Skip to content

9. Backups

Local
Time Machine
Off-site
Cloud backup service
Always
Test a restore

A server that runs unattended needs backups that also run unattended. Aim for the classic 3-2-1: three copies of your data, on two different kinds of storage, one of them off-site.

What Where it lives
Code and agent work ~/code/ (or wherever you keep projects)
Tool settings and sign-ins ~/.cursor/, ~/.claude/, ~/.config/, ~/.ssh/
Background jobs ~/Library/LaunchAgents/, ~/bin/
What’s installed ~/Brewfile (brew bundle dump --file ~/Brewfile --force)
Documents Your cloud storage — plus a copy in a backup, since sync also syncs deletions
  1. Connect an external SSD, or use a network share on a NAS (SMB) that supports Time Machine.
  2. System Settings → General → Time Machine → Add Backup Disk… and choose Encrypt Backup.
  3. Leave the schedule on Automatically every hour.

Useful commands:

Terminal window
tmutil startbackup # back up now
tmutil status # is a backup running?
tmutil latestbackup # path of the newest backup
tmutil listbackups # all of them

tmutil may need Full Disk Access for Terminal to read backup details. It prints errors but still exits 0, so read its output: tmutil destinationinfo says No destinations configured. if no backup disk is set up.

Exclude regenerable bulk to keep backups small and fast. Sticky exclusions follow the folder even if you move it:

Terminal window
tmutil addexclusion ~/code/my-project/node_modules
tmutil addexclusion ~/Library/Developer/Xcode/DerivedData
tmutil isexcluded ~/code/my-project/node_modules

Time Machine doesn’t help if the house floods or the Mac and its backup disk are stolen together. Add one off-site copy:

  • a cloud backup service with a Mac client that runs in the background, or
  • a backup app that writes encrypted, versioned backups to cloud object storage you control.

Whichever you choose: turn on encryption, keep versions (so a bad sync or ransomware doesn’t overwrite the only copy), add the app to Login Items, and include it in your health check with --app.

A backup you’ve never restored from is a hope, not a backup. Every few months:

  1. Restore one project folder from Time Machine to a new location (Enter Time Machine in Finder, or tmutil restore).
  2. Restore one file from the off-site copy.
  3. Tick the restore test on your checklist.
  1. Set up the new Mac and run Migration Assistant from the Time Machine backup — or start clean and run brew bundle install --file ~/Brewfile.
  2. Re-run the scripts: setup-power.sh --apply, then reinstall LaunchAgents.
  3. Sign in to your tools again, re-add Tailscale and disable key expiry for the new machine.
  4. Run health-check.sh until everything passes.