Run ssv on a schedule

Nightly audit and backup with cron

The example below audits every night and emails the report only when something is HIGH or worse, makes a nightly encrypted backup, and keeps 30 days of backups. Save it as /etc/cron.d/ssv:

PATH=/usr/local/bin:/usr/bin:/bin
MAILTO=admin@example.com

# 03:15 audit; the report is mailed only if a file is HIGH or worse, or ssv fails.
15 3 * * * root ssv audit --fail-on high >/var/log/ssv-audit.log 2>&1 || cat /var/log/ssv-audit.log

# 03:30 encrypted backup; warnings and errors are mailed.
30 3 * * * root ssv backup --recipients-file /etc/ssv/recipients.txt --output /var/backups/ssv/$(hostname)-$(date +\%Y\%m\%d-\%H\%M).age >/dev/null

# 04:00 delete backups older than 30 days.
0 4 * * * root find /var/backups/ssv -name '*.age' -mtime +30 -delete
  • Create the backup directory once: sudo install -d -m 700 /var/backups/ssv.
  • The PATH line lets cron find ssv and age in /usr/local/bin.
  • In cron files, % must be written as \%.
  • Cron email only works if the server can send mail; otherwise read /var/log/ssv-audit.log.
  • A backup kept only on the server is lost with the server. Copy the .age files elsewhere as well; they are encrypted, so any storage will do.

To decide which severity should trigger an alert, see failing on findings. Restoring a backup needs only age and tar; see restoring from a backup.

Exit codes

Code Meaning
0 Success. Warnings may still have been printed.
1 Error, for example a --root that doesn't exist, age not installed, or a failed backup.
2 Invalid command line, for example an unknown option or a path without --root.
3 audit --fail-on: at least one file is at or above the given severity.

Last updated 2026-10-08 · for ssv 0.2.0