This is how you set up a bucket at a service that speaks the S3 interface as a target for your backups: from the address of the service through the connection test to the saved target.
What you need
- the address that your provider names for the S3 interface,
- a bucket at this service that already exists: the plugin does not create one,
- an access key and the secret key that belongs to it, with the permissions for this bucket,
- the region, if your provider requires one.
The target type S3-compatible is for every service except Amazon S3 itself, for example Cloudflare R2, Backblaze B2, Hetzner Object Storage, DigitalOcean Spaces or MinIO on your own server. For Amazon S3 there is a separate target type: Store backups in Amazon S3.
No cloneworx service in between
You enter the access key and the secret key of your service. The plugin signs every request itself. The secret key never leaves the web server.
The address of the service
The address begins with https:// and names the service without the bucket. The bucket and the folder have their own fields. These addresses come from the documentation of the providers, as of 2026-09-28. What your provider names for your account is what counts:
| Service | Address | Region |
|---|---|---|
| Cloudflare R2 | https://<Konto>.r2.cloudflarestorage.com |
auto |
| Backblaze B2 | https://s3.<Region>.backblazeb2.com |
the region of the account, for example us-west-004
|
| Hetzner Object Storage |
https://fsn1.your-objectstorage.com, also nbg1 and hel1
|
as the provider names it |
| DigitalOcean Spaces | https://<Region>.digitaloceanspaces.com |
as the provider names it |
Step 1: Choose the target type
Open the Targets page and click Add target. Choose S3-compatible.
- The target types that exist. S3-compatible carries the cloud.
- Dismiss closes the selection.
The plugin talks to the service through the PHP extension cURL and reads the responses with the PHP extension DOM. If the web server lacks one of them, S3-compatible is greyed out and carries the label Not available on this server. The reason is shown below the selection.
Step 2: Fill in the form
- Name is up to you. The plugin suggests “S3-compatible 1”; any name that is not in use yet works.
- Address of the service is the address of the S3 interface, without the bucket.
- Bucket is the name of the bucket in which the backups are to be stored.
- Access key is visible in the form, like a user name.
- Secret key is stored encrypted and never goes back to the browser.
- Folder in the bucket may stay empty: then the folder of this website lies directly in the bucket.
- Test connection checks the entered values without saving.
Fields with a red star are required. Use a key that was created only for this backup and may reach only this bucket. It needs the permissions to list the bucket, to read, write and delete objects and to abort an upload. So that the plugin can check and clean up unfinished uploads, it also needs the permissions to list unfinished uploads and their parts. Your provider tells you how to grant permissions. If a permission is missing, the connection test names it.
The bucket must not be public
Make sure that the bucket is not public: without the keys nobody may reach it. The plugin never sends test requests from outside. That is why it cannot tell you whether the bucket is public.
Step 3: Test the connection
Click Test connection. The test writes a small file into the bucket, reads it back, lists it and deletes it again. In addition it uploads a test file of just over 5 MiB in two parts and measures the upload rate while doing so. It deletes this file again as well. Along the way it determines in which form the service expects the address.
- The result of the test: the connection works, a test file was written, read back and deleted.
- A warning of the test. In the picture the service does not list unfinished uploads.
- The region of the bucket, the upload method and the measured upload rate.
If the test succeeded, the form shows these lines:
| Line in the result | Meaning |
|---|---|
| Connection works: a test file was written, read back and deleted. | Writing, reading back, listing and deleting work. |
| Region of the bucket: … | The region the plugin works with. If the service names a different one than the one entered, the one of the service applies. |
| Upload method: in parts (multipart upload); an upload continues with the next part. | S3 cannot continue a file. That is why the plugin uploads every file in parts. |
| Measured upload rate: … per second. | Based on the rate the plugin chooses the size of the parts. |
Below the first line, warnings are shown in yellow if the test noticed something. The section “Warnings after a successful test” explains them.
Step 4: Save
Click Save. The plugin saves the target, tests the connection once more and reports the result: “…” saved and connected. Plans and backups use a target only after a successful connection test.
- All targets are connected.
- The message names the target: saved and connected.
- The new target is in the list. The green dot means: connected. A target of the type S3-compatible is preceded by the cloud.
If the plugin finds backups in the bucket that are not in your list, the tile Backups found at “…” appears. More about this: Find backups again after a total loss.
Step 5: Choose the target in the backup plan
- Your first target: The plugin creates the plan “Daily backup”: daily at a random time, everything, this target, Max. backups 7. The plan is paused until you switch it on.
- Another target: Choose it on the Backup page in the tile Backup plans in a plan. The free version allows two plans and one target per plan.
More about this: Schedule backups automatically.
The fields of the Extended view
-
Region may stay empty: then
us-east-1applies, which most services accept, or what the connection test determined. -
Form of the address may stay empty: then what the connection test determined applies. Possible values are
path(the bucket is in the path) andvirtual(the bucket is in the name of the server). - Connection timeout (seconds) takes 3 to 60, the default is 10.
- Upload rate (bytes per second) may stay empty: then what the connection test measured applies.
- Accepted key of the server is set by Accept this certificate. Empty means: the plugin checks the certificate against the list of trusted authorities.
An empty field whose value the test determines shows automatic. Every connection test determines region, form of the address and rate anew. A form of the address and an upload rate you enter yourself take precedence. If the service names a different region than the one you entered, the plugin works with the region of the service, and the connection test warns.
Encryption and certificate
https:// is the rule. The plugin accepts an address with http://; all data then travel in clear text. The result of the connection test warns: The connection is not encrypted: password and data can be read on the way.
With https:// the plugin checks the certificate of the service against the list of trusted authorities that comes with WordPress, together with the name of the server. If the check fails, the test fails and shows the certificate. For your own server with its own certificate you can then accept the certificate explicitly.
- The reason: not issued for this server name, self-signed, from an unknown authority or expired.
- The details of the certificate: who it is issued for, by whom, until when it is valid, and its fingerprint.
- Accept this certificate takes the key of the certificate into the form and tests again.
Above the reason 1 the picture shows the line Message from cURL with the original error message from cURL.
Accept only if the fingerprint matches
After accepting, the plugin trusts exactly this key and no longer checks who issued the certificate. Nobody has confirmed that this is the right server: compare the fingerprint with the one your provider names, or, for your own server, with the certificate that is set up there.
After accepting, the result of a successful test contains the warning: The certificate is not checked against the list of trusted authorities; the plugin trusts the key you accepted.
The check is never switched off. If the server later shows a different key, the target no longer passes its test. Accept the new certificate only if you know why it has changed.
Warnings after a successful test
| Warning | What you can do |
|---|---|
| The service names another region than the one you entered. The plugin uses the region of the service; correct the field Region. | In the Extended view, enter the region that the result names, or clear the field Region. |
| This bucket keeps versions: a deleted backup stays there as an old version and keeps taking space. Set a lifecycle rule at the service that removes old versions. | Set up the rule at your service. Deleting by the plugin only hides a backup in such a bucket. |
| The service does not list unfinished uploads, so the plugin cannot clean them up there. Set a lifecycle rule at the service that removes unfinished uploads. | Some services do not list unfinished uploads, or the key lacks the permission for it. Set up the rule at your service. |
| The service does not let the plugin list the parts of an upload. Uploads work, but the plugin cannot check them before it continues. | Give the key the permission to list the parts of an upload, if your service knows it. |
| The clock of this web server differs from the clock of the service by about … minutes. The plugin works with the time of the service; have the clock of the web server corrected. | Ask your hosting provider to correct the clock of the web server. Backups keep running until then. |
When the test fails
If the test fails, the result is shown below the fields of the form. The picture shows this on the form for Amazon S3; for S3-compatible the result has the same structure. In the picture the access key lacks the permission to write objects.
- The cause in plain language. The link at the end, Show log, opens the general log. The details of the test are there.
- The permission that the access key lacks.
- Message from the target is the original error message of the service.
Line 2 is shown only below some causes and names the reason more precisely, for example the missing permission. If cURL reported something too, the line Message from cURL is shown below Message from the target. The error messages in these two lines are not translated. The bucket, the access key and the server name from the address of the service are masked in them; the secret key is never sent.
| Message | What you can do |
|---|---|
| The target cannot be reached. Check the server name and the port; the host of this website may block the port. | Check the Address of the service: the server name and, if it names one, the port. |
| The service refused the keys. | Below it you see which key is wrong: The service does not know this access key. Or: The signature of the request was refused: the secret key does not belong to this access key. Enter the key again. |
| The access key lacks a permission that the plugin needs. | Below it the permission is named: Missing permission: …. Add it at your service. |
| The bucket does not exist at this service. The plugin does not create buckets. | Check the name in the field Bucket and the Address of the service, or create the bucket at your service. |
| The bucket lies in another region than the one that was used. | Below it the region of the bucket is named. Enter it in the field Region, or clear the field. |
| The service refuses the request because the clock of this web server is off by more than the service allows. | Ask your hosting provider to correct the clock of the web server. |
| The certificate of the target did not pass the check. | See the section “Encryption and certificate”. |
| The target redirects to another address. The plugin does not follow a redirect; test the connection of the target to see the new address. | Ask your provider for the address of the S3 interface and enter it as Address of the service. With this target type the plugin does not name the new address. |
| An upload did not arrive before the time of a step ran out: the connection to the target is too slow for it. | Below it the reason is named: This service takes an upload only in parts of at least 5 MiB, and such a part has to arrive within one step. How long a step takes at most is set by the setting Maximum time per step: Adapt the plugin to your server. |
| This value is not valid. at the field Address of the service | The address begins with https:// or http:// and names only the server, with a port if necessary. Bucket and folder belong in their own fields. |
Good to know
- The backups are stored in the bucket under
<folder>/cloneworx-backup-<code>/<backup>/. - A part of an upload is at least 5 MiB in size, only the last one may be smaller. A file appears in the bucket only when its upload is complete.
- An upload that was never completed keeps taking space at the service. The plugin aborts its own unfinished uploads, and cleaning up leftovers aborts the ones it finds. In any case, set a lifecycle rule at your service that removes unfinished uploads after a few days.
- The plugin places no protection files in a bucket: a bucket is not served by a web server that would read them.
- Backups that are stored only in a bucket you do not download through the plugin, but with a program for S3 or in the web interface of the service. Restore, check and finding backups read directly from the service.
- The plugin also uses a proxy from the
wp-config.phpfor this target type. - Below the selection of the target types the note reads: Names and logos of third parties are the property of their respective owners. This does not imply any affiliation or partnership.
See also
- Which target suits you?
- Store backups in Amazon S3
- The “Targets” page
- Renew the credentials of a target
- Check backups at a target and clean up leftovers
On the command line
WP-CLI not set up yet? How to install WP-CLI.
The command line does not accept the secret key; that is why you set up a target of the type S3-compatible on the Targets page. Everything else also works with WP-CLI:
# Show targets with ID and state wp cloneworx-backup target list # Test the connection wp cloneworx-backup target test s3-1 # Create a backup plan that backs up to this target wp cloneworx-backup plan add --targets=s3-1 --rhythm=daily --time=03:15 --name="Nachts" # Check the backups at this target wp cloneworx-backup target check s3-1 # Show leftovers and unfinished uploads (--dry-run) and clean up wp cloneworx-backup target cleanup s3-1 --dry-run wp cloneworx-backup target cleanup s3-1