Back up a server to Backblaze B2 with Object Lock
B2 has no minimum storage duration or minimum file size fees, and it has Object Lock over the S3 API, which is how the Arkame agent talks to the bucket. This guide goes from a new account to the first restored backup.
Console steps checked against the provider's official documentation on October 4, 2026. Screens change: if something doesn't match, follow the documentation linked in each step.
Before you start
- An email address for the Backblaze account.
- A Linux, Windows or macOS server with admin access, to install the agent.
- An Arkame panel account.
Create the account and pick a region
- Create the account. During sign-up you choose the data region: US East, US West, EU Central or Canada East.
- The region applies to the whole account and can't be changed later. Pick the one closest to your servers, or the one your data rules require.
Create a private bucket with Object Lock
- In the console, under B2 Cloud Storage → Buckets, click Create a Bucket and give it a name.
- For privacy, choose Private.
- Turn on Object Lock at creation. Backblaze lets you enable it on an existing bucket, but the same documentation says default bucket retention needs Object Lock enabled at creation. Once on, it can't be turned off.
- Create the bucket and note the Endpoint shown on it, in the form
s3.us-west-004.backblazeb2.com.
Versioning: already on
- B2 keeps every version of each file by default: under Lifecycle Settings, the default option is Keep all versions of the file. Those versions are how Arkame goes back in time.
- Don't switch to Keep only the last version of the file: that deletes the older versions.
In a bucket with Object Lock, Arkame deletes no versions at all: the lock is your decision that nothing leaves before its time. So old versions don't pile up forever, later use Keep prior versions for this number of days. That number of days is how far back you'll be able to go, and Backblaze won't delete a version that is still under Object Lock.
Turn on default retention
- On the bucket, click Object Lock, enter the default retention in days (1 to 3,000) and save.
- 30 days is a good start. Pick a period longer than it would take you to notice an attack.
- Check that the retention shows Compliance Mode. In that mode nobody can delete or overwrite a version before the period ends, not even with the key in hand.
Object Lock on without default retention protects nothing: every new file has to be born with a period.
Create a key just for Arkame
- Under Application Keys, click Add a New Application Key.
- In Allow Access to Bucket(s), choose only your bucket. In Type of Access, Read and Write.
- Check Allow List All Bucket Names. Backblaze says a key restricted to one bucket needs this permission to work with S3-compatible tools. It lists the account's bucket names, not their contents.
- Click Create New Key. The keyID is the access key and the applicationKey is the secret. The secret appears only once: save it right away.
Never use the account's master application key; Backblaze's S3 API doesn't even accept it. On B2, permissions come from the key's type of access, not from an IAM policy as on AWS and Wasabi. The agent installer tests the key against the bucket before going on.
Add the bucket in Arkame
- In the panel, open Storages → Add storage and pick Backblaze B2.
- Fill in the bucket name and the endpoint, as in the box below. You can leave the region blank: Arkame reads it from the endpoint.
- You do not type the key here. The installer asks for the keyID and the applicationKey on the server itself, and they stay there.
In Arkame, under Storages → Add storage:
- Provider
- Backblaze B2
- Bucket name
- the name you chose
- Endpoint
- https://s3.us-west-004.backblazeb2.com
- Region
- blank — Arkame reads it from the endpoint
Install the agent and run the first backup
- Under Agents → New agent, give it a name, choose the bucket and copy the command the panel shows for the server's system (installation).
- Run the command on the server. The installer asks for the keyID and the applicationKey, tests the key against the bucket before going on and, if the bucket refuses it, tells you why and asks again.
- Back in the panel, check the server's key fingerprint and approve it. Then use Test connection.
- Under Plans → New plan, choose the folders, the destination bucket and a schedule (plans). To skip the wait, use Run now on the plan page and follow it in History.
- When the backup finishes, restore one file to a new folder under Restore (restore). A backup that has never been restored is still a hypothesis.
Try it on your server
14-day free trial, no card. Backups go to your bucket, with your keys.