NetBackup™ for Cloud Object Store Administrator's Guide
- Introduction
- Managing Cloud object store assets
- Planning NetBackup protection for Cloud object store assets
- Enhanced backup performance in 11.0 or later
- Prerequisites for adding Cloud object store accounts
- Configuring buffer size for backups
- Configure a temporary staging location
- Configuring advanced parameters for Cloud object store
- Permissions required for Amazon S3 cloud provider user
- Permissions required for Azure blob storage
- Permissions required for GCP
- Limitations and considerations
- Adding Cloud object store accounts
- Manage Cloud object store accounts
- Scan for malware
- Protecting Cloud object store assets
- About accelerator support
- About incremental backup
- About dynamic multi-streaming
- About storage lifecycle policies
- About policies for Cloud object store assets
- Planning for policies
- Prerequisites for Cloud object store policies
- Creating a backup policy
- Policy attributes
- Creating schedule attributes for policies
- Configuring the Start window
- Configuring the exclude dates
- Configuring the include dates
- Configuring the Cloud objects tab
- Adding conditions
- Adding tag conditions
- Examples of conditions and tag conditions
- Managing Cloud object store policies
- Recovering Cloud object store assets
- Troubleshooting
- Error 5541: Cannot take backup, the specified staging location does not have enough space
- Error 5537: Backup failed: Incorrect read/write permissions are specified for the download staging path.
- Error 5538: Cannot perform backup. Incorrect ownership is specified for the download staging path.
- Reduced acceleration during the first full backup, after upgrade to versions 10.5 and 11.
- After backup, some files in the shm folder and shared memory are not cleaned up.
- After an upgrade to NetBackup version 10.5, copying, activating, and deactivating policies may fail for older policies
- Backup fails with default number of streams with the error: Failed to start NetBackup COSP process.
- Backup fails, after you select a scale out server or Snapshot Manager as a backup host
- Backup fails or becomes partially successful on GCP storage for objects with content encoded as GZIP.
- Recovery for the original bucket recovery option starts, but the job fails with error 3601
- Recovery Job does not start
- Restore fails: "Error bpbrm (PID=3899) client restore EXIT STATUS 40: network connection broken"
- Access tier property not restored after overwriting the existing object in the original location
- Reduced accelerator optimization in Azure for OR query with multiple tags
- Backup failed and shows a certificate error with Amazon S3 bucket names containing dots (.)
- Azure backup jobs fail when space is provided in a tag query for either tag key name or value.
- The Cloud object store account has encountered an error
- The bucket is list empty during policy selection
- Creating a second account on Cloudian fails by selecting an existing region
- Restore failed with 2825 incomplete restore operation
- Bucket listing of a cloud provider fails when adding a bucket in the Cloud objects tab
- AIR import image restore fails on the target domain if the Cloud store account is not added to the target domain
- Backup for Azure Data Lake fails when a back-level media server is used with backup host or storage server version 10.3
- Backup fails partially in Azure Data Lake: "Error nbpem (pid=16018) backup of client
- Recovery for Azure Data Lake fails: "This operation is not permitted as the path is too deep"
- Empty directories are not backed up in Azure Data Lake
- Recovery error: "Invalid alternate directory location. You must specify a string with length less than 1025 valid characters"
- Recovery error: "Invalid parameter specified"
- Restore fails: "Cannot perform the COSP operation, skipping the object: [/testdata/FxtZMidEdTK]"
- Cloud store account creation fails with incorrect credentials
- Discovery failures due to improper permissions
- Restore failures due to object lock
Features of NetBackup Cloud object store workload support
Table: Salient features
|
Feature |
Description |
|---|---|
|
Integration with NetBackup's role-based access control (RBAC) |
The NetBackup Web UI provides the Default cloud object store Administrator RBAC role to control which NetBackup users can manage Cloud object store operations in NetBackup. You do not need to be a NetBackup administrator to manage Cloud object stores. |
|
Management of Cloud object store accounts |
You can configure a single NetBackup primary server for multiple Cloud object store accounts, across different cloud vendors as required. |
|
Authentication and credentials |
Wide emphasis on security. For protecting a single Azure Blob Storage account, the storage account and access key must be specified. To protect the Azure blob storage account, the supported authentication mechanisms are Access key, Service Principal, and Managed Identity. For all S3 API-compliant cloud vendors, the Access key and Secret Key are supported. For Amazon S3, the Access Key, IAM role, and Assume role (for cross-AWS account) mechanisms of authentication are supported. For a complete list, see the NetBackup Compatibility Lists. |
|
Backup policy |
A single backup policy can protect multiple S3 buckets or Azure blob containers from one Cloud object store account. |
|
Intelligent selection of cloud objects |
Within a single policy, NetBackup provides flexibility to configure different queries for different buckets or containers. Some buckets or containers can be configured to back up all the objects in them. You can also configure some buckets and containers with intelligent queries to identify objects based on:
|
|
Fast and optimized backups |
In addition to full backup, NetBackup also supports different types of incremental schedules for faster backups. Accelerator feature is also supported for the Cloud object store policies. Enable checkpoint restart in the policy to be able to resume a failed or suspended job from the last checkpoint. You do not need to repeat the entire data transfer from the start of the job. This feature is not applicable for Dynamic multi-streaming backups. |
|
Granular restore |
NetBackup makes it easy to restore all objects in a bucket or container. It also lets you select which objects to restore by using a prefix, folder, or object-based views. You can narrow down a selection of backup images for restoration in NetBackup by providing a date and time range. |
|
Restore options |
NetBackup restore the object store data along with their metadata, properties, tags, ACLs, and object lock properties. NetBackup supports adding an arbitrary prefix to all objects when restoring. Consequently, it restores objects with a distinct name when it is desired to avoid any interference with the original objects. The Azure Data Lake files and directories, however, do not require a prefix. Instead, the files and directories are restored to a specified alternate location. By default, NetBackup skips overwriting objects that already exist in the Cloud object store to conserve bandwidth and cloud costs. You can modify this default behavior by using the Overwrite option, thereby enabling the restoration of copies to overwrite the copies stored in the Cloud object store. |
|
Alternate location restores |
You can select restore objects to:
|
|
Support for malware scan before recovery |
You can run malware scan of the selected files or folders for recovery as part of the recovery flow from Web UI and decide the recovery actions based on malware scan results. |
|
Dynamic multi-streaming |
This feature allows multiple backup streams to operate simultaneously for a single object store bucket/container, optimizing backup performance to meet the backup windows. Here are some advantages of Dynamic multi-streaming:
|
|
Scalability support for the backup host |
NetBackup Cloud object store protection supports configuring the NetBackup Snapshot Manager as a scalable backup host for cloud deployments, along with the media server. If you have an existing NetBackup Snapshot Manager deployment in your environment, you can use that as a backup host for Cloud object store policies. With NetBackup Snapshot Manager as the backup host, you do not need to configure multiple backup hosts for large jobs or create multiple policies to distribute the load across these backup hosts. Snapshot Manager can increase the number of data mover containers during a backup operation, and then reduce them when the protection tasks are completed. |
|
Object lock |
This feature lets you retain the original object lock properties and also provides an option to customize the object lock properties. If you use object lock properties on the restored objects, you can't delete those objects until the retention period is over, or the legal holds are removed. You can use the Object lock and retention properties without any configuration during policy creation and backup. |
|
Quick object change scan |
This feature significantly speeds up the NetBackup Accelerator resulting in faster backups. Apart from an object's modification time, NetBackup also checks for changes in the object's tags and user attributes to determine whether the object qualifies for an incremental backup. In those application environments, where metadata changes do not occur after the objects are created, you can use this option to skip these metadata checks that significantly increases the backup speed. Enabling this option speeds up change identification for Accelerator, as it skips the tags and attribute checks of the objects since the previous backup. However, the skipped objects are not backed up. Those object metadata changes which does not result in change in the modification time of the object are skipped. For more information, see the Knowledge article: https://www.veritas.com/content/support/en_US/article.100073853.html |