# Native Synology package: recommended way to back up protected files?

**URL:** https://forum.duplicati.com/t/native-synology-package-recommended-way-to-back-up-protected-files/22713
**Category:** Support
**Created:** [September 18, 2026, 7:50am UTC](https://forum.duplicati.com/t/native-synology-package-recommended-way-to-back-up-protected-files/22713 "2026-09-18T07:50:40Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![maxpow](https://forum.duplicati.com/user_avatar/forum.duplicati.com/maxpow/32/12866_2.png) [@maxpow](https://forum.duplicati.com/u/maxpow)
#### Post date: [September 18, 2026, 7:50am UTC](https://forum.duplicati.com/t/native-synology-package-recommended-way-to-back-up-protected-files/22713/1 "2026-09-18T07:50:40Z")

</div>

Hi everyone,

I’m using the official Duplicati 2.4.0.0 SPK on Synology DSM 7 and looking for guidance on source-file permissions.

My applications run in Docker on a separate machine, with their persistent data stored on Synology Volumes over NFS. Duplicati runs natively on the NAS (manually installed spk - not docker based) - and reads those files locally.

I’ve granted the `duplicati` system user read-only access to the shared folder. Most files back up successfully, but some are skipped:

- Files owned by root or application users, with Unix permissions such as `640`.
- Files with explicit Synology ACLs that don’t grant access to `duplicati`.

Here’s a short log sample:

```plaintext
Version: 2.4.0.0
ParsedResult: Warning
WarningsActualLength: 130
ErrorsActualLength: 0

[Warning-Duplicati.Library.Main.Operation.Backup.FileBlockProcessor.FileEntry-PermissionDenied]:
Excluding path due to permission denied: /volumeX/shared/stack/app/data/app.db

[Warning-Duplicati.Library.Main.Operation.Backup.FileBlockProcessor.FileEntry-PermissionDenied]:
Excluding path due to permission denied: /volumeX/shared/stack/app/config/notifications/service.yaml

```

The upload and remote verification succeed, but these source files are explicitly excluded. For two affected files, I confirmed that `duplicati` cannot read them while root can. I haven’t modified the package’s privileges.

Hyper Backup didn’t produce similar warnings; I suspect it have privileged access that the native Duplicati package lacks.

I found [this discussion about source-file permissions](https://forum.duplicati.com/t/permission-trouble-on-files/21479), where matching the Docker container’s UID/GID to the source owner resolved the issue, and [this older capabilities report](https://github.com/linuxserver/docker-duplicati/issues/41). My source files belong to several different application users, though, and Duplicati runs as the native DSM package.

**What’s the recommended, supported approach for the current native Synology package?** Is privileged read access available—for example through a helper or `CAP_DAC_READ_SEARCH`—in a way that survives package updates?

I’d prefer to avoid changing application-file permissions, installing Docker on the NAS, or maintaining a custom root-service setup.

Thanks for any guidance!

---

<div class="post-metadata">

### Author: ![maxpow](https://forum.duplicati.com/user_avatar/forum.duplicati.com/maxpow/32/12866_2.png) [@maxpow](https://forum.duplicati.com/u/maxpow)
#### Post date: [October 6, 2026, 6:37pm UTC](https://forum.duplicati.com/t/native-synology-package-recommended-way-to-back-up-protected-files/22713/2 "2026-10-06T18:37:50Z")

</div>

Quick follow-up: I ended up running Duplicati through Synology Container Manager instead of the SPK.

The main reason is permissions. On DSM 7, the SPK can’t run as root. You can grant it additional permissions, but it still can’t bypass filesystem permissions like root can.

Running the official Docker image as root solved this: I can mount the NAS folders directly into the container and Duplicati gets true root-level access to the local filesystem.

That was ultimately the deciding factor for me.
