Native Backups & S3-Compatible Storage After the 2025.1 Overhaul
Back in my original article — Safeguarding Home Assistant: 3-2-1 Backups Using rclone, S3, and Veeam 12.1 — I walked through building a fully off-site, fully automated backup pipeline. That method used rclone jobs, encrypted S3 storage, and even Veeam tiering for immutability and long-term retention.
That workflow still works. And for many people, it’s still the gold standard.
But Home Assistant has evolved.
With the Home Assistant 2025.1 release, the platform introduced the most significant backup and recovery improvements in its history. And for the first time thanks to a HACS addon, we can now integrate S3-compatible object storage directly into Home Assistant’s backup engine — no more external scripts, add-on snapshots, rclone timers, or juggling container mounts.
If you’ve been waiting for a native, reliable, and enterprise-grade backup workflow that doesn’t require duct tape or cron jobs…this is it.
What Changed in Home Assistant 2025.1
The January 2025 release fundamentally redesigned how backups work.
Key improvements from the release notes include:
1. Backups Became a Core System Feature
No more Supervisor “snapshots” or add-on bundles.
Backups are now first-class: structured, consistent, and UI-driven.
2. Encryption Is Now Default
Every backup is automatically encrypted unless you explicitly disable it.
This alone is a massive security upgrade.
3. Real Retention Policies
You can now keep:
- X daily backups
- Y weekly backups
- Z monthly backups
No more scripting cleanup jobs.
4. Plugins Can Add New Storage Locations
This is the breakthrough feature.
Backup targets are now extendable, which means integrations can register:
- Cloud storage
- Local network shares
- Custom providers
- External services
- S3 endpoints
- And more over time
5. Automated & On-Demand Backups
The new backup engine supports:
- Scheduled backups
- Event-driven backups (before updates, after automations, etc.)
- Manual backups
- Service-triggered backups from scripts & automations
6. First-Time Setup Wizard Encourages Off-Device Backups
This is huge for new users — it helps prevent the #1 reason HA restores fail:
“I stored all backups on the same device that died.”
Home Assistant is finally guiding users toward best practices.
Why S3-Compatible Storage Is the Perfect Match
Object storage is ideal for HA backups because it’s:
- Cheap
- Redundant
- Designed for durability
- Accessible from anywhere
- Often supports immutability (WORM)
- Cloud-agnostic
- Easy to lifecycle manage (tiering, archival, expiration)
And, importantly, the new S3-Compatible integration plugs directly into Home Assistant’s backup engine.
That means:
- No more rclone scripts
- No more addon container mounts
- No cron timers
- No sync loops
- No manual uploads
- No shell commands
Just a clean, native UI-driven configuration.
Installing the S3-Compatible Integration
The integration is available through HACS.
Step 1 — Open HACS and Search for “S3 Compatible”

Step 2 — Open the Integration Details

Step 3 — Install from HACS
Then restart Home Assistant.

Step 4 — Add Integration
Go to:
Settings → Devices & Services → Add Integration → “S3 Compatible”

Step 5 — Enter Your Credentials
Fill in your values:
| Field | Description |
| access_key_id | Your S3 access key |
| secret_access_key | Associated secret |
| bucket | Bucket where backups will be stored |
| prefix | Optional (subfolder) |
| endpoint_url | URL of your S3 endpoint |
Click Submit, and you should see a confirmation:

Enabling S3 as a Backup Location
Go to:
Settings → System → Backups → Configure Backup Settings
Scroll down and you’ll now see S3 Compatible listed as a storage location:

Turn it on — and Home Assistant immediately begins storing new backups there.
This works for:
- Default scheduled backups
- Manually created backups
- First-time setup backups
- Pre-update backups
- Automation-triggered backups
Everything goes to S3 automatically.
Comparing the Old Method vs. the New Method
2024 Method (rclone + snapshot exports)
✔ Very flexible
✔ Worked with any S3 endpoint
✔ Compatible with Veeam
✘ Required scripting and YAML configuration
✘ Depended on add-on behaviors
✘ No native UI integration
✘ Manual lifecycle management
✘ Restores required manual uploads
2025 Method (Native Backup Engine + S3 Integration)
✔ 100% native HA integration
✔ Encrypted by default
✔ Automated retention
✔ Multi-location support
✔ Restore works directly from primary S3 bucket
✔ Zero scripts or maintenance
✔ Cleaner, safer, faster
✘ Slightly less customizable than raw rclone
For 95% of users, the new method is the clear winner.
For power users (like me), you can still combine both approaches:
- Home Assistant uploads backups to S3
- Veeam SOBR pulls in the same bucket for long-term retention or immutability and 3-2-1 compliance
It is the best of both worlds.
My Exact Setup
For my environment, I use storage from iDrive e2 and Veeam Backup & Replication with an Ootbi virtual appliance from Object First. My backup methodology is the following:
- Versioning and Object Lock enabled on the Veeam buckets
- Access keys scoped only to the backup bucket
- Lifecycle policy:
- Keep 7 daily backups from Home Assistant
- Back up the HA bucket via Veeam daily and retain on a performance tier SOBR extent/Ootbi bucket for 7 days
- Move/copy to an iDrive capacity tier bucket in a second region and store for 3 months
- Public access explicitly blocked
This keeps the backups cheap, redundant, and protected — without manually cleaning anything up. In theory I could make this even more resilient by adding utilizing another S3-vendor such as Wasabi or Backblaze for the Capacity Tier, offering not only geo-redundant but provider-redundant copies.
Recommended Best Practices
1. Use a Dedicated Bucket
Don’t mix object storage with backups for anything else – even backups from another software.
2. Apply IAM Least Privilege
Only allow:
- s3:ListBucket
- s3:PutObject
- s3:DeleteObject
Nothing else. If your vendor allows it, you should also whitelist your external IP so if your keys ever leak the buckets cannot be accessed from another network.
3. Enable Versioning or Object Lock where supported
Versioning protects you from:
- Accidental deletions
- Corrupt upload cycles
- Malware wiping backups
Object lock (immutability) gives you:
- Ransomware resistance
- Guaranteed no early deletion
- Compliance (if you need it)
4. Keep Local + S3 Backups
Native backup locations allow multiple targets simultaneously — use it.
5. Test Your Restores
At least once every quarter:
- Restore to a VM or test system.
- Never assume backups are valid unless proven.
Final Thoughts — Backups Feel “Official” Now
The 2025.1 overhaul marks the moment Home Assistant’s backup system finally matches the maturity of the rest of the platform. Between the native backup engine, encryption defaults, retention policies, and pluggable storage system, we finally have a reliable, modern, and future-proof way to protect our HA deployments.
The S3-Compatible integration completes the puzzle — bringing cheap, durable, off-site storage directly into the Home Assistant UI.
No scripts.
No cron.
No rclone.
No mount paths.
No restore headaches.
Just a clean, native, cloud-ready backup strategy that anyone can set up — and power users can extend further with Veeam or custom lifecycle automation.
If your Home Assistant system matters — and let’s be honest, most of ours do — this is the backup architecture you should be running in 2025.
