Export files to Wasabi with rclone
Use rclone copy to export a local directory to Wasabi while keeping files that already exist only
at the destination. Then use rclone check --download --one-way to compare the uploaded bytes with
your local files. This walkthrough chooses a private bucket and a specific prefix, previews the
transfer, and turns the same commands into a repeatable export.
Choose a bucket and check the costs
You need a Wasabi account, an existing private bucket, its storage region, and access keys allowed to list, upload, and read objects in the chosen prefix. If you do not have a bucket, create one in the Wasabi console first. Keep public access disabled. Configuring an rclone remote does not create a bucket; the commands below deliberately use an existing one.
Wasabi exposes an S3-compatible API. Its standard Pay-Go pricing has a 1 TB monthly minimum and a 90-day minimum storage duration; deleting objects sooner can leave charges for the remaining days. Free egress is intended for monthly downloads no greater than your active storage volume, and repeated excess can lead to service limits or suspension. Free API requests also have a reasonable-use policy. Check Wasabi’s pricing FAQ against your plan before uploading test data. A tiny export does not imply a tiny monthly bill.
Configure rclone for Wasabi
Installation
Install rclone using its official installation instructions, then check the version:
rclone version
The shell examples use Bash on Linux. The transfer commands were exercised with rclone 1.75.1 against a local S3-compatible service; that does not verify a live Wasabi account’s permissions or regional connectivity. Keep the source directory unchanged during copying and checking. These examples export regular files, not a complete filesystem backup with permissions and symlinks.
Configuration
Start the interactive configuration:
rclone config
Use these values, following Wasabi’s rclone setup guide. Type the backend and provider values instead of relying on menu numbers, which can change:
- Create a remote named
wasabi. - Set the storage backend to
s3, then the provider toWasabi. - Set
env_authtofalseand enter your Wasabi access key and secret key at the prompts. The prompts call them AWS credentials because this is the S3 backend. - Leave
regionempty as in Wasabi’s guide, and setendpointto the service URL for your bucket’s actual region. - Leave
location_constraintempty for this existing bucket. It is used when creating buckets. - Set
acltoprivate, leave other options at their defaults, and save the remote.
For example, US East 1 accepts s3.us-east-1.wasabisys.com or s3.wasabisys.com; Amsterdam uses
s3.eu-central-1.wasabisys.com. Match the bucket location to
Wasabi’s endpoint table.
The console URL is not an S3 endpoint. A private object ACL does not undo a public bucket policy.
Security considerations
Keep credentials out of scripts and shell command arguments. Find the configuration file actually in use with:
rclone config file
Restrict access to that file and its backups. For scheduled jobs, use an explicit configuration path
through RCLONE_CONFIG or --config; see rclone’s
configuration documentation. Use a dedicated Wasabi
identity with access limited to the intended bucket/prefix. A copy job does not need permission to
delete destination objects. The optional mirror later in this article does.
Copy a directory and verify its contents
Copy files
In one Bash session, set an absolute local source path and replace the bucket name below. Use a
prefix reserved for this export, such as exports/project-a, rather than the bucket root:
src='/absolute/path/to/export'
dst='wasabi:your-existing-bucket/exports/project-a'
rclone lsf "$dst" --recursive
An empty listing can mean a new prefix; a nonzero exit means you must resolve the error before continuing. Preview the selected files without uploading:
rclone copy "$src" "$dst" --s3-no-check-bucket --checksum --exclude '*.tmp' --dry-run
The --s3-no-check-bucket option prevents rclone from
checking for or trying to create a bucket. A misspelled bucket still fails when accessed.
--checksum compares size and available checksums when deciding whether to replace a file.
copy preserves destination-only objects, but can overwrite an existing object with the same
name. It is not a versioned backup. See the copy command reference.
When the preview shows the intended source and prefix, run the copy and then the check:
rclone copy "$src" "$dst" --s3-no-check-bucket --checksum --exclude '*.tmp' &&
rclone check "$src" "$dst" --download --one-way --exclude '*.tmp'
The directory’s contents go directly into the prefix: report.pdf becomes
exports/project-a/report.pdf, without an extra export/ directory. Empty directories do not
become objects. An empty source can complete successfully without transferring anything; confirm
that you selected the expected files.
Read back the uploaded bytes
check --download reads the remote data and compares it
with the local files. It does not rely solely on object metadata or ETags. --one-way permits
extra destination files, matching the copy policy. The same exclusion must appear on both commands.
Success means the included source files match their remote counterparts at check time. A mismatch, missing object, or read error produces a nonzero exit status. The check downloads the included objects, so allow time and bandwidth and account for that traffic under Wasabi’s egress policy. For a nonempty source, expect a matching-file count and no differences.
Adjust what gets transferred
Filtering files
The quoted --exclude '*.tmp' pattern skips temporary files at any depth. Quoting keeps Bash from
expanding the pattern before rclone sees it. Excluding a file from copy leaves any existing remote
copy untouched. If you change the selection, apply the same
filter to the preview, copy, and check.
Parallel transfers
Rclone defaults to four simultaneous file transfers. Add --transfers=8 to the copy command if
measurements show it helps your workload; more concurrency can also increase resource use.
See the --transfers option.
Bandwidth control
Add --bwlimit=10M to cap transfer bandwidth at 10 MiB/s. Apply it to the download check as well
if verification should use the same limit. Rclone’s
bandwidth documentation also covers schedules.
Repeat the verified export
Save this as export-to-wasabi.sh. It accepts the same source and destination as the manual
commands, rejects a missing source directory, and stops if either copying or verification fails:
#!/usr/bin/env bash
set -euo pipefail
src=${1:?Pass a local source directory}
dst=${2:?Pass a wasabi:bucket/prefix destination}
if [[ ! -d "$src" ]]; then
printf 'Source directory does not exist: %s\n' "$src" >&2
exit 1
fi
rclone copy "$src" "$dst" --s3-no-check-bucket --checksum --exclude '*.tmp'
rclone check "$src" "$dst" --download --one-way --exclude '*.tmp'
Run it with the paths already selected:
bash ./export-to-wasabi.sh "$src" "$dst"
For a scheduler, supply absolute paths to Bash, the script, source, and configuration file. Ensure
rclone is on the job’s PATH, capture its output, and treat a nonzero status as a failed export.
Avoid overlapping runs. A rerun can replace changed files, but files removed locally remain in the
bucket. Schedule this copy script only if that retention behavior fits your needs.
Sync files
Use a mirror only when destination-only files should be deleted. With the same src and dst,
rclone sync changes only the chosen destination prefix.
If it contains old-report.pdf that is absent locally, copy keeps it and sync removes it.
Objects outside exports/project-a/ are outside this command’s scope.
Preview the mirror separately:
rclone sync "$src" "$dst" --s3-no-check-bucket --checksum --exclude '*.tmp' --dry-run
Read the planned deletions and recheck both paths. An existing but empty source can delete every
included object in the destination prefix. Excluded .tmp objects remain because this command
does not use --delete-excluded. A preview does not freeze the source or destination.
Only if those deletions are intentional, run:
rclone sync "$src" "$dst" --s3-no-check-bucket --checksum --exclude '*.tmp'
This requires delete permission. Object retention settings can block deletion, and Wasabi’s minimum storage duration can leave charges after deletion. Keep this choice separate from the non-deleting export script.
Diagnose a failed export
Common issues
- Access denied: check the credentials and permissions for this bucket/prefix. A successful
listing does not establish upload or download permission. Listing every bucket with
rclone lsd wasabi:may be denied even when access to your chosen bucket works. - Wrong endpoint or signature errors: compare the remote’s endpoint with the bucket region and check the machine’s clock. A connection reset alone does not identify a region mismatch.
- Missing configuration in a job: run with the intended
RCLONE_CONFIGor--configpath and confirm that the job’s user can read it. - Verification differences: keep source files stable, confirm both commands use the same filters, and investigate the reported filenames before accepting the export.
Debugging
Add -v to the failing command for file-level information. Use -vv for debug logging when needed,
and redact credentials, sensitive paths, and object names before sharing logs. A dry run checks the
planned actions; it does not prove that Wasabi will authorize the eventual writes.
If you need to export the results of a Transloadit workflow, see the 🤖 /wasabi/store Robot in our File Exporting service.
