Veritas Flex Appliances with Netbackup Design Guide
Total Page:16
File Type:pdf, Size:1020Kb
Veritas Flex Appliances with NetBackup Design Guide Bringing resilient, scalable and fully integrated data protection from the edge to the core to the cloud. The Veritas Flex Appliance family delivers enterprise data protection services, both on-prem and in the cloud. This white paper highlights the solution benefits and features, use cases, architecture, best practices, sizing guidance and deployment of Flex Appliances with Veritas NetBackup™. Veritas™ White Paper | October 2020 Contents Introduction 3 Executive Summary 3 Scope 3 Target Audience 3 Flex Appliance Key Values and Features 3 Enable Consolidation and Increase Agility and Simplicity 4 Provide Multi-Tenancy with Network and Storage Segregation 5 Ensure Resilience and High Availability 5 Ransomware resiliency 6 Integrate and Automate with API 8 Support Fibre Channel 9 Flex Appliance Use Cases 9 Flex Appliance Models 10 Flex Appliance High-Level Architecture 11 Application Container Image and Instance 11 Flex Architecture Deep Dive: Platform as a Service Components 13 Management Plane 13 Control Plane 14 Resource Plane 14 Best Practices 14 Default Configuration 15 Performance Tuning 15 LUN Sharing 16 Sizing 16 Flex Appliance Deployment 17 Choose an Application Container Image 17 Create an Instance on a Flex Appliance 18 Monitoring 19 Conclusion 19 References 19 Versions 19 2 INTRODUCTION Executive Summary Today, the IT organization is more than the core data center It spans from the edge to the core and to the cloud, including virtual environments and hybrid clouds along with traditional data protection deployments One appliance model cannot meet the needs of all these different use cases Organizations must quickly adapt their data protection infrastructure to rapidly changing business environments IT organizations are also under increasing pressure to consolidate data protection solutions and to reduce costs The Veritas Flex Appliance family delivers enterprise data protection services, both on-prem and in the cloud Flex Appliances bring agility, resilience, scalability and simplicity to NetBackup data protection Using the simplified web interface, you can run multiple NetBackup and NetBackup CloudCatalyst deployments on a single Flex Appliance and create new deployments and upgrade in minutes without increasing your hardware footprint With Flex Appliances, you get enterprise-wide on-premises and cloud data protection delivered on demand that you can rapidly adapt to meet the changing requirements of the business (See Figure 1 ) Consolidation High Availability Ease of Use • Reduce data center foot print • Data protection services • Operational simplicity • Simplify management on demand • Install & upgrade NetBackup • Eliminate data center sprawl • Easy to bring in new line of services in minutes business & protect their data • Edge to core to cloud • Fast deployment protection on the same appliance • Reduce planned & • Automate with APIs unplanned downtime Figure 1: An overview of the benefits of Veritas Flex Appliances. Scope The purpose of this document is to provide technical details to assist in understanding the Flex Appliances with NetBackup solution This white paper describes the solution benefits and features, use cases, architecture, best practices, sizing guidance and deployment of Flex Appliances with NetBackup For installation, configuration and administration of each of the products discussed in this white paper, please refer to the appropriate Veritas product documentation Target Audience This document is for customers, partners and Veritas field personnel interested in learning more about the Flex Appliances with NetBackup solution It provides a technical overview, architecture, guidance in sizing and highlights some best practices FLEX APPLIANCE KEY VALUES AND FEATURES The Veritas Flex Appliance family is a new concept in delivering enterprise data protection services both on-prem and in the cloud Rather than relying on complex and costly data protection environments consisting of many converged or single-function backup, data deduplication, cloud tiering and storage silos spread across the enterprise, Flex Appliances offer a single, highly available and scalable solution that uses containerization to deliver enterprise-wide data protection services on demand Table 1 provides a summary of Flex Appliance benefits and features 3 Benefits Feature Description Adapts with DevOps-like agility to • Containers provide a lightweight, secure environment to run standardized versions of business needs NetBackup software • With no hypervisor, operating systems or NetBackup to install, admins can deploy new instances of NetBackup in minutes • Quick NetBackup upgrades Simplifies infrastructure and • Consolidate multiple NetBackup domains in a single Flex Appliance reduces costs • Containerization of NetBackup enables administrators to scale NetBackup’s powerful data protection capabilities quickly and easily to many customers on commodity hardware • MSDP container provides deduplication On-demand deployment of NetBackup • Create NetBackup media, primary and CloudCatalyst servers on demand • Run multiple versions of NetBackup software with a single Flex Appliance • Use a streamlined administration console to deploy NetBackup application container Adapts with DevOps-like agility to • Containers provide a lightweight, secure environment to run standardized versions of business needs NetBackup software • With no hypervisor, operating systems or NetBackup to install, admins can deploy new instances of NetBackup in minutes • Quick NetBackup upgrades High availability • Container isolation prevents a container application failure from impacting other applications • Deep monitoring of the primary server’s critical operation services provides remedial actions during the failure • The Flex Appliance Shell provides hardware component information • Auto-support and call home Security and compliance • Provide WORM capability, retention locks and platform hardening against ransomware and malware threats • Use SELinux to provide intrusion detection and prevention system Scalability • Add capacity as needed, non-disruptively and automatically Multitenancy • Data and network connectivity are segregated to each deployed container • Flex uses Veritas Optimized Operating System (VxOS) security profiles to control container access Long-term retention on-prem and in • Efficiently tiers to the cloud with CloudCatalyst containers the public cloud • Connect with the Veritas Access Appliance, a software-defined storage appliance for long-term data retention with multicloud capability Automate operations • Public APIs for integration and automation • Available for any operations on the UI Table 1: Flex Appliance Benefits and Features Enable Consolidation and Increase Agility and Simplicity Flex Appliances provide container support through use of containerization Table 2 lists the advantages of container technology compared to virtualization Containerization Virtualization Size 10s MBs Several GBs Boot time Almost instantly Several minutes Modularity Can split applications into modules for easy management and Not available enhanced security Table 2: Comparison of Containerization and Virtualization Comparison 4 With containerization, the NetBackup application container provides the following benefits: • Operational reliability when moved between nodes in the cluster • Increased modularity • Simplicity • Application/process isolation • Improved security • Faster startup and shutdown Provide Multi-Tenancy with Network and Storage Segregation All application containers running on Flex Appliances need to share the hardware resources of the node such as CPU, memory, disk I/O and network Flex Appliances use network and data segregation and the Veritas Optimized Operating System (VxOS) security features to provide multi-tenancy to customers Network Segregation Flex Appliances use the Macvlan network driver to assign a MAC address to each container’s virtual network interface; each MAC address is bound directly to a physical network interface This approach provides external connectivity to and from the containers as well as network isolation between them Macvlan provides the best network isolation for containers and allows NetBackup Appliance containers to use an actual IP address NetBackup instances on a Flex Appliance support multiple interfaces, included physical interfaces and bonded interfaces Support for multiple networks enables NetBackup media server instances to span multiple networks VxOS Security Features for Containers The VxOS kernel provides name spaces, control groups and secure computing mode to control processes and resources at the OS level Flex Appliances use these features to control access and manage resources Namespaces The concept of namespaces is a feature of the VxOS kernel that provides fundamental support for containers in VxOS Namespaces ensures a group of processes only sees its set of assigned resources and another group of processes only has access to its own, discrete services Neither group of processes can see the resources assigned to the other Control Groups Control groups (cgroups) provide resources management for the CPU, memory, disk I/O and networking Using cgroups protects an appliance from being taken down by one container consuming all available resources on the physical system Cgroups can be used to defend against denial-of-service (DoS) attacks on Flex Appliances Secure Computing Mode The VxOS kernel seccomp (secure computing mode) feature limits the