Run ssv on a schedule
Nightly audit and backup with cron
The example below audits every night and emails the report only when something is HIGH or worse, makes a nightly encrypted backup, and keeps 30 days of backups. Save it as /etc/cron.d/ssv:
PATH=/usr/local/bin:/usr/bin:/bin
MAILTO=admin@example.com
# 03:15 audit; the report is mailed only if a file is HIGH or worse, or ssv fails.
15 3 * * * root ssv audit --fail-on high >/var/log/ssv-audit.log 2>&1 || cat /var/log/ssv-audit.log
# 03:30 encrypted backup; warnings and errors are mailed.
30 3 * * * root ssv backup --recipients-file /etc/ssv/recipients.txt --output /var/backups/ssv/$(hostname)-$(date +\%Y\%m\%d-\%H\%M).age >/dev/null
# 04:00 delete backups older than 30 days.
0 4 * * * root find /var/backups/ssv -name '*.age' -mtime +30 -delete
- Create the backup directory once:
sudo install -d -m 700 /var/backups/ssv. - The
PATHline lets cron findssvandagein/usr/local/bin. - In cron files,
%must be written as\%. - Cron email only works if the server can send mail; otherwise read
/var/log/ssv-audit.log. - A backup kept only on the server is lost with the server. Copy the
.agefiles elsewhere as well; they are encrypted, so any storage will do.
To decide which severity should trigger an alert, see failing on findings. Restoring a backup needs only age and tar; see restoring from a backup.
Exit codes
| Code | Meaning |
|---|---|
| 0 | Success. Warnings may still have been printed. |
| 1 | Error, for example a --root that doesn't exist, age not installed, or a failed backup. |
| 2 | Invalid command line, for example an unknown option or a path without --root. |
| 3 | audit --fail-on: at least one file is at or above the given severity. |
Last updated 2026-10-08 · for ssv 0.2.0