SYNOLOGY → S3 GLACIER DEEP ARCHIVE

Back up Synology to Glacier Deep Archive.

A self-hosted interface for choosing what to back up, creating dated TAR files, running dry runs and monitoring rclone jobs.

An anonymised Glacier Backup Manager overview showing a live TAR job

Taking advantage of AWS Deep Archive’s affordable price tier is a headache.

Synology Cloud Sync can copy files to S3, but checking a large NAS can generate thousands of API requests. In my case, that request overhead worked against the reason for choosing Deep Archive in the first place.

rclone was the logical alternative, but it has no GUI. Including and excluding folders is difficult if you are not comfortable with the command line. After Synology deprecated Glacier Backup, I built the visual interface I wanted as a designer: choose folders, preview a job and see what is happening.

How it works

01

Connect S3

Configure an rclone remote for your bucket.

02

Choose folders

Select exactly what is included or excluded.

03

Run the job

Dry run first, then copy now or on a schedule.

04

Move to Deep Archive

Your S3 lifecycle policy changes the storage class.

The manager does not create your AWS account, bucket or lifecycle policy. It uses the S3 destination you configure.

Back up selected folders

Add only the folders you want to protect. Exclude subfolders in the browser, preview the candidates with a dry run, then copy recent changes immediately or on a schedule.

  • Source volumes are mounted read-only
  • Existing S3 objects are not uploaded again
  • One file or folder can be forced into the next upload
An anonymised folder browser with selected and excluded backup folders
Select folders and configure a dated TAR archive

Create TAR archives of folders

Select one or more folders and package each as a separate dated TAR or TAR.GZ file. The source hierarchy can be reused at the destination, so an archive from /volume1/Docker/Persistent can be stored under Docker/Persistent.

  • The original folder is never changed or deleted
  • Available temporary space is checked before packaging
  • Local packages are removed only after a successful upload

Run to a schedule

Choose when the nightly backup starts and how far back the recent-file window should look. You can pause scheduled and manual jobs without removing the configuration.

Nightly backup schedule and modification window

Limit the system overhead

Set the scan pace, CPU cores, thermal pause point, bandwidth and AWS request rate. The runner stops work at the upper temperature and resumes after the NAS cools.

CPU, temperature, bandwidth and AWS request controls

Installation

Choose the layout of your Synology. The builder creates the complete Portainer stack and DSM runner command with the correct volume paths.

Describe your NAS

Nothing entered here is sent anywhere. The files are generated in this browser.

Volumes containing folders to back up

Security

This is self-hosted software, not a managed backup service. You remain responsible for AWS permissions, NAS access, lifecycle rules, restores and independent verification.

Local administrator login

First launch requires a username and a password of at least 12 characters with uppercase, lowercase, a number and a symbol. Passwords are stored as salted PBKDF2-SHA256 hashes, never as plaintext.

Protected sessions

Sessions use random HttpOnly, SameSite cookies and CSRF tokens. Enable secure cookies when serving the interface over HTTPS. Login attempts are rate-limited.

Credentials stay with the runner

The web interface never displays stored AWS secrets. One-time configuration requests expire, are written with restrictive permissions and are passed to rclone via standard input rather than command history.

No destructive sync

Jobs rebuild mandatory arguments and use copy, --no-traverse and explicit source mappings. The application does not expose remote delete operations.

Do not expose the app directly to the public internet. Keep it on a trusted network or behind a properly configured HTTPS reverse proxy and additional access control. Review SECURITY.md before deployment.
Please remember

Set your bucket lifecycle rules to move objects into Deep Archive.

Glacier Backup Manager uploads to your S3 bucket, but it does not create AWS lifecycle rules or spending alerts. Complete both steps before relying on the backup.

1

Create the S3 Lifecycle rule

  1. In Amazon S3, open the destination bucket, then choose Management → Lifecycle rules → Create lifecycle rule.
  2. Apply the rule to the whole bucket or only the prefix used by this manager.
  3. Add a transition for current object versions to S3 Glacier Deep Archive after the number of days you choose. If bucket versioning is enabled, review noncurrent-version transitions as well.
  4. Save the rule and confirm uploaded objects eventually show the Deep Archive storage class.
AWS guide to creating an S3 Lifecycle rule →
2

Create an AWS Budget alert

  1. Open Billing and Cost Management → Budgets → Create budget, then choose a cost budget.
  2. Set a monthly amount that reflects the storage, request and restore costs you expect.
  3. Add email alerts for actual and forecasted spend—for example, an early warning and a second alert at your maximum comfortable amount.
  4. Check that the notification recipient is correct and review the budget after the first full billing cycle.
AWS guide to creating a budget →

Worth knowing: new Lifecycle configurations do not transition objects smaller than 128 KB by default. Deep Archive also has a 180-day minimum storage duration and restores are not immediate. Packaging many small files into TAR archives can reduce per-object transition overhead.