Before You Begin

Before you configure networking settings for Cosmos DB accounts, make sure that your Azure environment meets the requirements listed in the following table. The scope of the requirements depends on whether you create cloud-native snapshots only or also store backups in a repository. Plan these changes in advance, as organization security policies may restrict them.

Before You Begin

Requirement

When Required

Purpose

Disabled public access to Cosmos DB account

Always

Disable public access so that the Cosmos DB account becomes unavailable through the public network. Veeam Backup for Microsoft Azure then connects to the account from within the private network.

Private endpoints for Cosmos DB for PostgreSQL account

Only if you enable backup to a repository

A private endpoint grants the backup appliance and the worker instances access to the cluster coordinator. Create a separate endpoint for every VNet to which worker instances are connected and select coordinator as the target sub-resource.

Private DNS zone for private endpoints

Only if you enable backup to a repository

The privatelink.postgres.cosmos.azure.com zone holds the DNS records of the private endpoints. Veeam Backup for Microsoft Azure components use these records to resolve the endpoint names to private IP addresses. Microsoft Azure creates the zone when you integrate the private endpoint with a private DNS zone.

DNS configuration and virtual network links for private endpoints

Only if you enable backup to a repository

Add the DNS zone configuration to each private endpoint, create an 'A' record for the endpoint and link the zone to the VNets of the worker instances. Otherwise, the worker instances cannot resolve the name of the cluster to a private IP address.

Considerations and Limitations

Before you start the deployment, review the following dependencies and limitations:

  • When you create a private endpoint for the Cosmos DB for PostgreSQL account, click Yes to the right of the Integrate with private DNS zone field. It is recommended that you create the DNS zone in the same resource group where the backup appliance resides, to simplify resource management.
  • To allow Veeam Backup for Microsoft Azure to update worker instances, the worker instances must have public access to the online Ubuntu repositories listed in section Ports.
  • To store backups of Cosmos DB accounts in repositories that reside in a private network, you must also configure network settings for storage accounts as described in section Configuring Network Settings for Storage Accounts.

Page updated 2026-10-09

Page content applies to build 13.1.1.18