A Backup Policy defines the backup schedule and the tiered retention settings for snapshots. Once defined, backup policies can be executed across AWS accounts at the organization level, and set to Active or disabled, depending on business requirements.
Setup policy to backup snapshots to Druva Cloud
Druva CloudRanger offers a simplified, global approach to backup policies, with options to define one or more policies to automate your backup schedule for EC2 backups to Druva Cloud.
Step 1: On the top navigation bar, select Policies, and then click Create Backup Policy.
Step 2: Specify the following policy Setup information:
Add a Name and a brief Description for your policy.
Select the Snapshot + Backup to Druva Cloud check box to move snapshots to Druva Cloud for all resources specified within the policy.
π Note
βEnsure that you have provisioned your Druva Cloud Storage and configured appropriate Storage Rules. A backup policy defined to move snapshots to Druva Cloud will be executed only when a corresponding Storage Rule is available.
The Prerequisites dialog displays information on getting started with Druva Cloud backups. You may click each step to be redirected to the individual pages to Provision Storage, set up Storage Rules, or manage Client Credentials. The icons indicate whether or not each of these steps have been successfully configured:
Step 3: Specify the backup Schedule.
Specify the backup Frequency.
Create backup every: Choose the backup frequency by day, week, month, or year.
βFor example:Backup every day every 30 minutes.
Backup every week on Monday every hour at 30 minutes past the hour.
Backup every month on the 1st day of the month every 30 minutes.
π Note
βWhen enabling a policy to backup data to Druva Cloud, the backup schedule must be set to an hourly frequency or higher. The following validation displays if the backup frequency is lower than an hour.
Backup Window [Optional]: Specify the backup from and to time in HH:MM notation.
βNote: This field applies only if you specify weekly backup every hour in the Create Backup Every field.Time Zone: Select the time zone that applies to the backup frequency specified.
Click Save & Continue.
Step 4: Specify the Resources for backup.
On the Resources tab, click Add to identify resources that you wish to include in the backup.
On the Identify Resources dialog, specify the filter criteria to identify specific resources to include or exclude.
How Include/Exclude conditions apply on Druva CloudRanger:
You can create multiple include and exclude rules.
Include rules: When multiple include rules are defined, this translates to an βORβ condition. In other words, resources are matched against each include rule, and do not have to meet all specified conditions concurrently.
Exclude rules: Exclude rules take precedence when the same resource is matched based on the include and exclude criteria selected.
When multiple tags are defined as part of include/exclude, this translates to an βANDβ condition.
Field | Description |
Find Resource types | Select the Resource Type, for example, EBS Volume, EC2, RDS, or Redshift. |
In account | Select the CloudRanger account associated with the AWS resources to be specified. |
And in regions | Select the applicable AWS regions, or select All regions. |
Match | Select the match criteria by Resource IDs, Tags, VPC IDs, Subnet IDs, or select All resources. Based upon the Match selected, you will need to specify the criteria values appropriate to that criteria. |
Similarly, on Exclude Resources, click Add to identify specific resources that you wish to exclude from the backup.
The resources identified are then displayed under Include or Exclude Resources, based on your selection criteria.
To eliminate a specific resource in the list from your backup policy, select the checkbox against that resource and click Remove.
Click Save & Continue.
β
Step 5: Specify the criteria for any additional backup Copies.
π Note
βCross-region and cross-account backups are not supported for Redshift instances.
Select the Save extra copies to other regions checkbox to create additional copies of your AWS backups in multiple regions.
You may specify up to two additional AWS regions to create copies in.Select the Save an extra copy to another account checkbox to create additional copies of your AWS backups in another CloudRanger account.
π Note
βThe Backup Copy Encryption is applicable only if one or more resources included in the policy is encrypted, and a backup is to be generated. If the source resource is encrypted, then an Encryption Key is applied to the backup operation.
The Backup Copy Encryption options are displayed only when a cross-region or cross-account backup is to be generated for encrypted snapshots.
To backup encrypted resources, you will need to define the association of keys between the source and the target regions for that backup. To do this, select the Target Key for each target region specified.
Under Resource Backup Options, you have the option to create backups of EC2 resources as AMIs or as snapshots. In the case of AMIs, you may also select your reboot preferences.
Step 6: Specify the backup Retention criteria.
π Note
βDruva CloudRanger follows the Grandfather-Father-Son (GFS) retention model. For more information on retention, please see About Retention for Backup Policies.
Specify the Tiered Retention criteria. The standard retention options are pre-populated, and you can modify these based on your business requirements.
All backups retained for: Select the retention duration in hours, days, weeks, months, or years.
Select the retention criteria for Weekly, Monthly or Yearly Backups.
β
EC2 and EBS snapshot retention: You may also specify the snapshot retention criteria. This retention applies to snapshots retained within your AWS environment post backup to Druva Cloud.
Do note that a master snapshot will still be retained, irrespective of the retention set here.Copy Options: Specify the retention criteria for any additional backup copies.
Select Same retention as source backup to retain the retention criteria.
Alternatively, you may specify the retention in hours, days, weeks, months, or years.
Click Save & Continue.
Step 7: Specify Additional Options for the backup.
Select the Execute VSS Consistent Scripts (Windows Only) checkbox to generate consistent snapshots for any Windows server with VSS installed.
π Note
For File level recovery, It is essential to take application-consistent snapshots. We recommend that you enable the Execute VSS Consistent Scripts (Windows Only) option at the policy level, to ensure data consistency during backup.
If the selected Backup Policy has servers defined that do not have VSS installed, then a standard AWS EBS snapshot is generated. For more information, see Generate VSS consistent snapshots for Windows servers.
Script Execution: The pre- and post-backup scripts feature offers enterprises the option to generate application-consistent snapshots for common applications like SQL Server. This ensures that the point-in-time snapshots will remain crash-consistent as well as application-consistent.
Select the Execute pre- and post-scripts for EC2 instances checkbox to enable script execution when creating a new backup policy.
In addition, you can manage backup generation in the event that the scripts configured are unavailable.Define the time limit to terminate script execution.
βFor example: Abort script execution in 5 minutesSelect the backup execution criteria if the script is unavailable.
Execute backup without the script: Selecting this option will execute the backup without the configured script.
Attempt backup execution with warning: Selecting this option will initiate the backup but fail it at the point of execution of the script.
Fail the backup and generate an error: Selecting this option fails the backup and generates an error corresponding to the backup failure.
π Note
βYou may configure scripts to specific resources from the main Scripts page. For more information, see Configure and Manage Backup Scripts.
Under EC2 Options specify whether the policy should generate an AMI or a Snapshot.
Take Snapshot: Select this option to generate a snapshot for each volume attached to the EC2 instance.
Take AMIs: Select this option to generate an AMI, and the reboot preferences. In addition, you many choose one of the following backup options for EC2 AMIs:
Backup root volume and data volumes (default): Enable this to backup both the data volumes and the root volume that contains the Operating System
Backup root volume only: In some cases, the EC2 instances may create a large amount of backup data, in which case you can choose to only backup the root volume and not the data volumes.
This option helps manage backup size and avoids the backup of the large data volumes, particularly for non-critical data.Create a second 'root volume only' AMI with each backup: Enable this to create a second AMI for all EC2 instances backed up by the policy, which will have the Block Device Mappings adjusted to only contain the root volume.
βThe backup retention, FLS as well as the Druva Cloud backup functionality will all work for this second AMI as expected. The second AMI is handled by the same job, and will begin to execute once the first AMI has completed. Both the AMIs will not be created together to prevent extra load on the instance.You may choose to Skip the backup of an EC2 resource if the AWS status check fails. If selected, any scheduled backups will be skipped in the event of an AWS status check failure due to network issues or hardware/software malfunction. The AWS status check failure or error could potentially result in data inconsistency, and we recommend backups be scheduled once the status checks are successful.
Under Add Tags to Backups specify the tags to be applied to each backup generated by the policy. Tags act as metadata to help identify and organize your AWS resources.
Based upon the Key selected, you will need to specify the appropriate Value. F or example:
βKey: Created by Policy; Value: New
βKey: Origin; Value: Specify Origin ID
Select the Inherit tags from Source checkbox to inherit or retrieve tags from the Origin servers and apply them to backups generated by the policy.
Click Save.
π Note
β To manage tags on existing snapshots, refer to AWS Management Console - Tag Editor.
The backup policy is now successfully defined and is displayed on the main Backup Policies page with the State toggle set to Active.
β
Migrate existing snapshots to a Druva Cloud-enabled policy
Druva CloudRanger allows you to import existing AWS backups into a policy that is enabled for backup onto Druva Cloud. You can manage all your backups within the retention period and backup schedules defined to ensure SLA compliance and reduce storage costs. Backups can be imported, regardless of whether they are tagged using specific tags in your AWS environment. Once imported, all backups will be managed based on the policy retention specified on the chosen policy.
To import existing backups into a backup policy enabled for Druva Cloud storage:
On the top navigation bar, click Policies and then select the policy you wish to import.
Click Import Backups.
The Import Backups popup displays.On the Find Backups tab, specify the criteria to locate specific backups.
π Note
β Ensure that the options specified here are relevant to the storage configured on Druva Cloud
Field | Desciption |
Find Backup Types | Select one or more backup types, for example, AMI or Snapshot. |
In accounts | Select the Druva CloudRanger account(s) to which the backups need to be imported. |
And in regions | Select the AWS regions to which the backup applies |
Match | Specify the tagging criteria:
|
4. Click Continue.
5. Review the policy retention on the Retention Review tab and then click Finish.
The resource backups are now imported into the selected backup policy, and the retention criteria for these new backups will be handled by that policy.
6. Select the backup policy and click Execute Now to migrate all imported snapshots to Druva Cloud based on the storage region configured.
π Note
βAll imported backups will be managed based on policy retention, and will now reside in Druva Cloud.
To manage tags on existing snapshots, refer to AWS Management Console - Tag Editor.
β
Next steps
While backup policies are automatically executed within the defined schedule, Druva CloudRanger offers options to execute your backup policies on demand. With the Execute Now feature, you can generate a manual (point in time) backup of a specific EC2 resource on Druva Cloud. For more information, see EC2 Airgap backup workflow.
π Note
Once your EC2 and EBS volumes are backed up successfully, you can choose to leverage Threat Hunting, a proactive approach to cybersecurity that involves actively searching for signs of malicious activity within your organization's network or systems.
Contact sales or support to procure the Threat Hunting for AWS Workloads (EC2 and EBS Volume) license to Get Started with Threat Hunting,