI reference: s3 cp
- AWS CLI reference: s3 ls