Why Connect Your Network-Attached Storage (NAS) to the Cloud?
Network-Attached Storage (NAS) units manufactured by Synology, QNAP, and Asustor are the gold standard for on-premises data redundancy. With multi-bay RAID arrays (RAID 5, RAID 6, or Synology Hybrid RAID), your data survives single or double physical drive failures.
However, an on-premises NAS remains vulnerable to environmental disasters, electrical surges, theft, and catastrophic ransomware outbreaks that encrypt local network shares. To achieve true compliance with the 3-2-1 Backup Rule (3 copies of data, across 2 different media, with 1 copy stored offsite), backing up your NAS directly to a secure cloud vault like Google Drive or Google Workspace is mandatory.
Need to ingest external web archives or direct download links straight into your Google Drive backup directory? Use SaveInDrive to bypass your local network entirely, preserving your NAS broadband bandwidth for scheduled offsite syncs.
Architecture Overview: Cloud Sync vs. Hyper Backup
If you operate a Synology NAS running DiskStation Manager (DSM 7.x), you have two distinct official packages available:
- Cloud Sync: Performs real-time or scheduled bidirectional/unidirectional folder synchronization. Files remain visible in Google Drive in their native format (e.g.
.docx,.mp4). Ideal for remote team collaboration. - Hyper Backup: Creates block-level, deduplicated, versioned backup archives (stored as proprietary
.hbkpackages). Supports point-in-time rollbacks and military-grade client-side encryption. Ideal for disaster recovery.
Step-by-Step: Backing Up Synology NAS to Google Drive
Method A: Setting Up Synology Hyper Backup (Recommended for Disaster Recovery)
- Log into DSM as Administrator and open Package Center. Install Hyper Backup.
- Open Hyper Backup, click the + icon in the bottom left, and choose Data backup task.
- Under Backup Destination, select Google Drive and click Next.
- A browser popup will prompt you to authenticate your Google account and grant OAuth scopes. Click Allow.
- Select your target Google Drive folder (e.g.,
/NAS_Offsite_Backup). - Choose which shared folders on your Synology NAS to protect.
- Enable Client-Side Encryption: Enter a strong 32-character master passphrase and save the recovery key file (
.key) in a secure password manager. This ensures Google cannot inspect your raw files. - Set an automated schedule (e.g., daily at 2:00 AM) and enable backup rotation (Smart Recycle) to retain 30 daily snapshots.
Method B: Setting Up Synology Cloud Sync (Recommended for Live Mirroring)
- Install Cloud Sync from Package Center.
- Click + to add a new cloud provider, choose Google Drive, and authenticate via OAuth.
- Configure task settings:
- Connection name:
Synology-to-GoogleDrive - Local path:
/volume1/Projects - Remote path:
/GoogleDrive/Projects_Mirror - Sync direction: Change to Upload local changes only (this prevents accidental deletions in Google Drive from wiping files on your NAS).
- Connection name:
- Optionally check Enable data encryption to encrypt files before they leave your local network.
Step-by-Step: Backing Up QNAP NAS to Google Drive (HBS 3)
QNAP users utilize Hybrid Backup Sync (HBS 3) to coordinate cloud replication:
- Open App Center on QTS and install HBS 3 Hybrid Backup Sync.
- Open HBS 3 → navigate to Storage Spaces → click Create → select Google Drive.
- Authorize your Google credentials and test connection latency.
- Navigate to Backup & Restore → click Create Backup Job.
- Select your source folders on the QNAP volume, designate the Google Drive storage space as destination, and enable QuDedup (QNAP's block-level deduplication algorithm to save bandwidth).
- Configure transfer policies: Enable SSL encryption, rate limiting (if working on shared office broadband), and schedule execution.
Managing Google Drive API Rate Limits on Large NAS Volumes
When executing an initial synchronization of millions of small files, NAS backup daemons can encounter HTTP 403: User Rate Limit Exceeded errors from Google's Drive API.
Best Practices to Avoid API Throttling:
- Batch Initial Transfers: Do not sync 10 TB in a single job. Split your backup into logical sub-tasks (e.g., Documents, Photos, Media) and run them sequentially.
- Adjust Worker Threads: In Cloud Sync settings, reduce concurrent upload threads from 10 down to 3–5 to avoid triggering Google's queries-per-second (QPS) thresholds.
- Exclude Temporary System Directories: Add exclusion filters for
@eaDir,.DS_Store,Thumbs.db, and temporary lock files.
Bandwidth Throttling and Traffic Shaping for Home Networks
Running a continuous multi-terabyte NAS upload can saturate your home or office internet connection, causing severe latency spikes (bufferbloat) for other users on Zoom calls or streaming video. To mitigate this:
- Enable Speed Limits in Synology DSM: Navigate to Control Panel → Network → Traffic Control. Create a rule for Hyper Backup or Cloud Sync capping outbound bandwidth during business hours (e.g., 9:00 AM to 6:00 PM) to 20% of your maximum upload speed, allowing 100% throughput overnight.
- Implement QNAP Schedule Policies: In HBS 3, open Services → Bandwidth Limits to configure scheduled rate limits based on time-of-day matrices.
Rsync and Rclone: The Command-Line Powerhouse for TrueNAS & Custom Linux NAS
If your storage array runs TrueNAS Core, TrueNAS SCALE, or custom Ubuntu Server ZFS storage pools, proprietary GUI packages like Hyper Backup are unavailable. The premier tool for open-source storage arrays is Rclone:
Configuring Rclone with Google Drive:
# 1. Install Rclone on your NAS:
curl https://rclone.org/install.sh | sudo bash
# 2. Configure encrypted Google Drive remote:
rclone config
# Name: gdrive-encrypted
# Type: crypt
# Remote: gdrive:/Backups/NAS_Crypt
# Encryption: AES-256-CTR with Poly1305
# 3. Execute automated backup script:
rclone sync /mnt/zpool/storage gdrive-encrypted: --fast-list --transfers 4 --checkers 8 --drive-chunk-size 64M --log-file=/var/log/rclone-nas.log --log-level INFO
Schedule this script via cron to run nightly at 3:00 AM for automated, military-grade encrypted cloud replication.
Verifying Backup Integrity and Test Restores
An untested backup is not a backup; it is merely an assumption. Implement a mandatory quarterly disaster recovery drill:
- Create a designated test restore folder on your NAS:
/volume1/Test_Restore. - Launch Hyper Backup or Rclone and execute a partial restore of at least 50 GB of random project directories.
- Compute SHA-256 cryptographic checksums of the restored files against the originals to verify bit-level integrity and confirm your decryption keys function flawlessly.
Frequently Asked Questions (FAQ)
Can ransomware on my computer infect files backed up to Google Drive via NAS?
If your computer is infected, ransomware can encrypt network shares on your NAS. If your NAS then syncs those encrypted files to Google Drive, the cloud files will be overwritten. However, if you use Hyper Backup with multi-version rotation, you can instantly roll back to an unencrypted snapshot taken the previous night.
Does Synology Cloud Sync upload faster than desktop clients?
Yes. Synology DSM runs directly on Linux with a dedicated gigabit network interface card, bypassing Windows desktop virtualization layers and sleep states.