Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.restic-rest-server-ubuntu-24-04-5892cc89-a312-4ab7-9914-3c6acd638f21/image2_logolarge.png

Rest Server on Ubuntu 24.04 LTS

by cloudimg

Self hosted restic REST backend, HTTP Basic authenticated and secure on first boot

Rest Server is a high performance open source HTTP server that implements the restic REST backend protocol. This cloudimg image turns a virtual machine and its dedicated data disk into a self hosted backup repository server: point any restic client at it over HTTPS and read and write backup repositories exactly as you would against any restic remote, entirely within your own subscription. It runs Rest Server 0.14.0 from the official release as a single static binary, under systemd as an unprivileged service user.

The server binds to loopback and is exposed through an nginx reverse proxy that terminates TLS on port 443, so the REST endpoint is reachable securely over HTTPS with a certificate generated per virtual machine on first boot. Rest Server is headless: there is no web interface, so you operate it with the restic client from the machines you back up. Repository data lives on a dedicated data disk.

Security is built in. Rest Server can be run with authentication disabled, which serves an open, anonymous repository server; this image closes that gap by requiring HTTP Basic authentication on every request against a bcrypt htpasswd file and enabling private repositories, so each user is confined to their own namespace. On the first boot of every VM a unique username and password are generated, written into the htpasswd file and recorded in a root only file, and the service is configured to refuse to start until a credential is present. As a result an unauthenticated or wrong password request is rejected with HTTP 401, no two instances share a credential, and no known credential is ever baked into the image.

Rest Server is distributed under the BSD 2 Clause License, free and open source with no per CPU or per deployment fee. cloudimg is not affiliated with or endorsed by the restic project; restic and Rest Server are marks of their owners. cloudimg provides packaging, systemd hardening, the secure by default authentication configuration, per instance credential automation, TLS termination, security patching, and 24/7 support with a guaranteed 24 hour response SLA.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.restic-rest-server-ubuntu-24-04-5892cc89-a312-4ab7-9914-3c6acd638f21/image5_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.restic-rest-server-ubuntu-24-04-5892cc89-a312-4ab7-9914-3c6acd638f21/image0_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.restic-rest-server-ubuntu-24-04-5892cc89-a312-4ab7-9914-3c6acd638f21/image6_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.restic-rest-server-ubuntu-24-04-5892cc89-a312-4ab7-9914-3c6acd638f21/image7_screenshot04.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies