cPFence v4 public beta is here.

Explore v4
Enhance CP Tutorials

Enhance Backups Running at Random Times? Here’s a Tip

Backup Timing conceptual feature illustration

Backups are crucial, and a predictable backup window makes tracking and troubleshooting much easier. If your Enhance backups seem to have a mind of their own, here’s how we approached the timing—and what to check before changing yours.

A quick update: This article began as a February 2025 scheduling tip. Enhance’s maximum backup age is a target, not a promise of an exact start time. The examples below help you plan a window; check completed backups to see whether your own settings are working.

Sign in as an Enhance administrator who can manage servers, website assignments and global service settings. This guide assumes that you’ve already:

  • Added a new ext4 backup server to your Enhance cluster.
  • Assigned the backup role to it.

These steps are straightforward:

  1. Click Add New Server, grab the setup code, paste it into your Ubuntu 22.04 or 24.04 server, and hit enter.
  2. Once the installation is complete, go to Control Panel → Servers, open your new backup server, click Add Role, and select Backups.
  3. Finally, head over to Websites, select the sites you intend to back up, and make sure their Backup role is assigned to the correct server. Review that selection before applying a move.

Confirm the Backup role is installed and your selected sites are assigned before moving on. These are Enhance’s own backups; the settings below do not configure cPFence’s separate WordPress backups.

Setting Up Enhance Backup Timing

Head to Settings → Service settings → Backups. These settings apply globally, so note the existing values before changing them. Enhance’s global backup settings reference explains the controls.

  1. Ensure Timezone Consistency
    • Allowed backup hours follows the timezone of the main control panel server. Use that timezone when planning your window.
    • Matching timezones make logs easier to compare. If they differ, account for the offset when reading the backup-server timestamps below.
    • Our original routine included a reboot after timezone changes. Do not reboot a busy server just to adjust this schedule; plan any needed service interruption separately.
  2. Configure Backup Frequency
    • For a 24-hour backup cycle, set minimum: 23 hours and maximum: 24 hours.
    • For 12-hour backups, set minimum: 11 hours and maximum: 12 hours.
    • These are example intervals, not exact schedules. Minimum age determines when a site becomes eligible again; maximum age is a target that load can delay.
  3. Check the Last Backup Time

    Using your normal administrator SSH session on the backup server, run this read-only example if your backups use /backups/SITE/snapshot-TIMESTAMP directories. Adjust /backups if your configured directory differs:

    
    for site in /backups/*; do
        [ -d "$site" ] || continue
        latest_snapshot=$(ls -d "$site"/snapshot-* 2>/dev/null | sort -V | tail -n 1)
        if [[ -n "$latest_snapshot" ]]; then
            timestamp=${latest_snapshot##*-}
            timestamp=$((timestamp / 1000))
            echo "$(date -d @$timestamp '+%Y-%m-%d %H:%M:%S') -- ${site##*/}"
        fi
    done | sort
    

    This lists timestamps from matching directory names in the backup server’s local timezone. It does not prove that a backup completed or can be restored. If the layout differs or the list is empty, check the website’s backups in Enhance instead; do not rename or delete directories to make the example fit.

  4. Set the Allowed Backup Hours
    • Let’s say you want a window beginning at 4 AM.
    • Check when the last backup happened (using the above command) and ensure the minimum time setting aligns with it.
    • Set Allowed backup hours to 4 AM – 6 AM only if your measured workload fits that window. Allow enough time for the selected sites, save, and check the following backup cycle.
  5. If Backups Don’t Start on Time
    • Our original post described a manual backup of one site appearing to kickstart the queue. That was an observation, not a documented scheduler reset or a guaranteed fix.
    • First check site assignment, available space, minimum age and server load. Too little concurrency can delay backups; increasing it too far can overload the server.
    • If you choose to request a manual backup for a selected site, wait for its result in Enhance. A submitted request or a load spike is not evidence of a completed backup.

Fixing Backups That Run at Random Times

What if the command from step 3 gives you wildly different times for different websites?

We like to keep things predictable. In the original setup, cPFence Owl load alerts shortly after 2 AM helped us notice the backup window. Load alerts are useful clues, but they cannot tell you which backups succeeded—use Enhance’s backup status for that.

If your backups are all over the place, the original tip was to let them become eligible before reopening a common window:

Before trying it: Blocking every allowed hour pauses automatic backups across the affected global policy. That leaves a gap in protection. Keep a verified recovery copy, record the old schedule and agree a bounded maintenance window; skip this workaround if you cannot accept missed backups.

  1. Find the most recent backup time—let’s say it’s 7 AM, but you want backups to start at 2 AM instead.
  2. Temporarily block automatic backup hours using the Allowed backup hours setting, only for the maintenance window you agreed.
  3. Let your backups get hungry—in other words, allow their minimum age to elapse, without extending the agreed backup gap.
  4. At 2 AM in the main control panel server’s timezone, reopen the intended window and save. Check that backups resume, then compare completed backup times. Restore the previous policy if the experiment does not help.

This may bring eligible sites into the same window, but it does not force simultaneous starts or fix a scheduler fault. If backups still run outside the saved window, collect the settings, timezone and affected timestamps for Enhance support instead of repeatedly pausing protection.

Enhance’s backup log reference gives journalctl -u orchd on the main control panel server and journalctl -u appcd on the source server. Review logs privately; a website file-permission error needs its own investigation.

Got it set up? Time to grab a coffee and let the automation do its job.

Add cPFence to Your Enhance Servers

Keep your backup plan and server protection working together. Explore cPFence v4+ for Enhance alongside your existing Enhance backups.

Start free trial
← Back to all articles
KEEP EXPLORING
All articles