Guides / Heroku
Back up Heroku PostgreSQL to Cloudflare R2
Set up automatic, scheduled PostgreSQL backups from Heroku into your own Cloudflare R2 bucket โ with retention, optional encryption and failure alerts โ without writing a script or maintaining a cron server.
Why back up off-platform?
Heroku PGBackups is decent, but backups live in Heroku and are limited by plan. Shipping a copy to your own bucket makes migration off Heroku a one-command restore.
Zero egress fees and a generous 10 GB free tier make R2 the cheapest home for backups โ restoring never costs bandwidth.
Step 1 โ Find your Heroku database credentials
Run heroku pg:credentials:url -a your-app or open the Heroku Postgres add-on โ Settings โ View Credentials. SSL is required.
Then allow the Dumpling worker's static IP address 2.28.121.200 to connect. Keep SSL enabled โ Heroku requires it. For extra safety, create a read-only user; the exact GRANT statements are in the docs.
Step 2 โ Create a Cloudflare R2 bucket and access key
- R2 โ Create bucket.
- R2 โ Manage R2 API Tokens โ Create API token with Object Read & Write scoped to that bucket.
- Copy the Access Key ID, Secret Access Key and the S3 endpoint
https://<accountid>.r2.cloudflarestorage.com.
In Dumpling, the endpoint is https://<accountid>.r2.cloudflarestorage.com and the region is auto. R2 charges $0.015/GB-month with no egress fees. Ten GB is free forever, which covers most side projects entirely.
Step 3 โ Create the backup job
- Sign in (free, no card) and add the database from step 1. Dumpling tests the connection and reports the version and size immediately.
- Add the Cloudflare R2 bucket from step 2. Dumpling writes and deletes a tiny test object to confirm the key works.
- Create a job: pick a schedule (daily at 02:00 UTC is a good default), how many backups to keep, and optionally a passphrase to encrypt files client-side-decryptably.
The first backup starts right away. From then on, Dumpling runs pg_dump on schedule and streams the output straight into R2. Every run shows the object key, size, duration and log.
Restoring
Download the object from Cloudflare R2 and run:
createdb restored_db pg_restore --no-owner --no-acl -d restored_db 2026-09-10T02-00-01Z.dump
Encrypted files (.enc) decrypt with openssl enc -d -aes-256-cbc -pbkdf2; see the restore docs.
Prefer to do it yourself?
It is a few lines of shell โ the hard part is the machine to run it, retention, and knowing when it silently stops working:
# DIY alternative: a cron job on a server you maintain 0 2 * * * PGPASSWORD=... pg_dump -Fc -h HOST -U USER DB \ | aws s3 cp - s3://BUCKET/backups/$(date -u +%FT%TZ).dump --endpoint-url https://<accountid>.r2.cloudflarestorage.com # ...plus retention, alerting, and a machine to run it on.
Dumpling exists so you do not have to babysit that cron job. The free plan covers one database with daily backups forever.