Immutability
Veeam Plug-In for Google Cloud allows you to protect VM, Cloud SQL and Cloud Spanner configuration data stored in backup repositories from deletion by making the data temporarily immutable. To do that, backup appliances use Google Cloud Object Retention Lockhttps://docs.cloud.google.com/storage/docs/object-lock — once imposed, Object Retention Lock prevents objects from being deleted or overwritten for a specific immutability period. The immutability period is set based on the retention policy configured in the backup policy settings.
|
Note |
|
To reduce the number of requests sent to immutable repositories during VM, Cloud SQL and Cloud Spanner backup operations,backup appliances leverage the block generation mechanism. |
Considerations and Limitations
Before you start creating immutable backups, keep in mind the following limitations:
- Object Retention Lock and Object Versioning must be enabled for the Google Cloud bucket in which the immutable backup repository will be located. The default retention period must not be configured in the Object Retention Lock settings. For more information on the Object Versioning and Object Retention Lock features, see Google Cloud Documentation.
- Veeam Plug-In for Google Cloud does not support changes made to immutability settings in the Google Cloud Console for buckets that are already used as target locations for image-level backups.
- The service account that will be used to create the immutable backup repository and further to access the repository when performing data protection and recovery tasks must be assigned the permissions required to collect immutability settings of Google Cloud buckets and to create immutable backups. For more information on the required permissions, see Repository Permissions.
- You cannot manually remove immutable data from immutable repositories using the Veeam Plug-In for Google Cloud Web UI, as described in section Managing Backed-Up Data.
- You can neither remove immutable data from Google Cloud using any cloud service provider tools nor request the technical support department to do it for you. Since Veeam Plug-In for Google Cloud uses Object Retention Lock, none of the protected objects can be overwritten or deleted by any user, including the root user in your Google Cloud account. For more information on Object Retention Lock, see Google Cloud Documentation.
How To Create Immutable Backups
To protect backups created with Veeam Plug-In for Google Cloud from deletion by making them temporarily immutable, perform the following steps:
- Add a backup repository with immutability enabled.
- Create a backup policy and specify the backup repository with immutability enabled as the target location for image-level backups. For more information, see Creating VM Backup Policies, Creating SQL Backup Policies, Creating Spanner Backup Policies.