Before You Begin
Before you configure networking settings for Cosmos DB accounts, make sure that your Azure environment meets the requirements listed in the following table. The scope of the requirements depends on whether you create cloud-native snapshots only or also store backups in a repository. Plan these changes in advance, as organization security policies may restrict them.
|
Requirement |
When Required |
Purpose |
|---|---|---|
|
Disabled public access to Cosmos DB account |
Always |
Disable public access so that the Cosmos DB account becomes unavailable through the public network. Veeam Backup for Microsoft Azure then connects to the account from within the private network. |
|
Only if you enable backup to a repository |
A private endpoint grants the backup appliance and the worker instances access to the cluster coordinator. Create a separate endpoint for every VNet to which worker instances are connected and select coordinator as the target sub-resource. |
|
|
Only if you enable backup to a repository |
The privatelink.postgres.cosmos.azure.com zone holds the DNS records of the private endpoints. Veeam Backup for Microsoft Azure components use these records to resolve the endpoint names to private IP addresses. Microsoft Azure creates the zone when you integrate the private endpoint with a private DNS zone. |
|
|
DNS configuration and virtual network links for private endpoints |
Only if you enable backup to a repository |
Add the DNS zone configuration to each private endpoint, create an 'A' record for the endpoint and link the zone to the VNets of the worker instances. Otherwise, the worker instances cannot resolve the name of the cluster to a private IP address. |
Considerations and Limitations
Before you start the deployment, review the following dependencies and limitations:
- When you create a private endpoint for the Cosmos DB for PostgreSQL account, click Yes to the right of the Integrate with private DNS zone field. It is recommended that you create the DNS zone in the same resource group where the backup appliance resides, to simplify resource management.
- To allow Veeam Backup for Microsoft Azure to update worker instances, the worker instances must have public access to the online Ubuntu repositories listed in section Ports.
- To store backups of Cosmos DB accounts in repositories that reside in a private network, you must also configure network settings for storage accounts as described in section Configuring Network Settings for Storage Accounts.