faaleoleo · June 2026 · Resources
New Whitepaper: Self-Hosting Bacula
Security & Operations Checklist
We have published a free whitepaper: a 34-point security and operations checklist for teams deploying and operating Bacula themselves. It covers the decisions that separate a functioning backup installation from a resilient one.
What it covers
Installing Bacula takes an afternoon. What takes deliberate effort — and what is almost always incomplete in self-hosted environments — is everything around it. The checklist works through 12 domains:
- OS and network — distribution selection, minimal install, inbound and outbound firewall policy
- Access control — no root login, least-privilege accounts, operator role separation with restricted shells, 2FA at every layer
- Intrusion detection — host-based IDS (CrowdSec or fail2ban), file integrity monitoring
- Daily verification — knowing every morning, without logging in manually, that last night's backups succeeded
- GUI security — network-restricted access, individual named accounts, 2FA enforced
- Bacula configuration — best-practice setup, scripting hygiene, per-client unique passwords
- Encryption — client-side before transmission, TLS between components, storage at rest, FIPS awareness
- Logging and audit — centralised retention, compliance reports, tamper-evident audit trails
- Backup scope — scope register, FileSet exclusion review, drift detection for new systems
- Restore testing — automated verification reviewed not just logged, tested DR plan with RTO/RPO
- Dedicated resources — why sharing infrastructure with production workloads fails under pressure
- Database and continuity — catalog backup and restore test, bootstrap file retention, documentation
Each item includes a brief explanation of why it matters — not just what to do.
Why this exists
Most self-hosted Bacula installations work. Jobs run, files land on storage, nobody complains. The gaps are in the less visible areas: outbound firewall policy, operator privilege separation, scripting hygiene, daily backup status confirmation, automated restore testing, catalog database backup. These are the things that surface only during a security incident or a recovery under time pressure.
The checklist exists to make those gaps visible before they become consequential.
One example from the checklist: do you know every day, without logging in, that last night's backups completed? If the only way to find out is to check manually — then on the days nobody checks, you have no coverage. Silence should be an alarm, not reassurance.
The alternative: faaleoleo Managed Bacula Backup
If working through this checklist looks like a significant operational commitment, that is precisely the point. Every one of these 34 items needs to be set up correctly, kept current as infrastructure changes, and revisited when new systems are added or compliance requirements evolve. That is the operational reality of running Bacula in production.
faaleoleo's managed Bacula Enterprise backup service covers all of it: initial hardening, access control, encryption, daily job monitoring with proactive failure response, restore testing on a defined schedule, compliance reporting, and ongoing maintenance. Our customers get a complete, production-grade Bacula installation — without building and maintaining the operational capability in-house.
Download the checklist: Self-Hosting Bacula: Security & Operations Checklist — free PDF, no registration required.
Prefer to hand it over? Read more about what managed Bacula backup covers — or get in touch directly.