CloudnRoll Blog

  • Participation in the Veeam Community Weekly Recap number 161

    Participation in the Veeam Community Weekly Recap number 161

    The Veeam Community Weekly Recap is available with incredible content and relevant information! Congratulations to Nico Losschaert, Brad Linch, Christian Eromosele, and Philippe Dupuis for the posts and articles.

    Thanks so much to Madalina Cristil, Mark Boothman, and Safiya Mohamed for the opportunity to participate! I am honored.

    Link:
    Back Up Audit, Hidden Cloud Costs and Active Directory Rename | Veeam Community Resource Hub


  • Integrating Veeam with HPE Alletra MP B10000 and GreenLake

    Integrating Veeam with HPE Alletra MP B10000 and GreenLake

    The integration of Veeam backups with the HPE Alletra MP B10000 block storage family is both straightforward and highly efficient, utilizing native APIs and the intuitive graphical management console.

    Furthermore, the Virtual Lock capability provides advanced ransomware protection through robust, immutable snapshots, ensuring that critical data remains safeguarded against accidental deletion or Ransomware attacks.

    The HPE Alletra Storage MP B10000 serves as both primary production storage and the initial point of Veeam recovery integration. By creating primary storage snapshots directly at the source where data is generated, protection begins immediately, thereby reducing the risk of data loss and enabling rapid recovery through Veeam’s Instant Recovery feature.

    In addition, the integration supports application-consistent snapshots, enabling either full VM recovery or granular restores, delivered at primary storage speeds without impacting the production performance of critical applications, such as datastores.

    HPE Alletra MP B10000

    HPE Alletra Storage MP B10000 delivers mission-critical storage at mid-range economics with the industry’s first disaggregated, scale-out block and file storage with 100% data availability. 

    Built on the new HPE Alletra Storage MP modular, disaggregated platform and managed via HPE GreenLake, this enhanced storage delivers a cloud-like experience with efficient scaling, extreme resilience, and top-tier performance for mission-critical applications.

    It combines HPE’s best-in-class technologies:

    • High-performance hardware from the Alletra Storage MP platform.
    • All-flash and NVME.
    • Proven enterprise SDS capabilities from the 3PAR code stream (including HPE 3PAR, Primera, and Alletra 9000).
    • Built-in AI for automation and self-healing.
    • Hybrid-cloud management.
    • Effectively, an all-in-one resilient data solution.

    Reference: https://www.hpe.com/psnow/doc/a50006985enw

    Cyber‑resilience Against Ransomware

    The HPE Alletra MP B10000 integrates built‑in ransomware detection directly into its storage operating system, providing organizations with proactive defense at the data layer. By applying anomaly detection methods, the system can identify suspicious encrypted I/O operations in real time and generate immediate alerts for potential ransomware activity.

    This adaptive technology can detect both traditional ransomware patterns and advanced variants that may evade conventional signature-based detection.

    When ransomware detection is enabled on a source storage volume, it can also be activated on the corresponding replication target volume, ensuring that both production and backup environments benefit from continuous monitoring. This dual protection delivers critical visibility and awareness, helping organizations prevent catastrophic consequences and maintain operational continuity.

    From a cyber‑resilience perspective, this capability strengthens the defense‑in‑depth model by combining prevention, detection, and recovery.

    The Alletra MP B10000 not only secures primary data but also ensures replicated copies remain uncompromised, aligning with Veeam’s 3‑2‑1‑1‑0 backup strategy.

    While the HPE Alletra immutable snapshots orchestrated by Veeam provide guaranteed recovery points, Alletra’s real‑time detection ensures that recovery points are free from compromise. The ransomware detection capability in the B10000 supports integration with third-party security solutions, including security information and event management (SIEM) and extended detection and response (XDR).

    Exploring the HPE GreenLake

    HPE GreenLake is Hewlett Packard Enterprise’s cloud platform, purposefully designed to streamline and modernize IT operations. It provides a unified framework that integrates on‑premises resources across storage, computing, networking, and public-cloud environments, enabling organizations to manage hybrid infrastructures more efficiently.

    Unlike conventional cloud offerings, HPE GreenLake delivers exceptional flexibility in both management and consumption models. Customers can choose to manage the platform themselves, delegate management to HPE, or adopt a hybrid approach. Consumption options are equally versatile, supporting both OpEx and CapEx financial models to align with diverse business strategies.

    Originally introduced as an as‑a‑service IT consumption model, HPE GreenLake has evolved into a comprehensive hybrid cloud platform. Today, it encompasses advanced capabilities such as multi‑vendor and multi‑cloud observability with AIOps, hybrid management and orchestration, integrated data protection and disaster recovery, cloud cost optimization, and a unified data platform.

    HPE Alletra Storage MP B10000, integrated with HPE GreenLake, delivers a single platform with a unified storage management paradigm.  The focus is on orchestration and automation to streamline operations and enhance efficiency.

    Like other cloud platforms, HPE GreenLake is delivered through a unified interface, the HPE GreenLake Central, which provides streamlined access to a broad portfolio of services consoles.

    In this context, the Data Services Cloud Console (DSCC) serves as a cloud‑based control plane for managing the entire storage lifecycle. Customers can shift from LUN-centric to AI-driven, app-centric storage provisioning. No storage domain expertise is required, and no more guesswork.

    With DSCC, storage provisioning time is reduced from days or weeks to minutes, enabling line-of-business owners and app admins to self-provision storage to accelerate app deployment, freeing up IT resources to focus on strategic, higher-value initiatives.

    It enables agile provisioning of volumes and pools, storage fleet management, simplifies performance and monitoring, protects workloads with integrated backup and recovery, optimizes resources with intelligent insights, automates operations through policies and APIs, and provides centralized storage management across hybrid environments.

    Among the options available in the Data Services Cloud Console (DSCC), the HPE GreenLake for Block Storage service focuses on storage lifecycle management, including block provisioning, native replication, and snapshot‑based data protection and recovery. Block Storage service enables fast and efficient provisioning, security, and management of application volume sets.

    The intended users for the Block Storage are application administrators and users who need to provision and expose storage to their application hosts, but who do not necessarily require access to or knowledge of the underlying storage arrays.

    In HPE GreenLake Block Storage, creating new volumes is intuitive and efficient. For the Veeam configuration procedure outlined below, a dedicated volume has already been provisioned on the HPE Alletra MP B10000 system: V035‑veeam‑vol.

    Ransomware detection can be enabled on a per‑volume basis. When an attack is detected, the system automatically generates a read‑only alert snapshot of the affected volume.

    Administrators can then compare this alert snapshot with an existing immutable snapshot already stored in the system. This comparison confirms whether an attack occurred and helps identify the specific data that was affected.

    The alert snapshot serves as a valuable resource for forensic investigation and validation, while data recovery is performed from the immutable snapshot. This ensures both the integrity of information and the continuity of services, even in the event of a ransomware incident.

    Reference: https://www.hpe.com/psnow/doc/a00146263enw.pdf

    The Data Ops Manager service is HPE’s central management hub for storage arrays. It enables system administration, replication configuration, performance monitoring, and host management from a single console.

    At the same time, storage provisioning and protection are managed separately through dedicated applications, such as Block, File, and Object Storage services.

    The intended users of Data Ops Manager are cloud operators and anyone responsible for managing the organization’s infrastructure and storage fleet.

    A host group in the Data Ops Manager service is a logical collection of hosts (servers or nodes) that enables collective management of storage access. This configuration allows simultaneous presentation of storage volumes to multiple hosts, such as those in VMware clusters.

    In the environment used to demonstrate the integration of the HPE Alletra MP B10000 with Veeam Backup & Replication, a host group has been created and associated with the dedicated volume V035‑veeam‑vol.

    Similarly, three virtual servers have been configured on this host to access the V035‑veeam‑vol volume on the HPE Alletra MP B10000.

    The connection between the host and the Alletra is established through the iSCSI protocol.

    Adding HPE Alletra Storage MP B10000 to Veeam Storage Infrastructure

    Reference: https://helpcenter.veeam.com/docs/vbr/userguide/hp_3par_add.html?ver=13

    Before adding HPE Alletra to the Veeam Backup & Replication Storage Infrastructure, the HPE Web Services API (WSAPI) server must be enabled. Veeam Backup & Replication relies on the WSAPI server to communicate with HPE Alletra Storage MP B10000 systems. Therefore, ensure that the WSAPI server is active before use, and enable it if necessary:

    https://helpcenter.veeam.com/docs/vbr/userguide/storage_configure_enable_web.html?ver=13

    In the VBR console, open the Storage Infrastructure view. In the working area, click Add Storage.

    In the displayed window, click Hewlett Packard Enterprise.

    In the Add HPE Storage window, select HPE Alletra/Primera.

    Specify HPE Web Services API Address and Storage Role.

    In the DNS name or IP address field, enter a full DNS name, or IPv4 or IPv6 address of the server.  In the Web Services API server URL field, enter a URL of the HPE Web Services API Server. For Alletra Storage MP B10000, use https://< websapiserver>:443.

    In the Role section, select the Block or file storage for VMware vSphere checkbox to enable VMware backup.

    At the Credentials step of the wizard, specify credentials for a user account with administrator privileges on the HPE Web Services API Server.

    At the VMware vSphere step of the wizard, select the iSCSI option to access the storage system. In the Volume to Scan section, select the Choose option.

    Select the volumes using the wildcard option.

    Search for the volume you created in the GreenLake console. In this example, V035*.

    Click on OK.

    Back in the VMware vSphere configuration, keep the automatic selection for the backup proxies to use and click on Apply.

    The verifications will be performed. After concluding, click on “Next”.

    Review the summary information, then click Finish.

    Backup job using Alletra MP B10000 snapshots and immutability

    In the VBR console, create a new VM backup job.

    Enter a name for the job.

    Select the VM you want to protect.

    In the Backup Repository field, select the option HPE Alletra/Primera Snapshot (Primary storage snapshot only).

    Make the snapshot immutable for the desired time. In this example, 03 days. HPE Alletra will use the Virtual Lock feature to keep this snapshot immutable.

    If desired, you can enable a secondary destination for this jo – backup copy job.

    If necessary, Veeam supports Application‑Aware Processing (AAP) in backups created from HPE Alletra MP snapshots, generating transactionally consistent restore points for applications.

    Select the desired schedule for the backup job.

    Review the configuration, select the option Run the job when I click Finish and click on Finish.

    The job will be executed. Note that the immutable storage snapshot is created on the HPE Alletra MP B10000, and the backup job completes successfully.

    Go to the Storage Infrastructure option in the VBR menu and select HPE Alletra/Primera. Expand the folder until you see V035-veeam-vol, then locate the snapshot.

    Select the snapshot and choose the Delete Snapshot option. The operation will fail, the snapshot will not be removed, and a message will be displayed: Storage snapshot is protected (immutable). The snapshot can be deleted only after the retention period defined in the backup job (three days) has expired.

    By accessing the HPE GreenLake console and navigating to Data Services > Block Storage > Configured Volume, we can confirm that the snapshot is set to read‑only and that Virtual Lock (immutability) is enabled for three days, as specified in the backup job configuration.

    Veeam Instant Recovery from HPE Alletra MP B10000 snapshot

    Go to Storage Infrastructure and select HPE Alletra/Primera. Expand the folder until you see V035-veeam-vol, then click on the snapshot.

    Locate the protected VM, right‑click on it, and select Instant recovery.

    Confirm the selected VM.

    Let’s restore to the original location.

    Let´s inform the restore reason.

    Verify the summary, select the connect VM to the network, and Power on the target VM after restoring options. Click on Finish.

    A warning message will be presented. Click on Yes.

    The instant restore procedure is performed.

    Now, select the Instant recovery job and click on Migrate to Production.

    Confirm or adjust the destination configurations.

    Keep the automatic proxy selection.

    Review the summary and select the option to delete the source VM file after a successful quick migration. Click on Finish.

    Conclusion

    Integrating the HPE Alletra Storage MP B10000 with Veeam Backup & Replication empowers organizations to achieve faster, more reliable, and more secure data protection. Through efficient storage snapshot orchestration, backup windows are significantly reduced, and production impact is minimized, enabling rapid, consistent backups.

    The HPE Alletra MP B10000 further strengthens ransomware resilience with native immutability features, including HPE Virtual Lock and integrated ransomware detection within its storage operating system. These capabilities align seamlessly with Veeam’s 3‑2‑1‑1‑0 best‑practice rule, ensuring that immutable snapshots orchestrated by Veeam remain uncompromised.

    This integration establishes a cyber-resilient foundation at the data source, providing rapid data access (1+ million IOPS and sub-1ms latency), 100% guaranteed availability, high‑speed data recovery, low RPO, simplified management, and the ability to consume on-demand resources through the HPE GreenLake offering.

    Additional References

    https://www.hpe.com/us/en/greenlake.html

    https://helpcenter.veeam.com/docs/vbr/userguide/transport_modes.html?ver=13

  • Os Desafios da Cibersegurança no Setor de Saúde Brasileiro

    Os Desafios da Cibersegurança no Setor de Saúde Brasileiro

    Em 2025, o Brasil ocupa a 2ª posição no ranking mundial de países mais atacados por ameaças cibernéticas.

    As empresas brasileiras são alvo de ciberataques devido ao alto valor dos dados, à baixa maturidade em segurança digital e ao uso ainda deficiente de ferramentas de proteção.

    O setor de saúde se tornou o principal alvo de ataques de ransomware no Brasil.

    Apenas em 2024 no Brasil, estima-se que ocorreram mais de 16 mil tentativas de ataque de ransomware no setor. Isso acontece pois os dados médicos têm um valor muito alto e permitem maior sucesso aos cibercriminosos durante o processo de extorsão

    Com este aumento brutal de ataques, estima-se que 75% das organizações de saúde vão sofrer ataques de ransomware até o final de 2025 no Brasil.

    Quando os ataques são bem-sucedidos, os custos médios relacionados com violações de dados são de mais de 11 milhões de reais, os maiores entre todos os setores.

    O grande problema é que, em média, as organizações de saúde levam até um mês para se recuperar de um ataque de ransomware.

    Todo este contexto resulta em enormes danos, como:

    • Paralisação de serviços médicos, incluídos procedimentos cirúrgicos e de emergência.
    • Vazamento de prontuários e dados dos pacientes.
    • Enormes prejuízos financeiros devidos à interrupção.
    • Perda de confiança pública.

    Para entendermos a dimensão do desafio, no setor de saúde global, estima-se que mais de 195 milhões de registros de pacientes foram sequestrados no ano passado.

    Além disso, um estudo com mais de 640 organizações do setor confirma que 20% das organizações de saúde experienciaram um aumento na taxa de mortalidade dos pacientes após um ciberataque significativo.

    Além disso, mais de metade afirmaram ter registado piores resultados na evolução dos pacientes, sendo que quase metade reportou um aumento nas complicações médicas

    Para confirmar este levantamento, outro estudo revela que 64% das organizações entrevistadas relataram que um ataque ocasionou atrasos nos procedimentos ou exames.

    Há outros desafios de cibersegurança significativos no setor de saúde, como o espalhamento dos dados e dos usuários, a adoção de novos tipos de aplicações, as regulamentações do setor local se tornam cada vez mais rígidas e as interrupções não planejadas ainda são um problema para a continuidade dos negócios.

    Todo este contexto se reflete na criação de silos tecnológicos, num aumento da complexidade e, consequentemente, dos custos operacionais

    Diante do cenário alarmante apresentado, fica evidente que o setor de saúde brasileiro enfrenta uma crise silenciosa, mas devastadora, no campo da cibersegurança. O crescimento exponencial dos ataques de ransomware, aliado à vulnerabilidade estrutural das instituições, coloca em risco não apenas dados sensíveis, mas vidas humanas.

    A paralisação de serviços médicos, o vazamento de informações confidenciais e o impacto direto na saúde dos pacientes revelam que a segurança digital deixou de ser uma questão técnica para se tornar uma prioridade estratégica e ética.

    Para mitigar esses riscos, é urgente que as organizações de saúde invistam em maturidade digital, implementem políticas robustas de cibersegurança, promovam a capacitação contínua de suas equipes e estabeleçam planos de resposta a incidentes eficazes. A transformação digital precisa caminhar lado a lado com a resiliência cibernética. Só assim será possível proteger o que há de mais valioso: a confiança da sociedade e a vida dos pacientes.

    Referências:

    Brasil:

    1 – https://inforchannel.com.br/2025/07/25/o-setor-de-saude-se-tornou-o-alvo-preferido-de-ataques-de-ransomware/

    2 – Ransomware contra o setor da saúde cresce 146% | TI INSIDE Online

    3 – Aumento de ataques cibernéticos ao setor de saúde exige resposta rápida para minimizar impactos

    4 – Abranet | Notícias

    5 – Kaspersky: novo estudo mostra aumento das vítimas de ransomware no Brasil

    6 – Two-Thirds of Healthcare Organizations Hit by Ransomware – A Four-Year High, Sophos Survey Finds | Sophos

    Global:

    1 – 2024 Was Another Bad Year for Healthcare Ransomware Attacks

    2 – Study Confirms Increase in Mortality Rate and Poorer Patient Outcomes After Cyberattacks

    3 – Healthcare cyberattacks led to worse patient care, increased mortality, study finds | Healthcare Dive

  • Zerto 10.8: New Features for Cyber Security, Resilience, Interoperability and Simplicity

    Zerto 10.8: New Features for Cyber Security, Resilience, Interoperability and Simplicity

    HPE released a new version of the Zerto software, featuring many new capabilities and improvements. Why does this matter to customers?

    • Compliance with Security Standards: HPE Zerto version 10.8 complies with critical US federal government security standards (FIPS 140-2/3) and has received attestation of compliance from the Cybersecurity and Infrastructure Security Agency (CISA). HPE Zerto helps federal agencies comply with FISMA, DFARS 800-171, NIST 800-53, NIST CFS, CIS Level 1, ISO 27001 & 9001, HIPAA, PCI, and GDPR.
    • Improved Security Posture: From enhanced operational controls to encryption and host attestation, Zerto 10.8 helps customers meet modern security and compliance standards.
    • Cloud Agility & Coverage: Expanded region and OS support in AWS and Azure, plus tools for AWS architecture transition, make cloud DR more scalable and cost-effective.
    • Operational Simplicity: Automated upgrades, centralized logging, and improved UI reduce administrative overhead and provide centralized security oversight.
    • Resilient Recovery: Native integration with CrowdStrike, APIs for a new Integration Hub with third-party cybersecurity solutions, faster recovery from an isolated vault using HPE Alletra immutable snapshots, and improved VRA startup ensure rapid, clean recovery from threats and outages.
    • Future-Ready Architecture: Support for VMware VCF 9.0 and more advanced interoperability options positions customers for hybrid and multi-cloud evolution.

    Let’s take a look at each of the new significant capabilities in Zerto 10.8.

    Compliance with Security Standards

    Compliance with FIPS

    HPE Zerto version 10 U8 complies with critical US federal government security standards (FIPS).

    Federal Information Processing Standard (FIPS) is a U.S. government standard for cryptography required on federal systems.

    With FIPS-validated encryption as of version 10 update 7, HPE Zerto satisfies federal standards for encrypted data, helping to reduce risk across critical IT environments for federal agencies, contractors, and other security-conscious organizations.

    CISA attestation of compliance

    With the Cybersecurity and Infrastructure Security Agency (CISA) attestation, HPE Zerto formally declares alignment with the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF) as of version 10 update 8.

    It is now required for software suppliers to federal agencies. It affirms that HPE Zerto is developed in accordance with rigorous security practices designed to reduce cyber risk across U.S. government systems and their supply chains.

    The SSDF framework outlines best practices that include secure coding, vulnerability management, the implementation of security controls, and the maintenance of a Software Bill of Materials (SBOM).

    Broadcom VMware

    ICMP Echo (Ping) Management

    Starting with Zerto 10.0_U7, Zerto blocked ICMP Echo (Ping) as part of security hardening, reducing the risk of reconnaissance, denial-of-service, and other ICMP-based attacks.

    Versions 10.7.20 and 10.8 introduce a new CLI option (Option 10: ICMP Echo (Ping) Management) that enables or disables ICMP Echo as needed.

    • Default: Disabled (recommended for security).
    • Behavior: If re-enabled, a warning message is displayed, highlighting the associated security risks.

    This change provides flexibility for users who rely on Ping for diagnostics while maintaining Zerto’s security posture.

    Updated Authentication for Zerto Analytics and CloudOps

    To enhance security, Zerto has updated the authentication method for Cognito in Zerto Analytics and CloudOps.

    Refer to the configuration procedure in the following link:

    User Authentication with Amazon Cognito

    Host Attestation and VAIO Support for Offline Recovery from a Storage Snapshot (zDriver and VAIO)

    Zerto 10.0_U6 and later support offline recovery mode, in which an offline recovery site is used to recover VMs from a storage snapshot. Zerto’s offline recovery mode is designed for fast offline recovery, significantly reducing recovery time (RTO).

    This feature is directly associated with the HPE Cyber Resilience Vault and with a safe recovery process inside the Vault Zone.

    Host attestation is a security process that verifies the integrity and trustworthiness of a host machine (a computer or server) before it is allowed to interact with sensitive data or workloads. It involves the host proving its secure configuration state, typically through hardware-based measures such as a Trusted Platform Module (TPM).

    Implementing host attestation in the Vault Zone ensures a trusted and secure recovery process, safeguarding the Cyber Resilience Vault and enabling reliable, secure system restoration after a cyber incident. It also complies with the vSphere security standards by allowing TPM and Secure Boot on all hosts.

    VMware VAIO (vSphere APIs for I/O Filtering) adds a standardized, VMware-endorsed IO filtering layer, and HPE Zerto provides the advanced replication, recovery orchestration, and data protection services.

    HPE Zerto now supports host attestation when performing offline recovery from a storage snapshot.

    For more details, refer to:

    Offline Recovery Process from a Storage Snapshot

    Improved Upgrade Process

    Zerto now supports an improved upgrade process. The new UI displays a complete manifest of all upgrade steps while highlighting the current step, its status, and the remaining steps. It provides detailed error and warning messages tied to the actual issue and shows the result of the last upgrade attempt.

    For more details, refer to:

    Upgrading the ZVM Appliance From Version 10.8

    VMware Cloud Foundation (VCF) 9.0 Support

    Zerto now supports VMware Cloud Foundation (VCF) 9.0 for new deployments, enabling resilient protection and recovery across VMware’s integrated cloud infrastructure.

    For more details, refer to:

    VMware Cloud Foundation 9.0

    Public Cloud

    Expanded AWS Region Support

    AWS ZCA and ZIC now support the following new AWS regions: Malaysia, Thailand and Mexico.

    AWS Launch Template Support

    The integration with AWS Launch Templates enables customers to use an existing template to launch an EC2 instance during the recovery process in VPG settings.

    During the recovery operation, the selected launch template (if any) will be included in the launch instance request for each recovery VM. You can apply launch templates that set predefined, automatic properties, thereby streamlining failover configuration. This enhancement enables you to quickly and seamlessly use the default configuration, saving time and reducing manual setup.

    With Launch Templates, failover instances can inherit consistent metadata, tags, and other configuration options, making your disaster recovery faster, more reliable, and easier to manage.

    Currently, some settings, such as networking, storage, AMIs, instance type, and security groups, still need to be configured separately.

    For more information about AWS Launch Template, refer to:

    Replication to AWS

    AWS Consolidation Tool for Single ZCA Architecture Transition

    The AWS Consolidation tool assists with transitioning to the new AWS architecture: a single AWS Linux ZCA with multiple VRAs.

    The tool creates a VRA for each ZCA it consolidates from, and, during the consolidation process, recreates existing VPGs from a source recovery ZCA to a target recovery ZCA.

    The purpose of the tool is to optimize the transition to a single Linux ZCA by automating the VPG recreation process. It is recommended to consolidate the environment gradually, and once the VPGs are successfully recreated and sufficient history has been gathered, the original ZCA can be terminated to avoid additional costs and network load.

    The tool is available for download on MyZerto.

    For more details, refer to:

    AWS Consolidation Tool Overview

    Expanded Guest OS Support for AWS and Azure

    Zerto now supports additional guest operating systems when failing over to AWS and Azure.

    This means a broader range of workloads can be recovered seamlessly without manual configuration. Failover to supported OS types is fully automatic—the system detects the OS and applies the necessary settings during recovery.

    Operating Systems Supported Automatically when Failing over to AWS:

    • CentOS 7.x, CentOS 8.x
    • Red Hat Enterprise Linux 7.x, Red Hat Enterprise Linux 8.x. Red Hat Enterprise Linux 9.x
    • Windows Server 2016. Windows Server 2019, Windows Server 2022, Windows Server 2025
    • Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04
    • Debian 11.x
    • Oracle Linux 8

    Operating Systems Supported Automatically when Failing over to Azure:

    • Windows 2016, Windows 2019, Windows 2022, Windows 2025
    • CentOS 7.x, CentOS 8.x
    • Red Hat Enterprise Linux (RHEL) 7.x, Red Hat Enterprise Linux (RHEL) 8.x
    • Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04
    • Debian 11.x, Debian 12.x
    • Oracle Linux 8.x, Oracle Linux 9.x

    Platform Encryption for AWS Recovery

    Zerto now offers platform encryption capabilities for recovery using AWS encryption keys. Using key encryption provides essential data protection for security and compliance requirements. In VPG configuration, you can now select an encryption key from your existing key list, which is automatically applied to encrypt all recovery volumes.

    AWS customers must leverage Customer Managed Keys (CMKs) to gain control, visibility, and compliance over encryption.

    Zerto now offers platform encryption capabilities for recovery using AWS encryption keys. Using key encryption provides essential data protection for security and compliance requirements.

    Users will be able to set the CMK ARN as the VPG default or per VM in VPG settings. On recovery operations, each volume will be created as encrypted with the selected CMK.

    IMDSv2 Configuration

    WS ZCA, VRA, and zImporter instances now support Instance Metadata Service Version 2 (IMDSv2), which enhances security by requiring session-based access to the instance metadata.

    IMDSv2 was introduced in November 2019. Unlike its predecessor (IMDSv1), which allowed unauthenticated HTTP requests, IMDSv2 requires a session-oriented approach using temporary tokens. This makes it significantly harder for malicious actors to exploit metadata endpoints.

    The recommended approach is to migrate the ZVM, VRA, and ZImporter components to use IMDSv2.

    Deployment via AWS Marketplace (ZCA)

    • New ZCAs deployed through the AWS Marketplace using CloudFormation will have IMDSv2 set to “required” by default.
    • New VRAs and ZImporters will also have IMDSv2 set to “required” by default.

    Existing VRAs and ZCAs

    • VRAs and ZCAs created before version 10.8 will retain their current IMDS settings during upgrades.
    • Customers may optionally update these instances to enforce IMDSv2 by manually setting the IMDS configuration to “required.”

    VAIO (vSphere APIs for I/O Filtering)

    Microsoft AVS Automatic Host Replacement (AHR)

    Microsoft AVS Automatic Host Replacement (AHR) is now officially supported in VAIO-based environments.

    AHR is a Microsoft AVS capability that automatically replaces ESXi hosts during hardware failures or planned maintenance. Zerto has enhanced its handling of these events to ensure:

    • Replication continues without disruption during host replacement.
    • Virtual Protection Groups (VPGs) are automatically evacuated.
    • Orphaned Zerto components (such as VRAs) are cleaned up automatically.

    This ensures business continuity during AVS infrastructure changes.

    For more information, refer to:

    Microsoft AVS Automatic Host Replacement (AHR) Support in Zerto 10.8 (VAIO)

    Automated VAIO I/O Filter Upgrade

    Zerto automatically enters Maintenance Mode and performs the VAIO I/O Filter upgrade automatically. No manual action is needed, and you no longer need to place the host into Maintenance Mode manually.

    When upgrading the I/O filter, Zerto first upgrades the filter on the cluster level and upgrades each host sequentially by:

    • Placing the host into Maintenance Mode.
    • Waiting for the upgrade to complete on the host level
    • Exiting the host from the Maintenance Mode.

    This new feature creates two Zerto tasks:

    • Upgrade IOFilter on the cluster: initiate the I/O Filter upgrade in vCenter.
    • Upgrade IOFilter on host: individual task for each host.

    Convert Existing AVS Deployments from Non-VAIO to VAIO

    Now, you can now convert existing AVS deployments from non-VAIO to VAIO using a new RunCommand, simplifying migration away from the legacy Zerto driver with minimal disruption.

    For more information, refer to:

    Deploying Zerto 10.8 on Azure VMware Solution (AVS)

    VPGs Across VAIO/Non-VAIO

    That´s a great new feature. You can now protect virtual entities from a vSphere non-VAIO (zDriver) site to a vSphere site in the VAIO variant, and vice versa.

    In this version, Hyper-V and public cloud environments are not supported.

    For more information:

    VAIO with Zerto: Frequently Asked Questions (FAQs)

    General

    Crowdstrike Falcon Integration

    You can now integrate Zerto with CrowdStrike Falcon to enhance cybersecurity resilience through advanced threat detection and recovery capabilities.

    Configure your CrowdStrike instance to receive alerts for VMs protected by Zerto, and Zerto will automatically tag checkpoints associated with those alerts. This enables you to fail over to a clean point in time before the detected threat, strengthening both security and recovery.

    For more information, refer to:

    CrowdStrike Integration

    Centralized Log Management

    You can now forward all Zerto logs, including ZVM and service logs, to an external Centralized Log Management server. Configure log forwarding from the new Log Management screen in the Management Console, supporting syslog over TCP and optional TLS encryption.

    For more information, refer to:

    Centralized Log Management

    Secure NTP Configuration

    You can now configure secure NTP (Network Time Protocol) settings on the Zerto Appliance to enhance time synchronization security and ensure accurate, tamper-resistant system time.

    For the configuration procedure, refer to:

    Configuring NTP in ZVM Appliance

    Improved Performance and Usability

    The VRA now starts up faster when performing an offline recovery from a snapshot.

    For more details, refer to:

    Offline Recovery Process from a Storage Snapshot

    API

    New Integration Hub APIs

    The Integration Hub enables integration with third-party cybersecurity platforms to enhance threat detection and recovery. Zerto now provides a set of REST APIs for managing integrations with third-party platforms through the Integration Hub. The new endpoints enable you to create, retrieve, update, and delete integrations:

    • POST /v1/integrationhub/{type} – Create a new integration.
    • GET /v1/integrationhub/{type}/{id} – Retrieve details for a specific integration.
    • GET /v1/integrationhub – List all existing integrations.
    • PUT /v1/integrationhub/{type}/{id} – Update an existing integration.
    • DELETE /v1/integrationhub/{type}/{id} – Remove an existing integration.

    NTP Configuration APIs

    The following API endpoints are now available in the ZVM Appliance for managing NTP settings:

    • GET /configuration/v1/ntp – Retrieves the current NTP configuration.
    • POST /configuration/v1/ntp – Sets or updates the configured NTP servers.
    • DELETE /configuration/v1/ntp – Deletes all configured NTP servers.
    • GET /configuration/v1/ntp/status – Displays the current NTP synchronization status.

    Reference

    You can access the 10.8 release notes on the following page:

    Release Notes for Zerto 10.8

  • Instant VM Restore: Minimize Downtime with HPE Zerto Software

    Instant VM Restore: Minimize Downtime with HPE Zerto Software

    HPE Zerto Software offers an Instant VM Restore feature, enabling you to recover applications in seconds with minimal performance impact, ensuring your business remains resilient and continuously operational.

    Built on Continuous Data Protection (CDP), this enables near-zero data loss and downtime, measured in minutes, allowing for the rapid failover and recovery of entire virtual machines (VMs) or multi-VM applications.

    In the recovery tests presented below, it was possible to restore a VM almost immediately, with Recovery Point Objectives (RPO) as low as 5 seconds and Recovery Time Objectives (RTO) as low as 16 seconds, all with minimal impact on performance during the recovery process.

    Local Continuous Backup

    HPE Zerto Software Local Continuous Backup is a data protection solution that provides continuous, journal-based backup of virtual machines and applications, creating recovery points every few seconds in the same environment.

    Unlike traditional backup methods that rely on periodic snapshots taken every 4, 8, or 24 hours, HPE Zerto continuously captures every write change made by the application through the Zerto Virtual Replication Appliance (VRA) and immediately copies it to the local journal at the production site’s datastore.

    At regular intervals of a few seconds, the solution creates a checkpoint timestamp across all journals to ensure write-order fidelity and crash consistency. This process preserves the exact sequence of write operations as they occurred, enabling recovery to precise and consistent points in time. Each checkpoint is assigned a unified timestamp, which is managed and synchronized by the Zerto Virtual Manager to maintain consistency across the applications.

    The local replica disk serves as the baseline recovery target for the protected VM and is also located in the datastore of the protection site. As the journal accumulates data over a pre-defined period, older writes and checkpoints are periodically flushed from the journal to the replica disk.

    This process permanently commits those changes, ensuring that the replica disk consistently reflects a stable state of the protected VM disk.

    In the figure above, we have some parameters.

    A virtual SQL server is replicating locally to the journal, with an RPO of 05 seconds. In addition to the journal, a replica disk is also being stored locally and associated with this VM.

    • SQL server VMDK disk = approximately 8.2 GB
    • Replica disk = approximately 7.4 GB
    • Journal = approximately 1.3 GB

    To simulate a failure on the virtual SQL database server, a “disk detach” action was performed in the VMware vCenter console, followed by a power-off.

    In this way, after this action, we rely solely on the local journal and the replica disk to recover the operation of this VM.

    The recovery operation is effortless and fast.

    In the Zerto Virtual Manager (ZVM) console, we select the SQL VM we want to restore, choose the latest recovery point (checkpoint) before the “disk detach action”, and select the “Instant Restore” operation.

    A new VM SQL (1) is created immediately. The restored VM is a replica of the original VM’s state at the selected checkpoint within the local journal. This process does not overwrite or affect the original SQL VM or its protection; instead, it generates a cloned VM that operates independently from the original.

    The cloning process enables you to quickly resume operations without waiting for a complete data copy from backup storage to production storage.

    After that, HPE Zerto presents the replica disks and journal disks together as virtual disks attached to the cloned VM SQL (1).

    Because the new VM runs directly from a combination of replica disks (containing the baseline data) and journal disks (storing recent writes) that are immediately ready to be attached, it enables near-instant VM availability.

    If the “Auto-commit” option with a duration of “0” seconds is enabled during the operation in the Zerto Virtual Manager (ZVM) console, the promotion process begins automatically.

    The cloned VM SQL (1) is then promoted to become the new production VM. It is registered in the production inventory and assumes either the original VM’s identity or a new identity as configured.

    Once committed, the VM SQL (1) is fully operational and ready for use.

    The measured recovery performance from ZVM and vCenter was:

    • RTO = 16 seconds
    • RPO = 05 seconds

    While the restored VM is running, all new writes it generates are initially written to the journal, preserving write-order fidelity and ensuring crash consistency. The journal functions as a write cache overlay, temporarily storing recent writes to disk.

    Gradually, the data is flushed from the journal to the replica disk, updating the baseline VM data. This process is known as promotion.

    During this process, while the VM operates using both the journal and replica disks, the associated Virtual Protection Group (VPG) remains in the “Instant VM Restore” state in the Zerto Virtual Manager console.

    After the promotion process is complete, the associated VPG status returns to the “normal state” in the ZVM console.

    The restored VM runs from the replica disk, which becomes its active storage. The original replica and journal data remain available in the background to support additional recoveries or rollbacks if necessary.

    In the figure above, we can verify that the original journal was preserved: “180_DS-VM_Left_vm-8051”.

    Preserving journal checkpoints enables reverting to an alternative point in time for the same VM if the initially selected restore point does not meet the requirements.

    After that, we can edit the VPG and change the protected VM from VM SQL to VM SQL (1). A new journal and replica disk are created for this VM SQL (1).

    It´s also possible to keep the previous journal and replica disks in the ZVM console, if necessary.

    This is a simple yet powerful process that minimizes RTO, RPO, and performance impact because both the journal and replica are stored locally, typically on production storage, and ready to be attached to the recovered VM.

    As a result, this approach from HPE Zerto Software is ideal for fast local recovery with minimal data loss, especially for critical applications.

    References:

    Instant VM Restore from the Journal

    Hewlett Packard Enterprise (HPE) – Auth – Sign In

    Demo- HPE Zerto Software in 2 minutes

  • Real-Time Ransomware Detection with HPE Zerto Software

    Real-Time Ransomware Detection with HPE Zerto Software

    Traditional periodic ransomware detection methods, such as scheduled backups, inherently introduce delays in identifying and responding to ransomware. Since these backups typically occur once daily, the data being analyzed is often outdated and potentially already compromised for several hours.

    Moreover, the large volume of data involved means ransomware detection takes much longer. This challenge applies to in-line scanning during the backup job process and post-backup analysis performed by third-party tools like antivirus software or rule-based detection systems.

    In a real-world test by Splunk on ransomware encryption speeds, the LockBit executable (lockbit-9.exe) demonstrated an average encryption time of 05 minutes and 50 seconds across 98,561 files.

    It is imperative to use technologies that minimize this gigantic impact, using real-time detection and recovery capabilities with RPOs and RTOs much better than those offered by scheduled backup.

    HPE Zerto’s always-on, agentless, near-synchronous replication engine enables near-real-time recovery and ransomware encryption analysis.

    This highly scalable solution can protect up to 10,000 VMs simultaneously per environment. Designed to detect ransomware activity in real-time, it effectively eliminates detection delays, ensuring rapid response to threats.

    Differentiators

    HPE Zerto’s Continuous Data Protection (CDP) technology forms the backbone of block-based (rather than file-based) hypervisor-level replication, unlocking key advantages for encryption detection, including:

    Real-time: Zerto’s always-on, near-synchronous replication engine allows users to analyze data in virtually real-time with high degrees of granularity.

    Agnostic: the encryption analyzer block-based inspects, assesses, and dynamically adjusts as the I/O comes in, regardless of what the data is, how it’s encoded, how large it is, or where it’s coming from.

    Relative: The encryption analyzer is dynamically adaptive. It constantly adjusts to the environment’s ever-changing conditions. A continuous, moving training period helps HPE Zerto learn standard write patterns and identify anomalies and expected encryption.

    Agentless: Zerto’s agentless real-time replication offers two key benefits: it eliminates the need for agent installation, configuration, or maintenance, reduces management overhead, and improves performance by consuming no additional resources on protected VMs. Most importantly, during a ransomware attack, the absence of agents means no Zerto components can be disabled or exploited by attackers, ensuring better security and protection.

    Lightweight: The encryption analyser’s block-level, real-time nature requires light infrastructure. There are no additional Zerto elements or software to install, configure, or manage.

    Scalable: Zerto’s CDP with elastic infrastructure is designed to effortlessly scale across virtualized and cloud environments, adapting seamlessly to your organization’s growth and evolving workload demands. It supports the protection and encryption inspection of up to 10,000 virtual machines (VMs) simultaneously per VMware environment.

    API-First: HPEZerto’s analyses and metrics are also exposed via our open REST, Swagger-based API to enable integration with an organization’s larger security stack. You can integrate it with your existing security or observability stack: EDR, SIEM, SOAR, Prometheus, and Grafana.

    Signatureless: HPE Zerto’s encryption analyzer employs a signatureless approach to detect encryption by evaluating data patterns and entropy. It doesn’t rely on predefined signatures, making it capable of identifying encrypted data regardless of the type or nature of the encryption, including newer and more sophisticated encryption methods.

    How does it work?

    The encryption analyzer is enabled by default, but this can be toggled on or off via the virtual manager GUI under Site Settings → Encryption Detection.

    It operates in three main phases: Collection, Inspection, and Reaction. Together, these phases form the CIR process, which powers Zerto’s real-time encryption detection capabilities.

    In the Collection phase, Zerto Virtual Replication Appliances (VRAs) capture every I/O operation into an in-memory buffer. Once sufficient data has been gathered for meaningful analysis, the process transitions to the second phase: Inspection. Each protected VM volume undergoes its dynamic training period during Collection. These training periods are independent, ensuring resetting one does not affect the others.

    To minimize performance impact, data writes are collected by the source VRA before Continuous Data Protection replication and data compression commence. Zerto will prioritize replication and discard I/Os from the collection buffer to ensure unaffected performance if necessary.

    The Inspection phase occurs on the Zerto Virtual Manager (ZVM) and utilizes two proprietary, patent-pending Real-time Encryption Detection (RED) algorithms: RED-C and RED-E.

    RED-C uses a cumulative sum (CuSum) test to assess randomness, while the RED-E algorithm evaluates the entropy of the sample dataset. RED-E’s ability to measure relative entropy by dynamically adapting to incoming data patterns makes it unique in data protection.

    This enables RED-E to set dynamic thresholds independent of the data type—whether text, images, binaries, or other formats. Together, these two algorithms allow Zerto to evaluate both the likelihood that an encryption event is expected or anomalous and its severity.

    In the Reaction phase, Zerto assigns an encryption detection score based on the site, rather than individual VMs or volumes. This approach reduces false positives and enhances detection accuracy.

    The site score aggregates and analyzes all data related to encryption detection, generating alerts only when a potential ransomware threat exists that could affect multiple disks, VMs, or both across various vectors.

    Alerting: Zerto generates alert ENC0001 if the overall site score reaches its threshold.

    Tagging: Zerto sets all VPGs’ impacted state to “Potential Encryption Event” and tags journal checkpoints in two places: the time the encryption was detected and the clean checkpoint for a more confident recovery.

    • Suspicious Encryption Activity. This checkpoint marks the exact moment when the abnormal encryption behavior was identified. It is a reference point for investigating the potential threat or event causing suspicion.
    • Suspicious Encryption Activity—Clean Checkpoint. This checkpoint is created 10 minutes before the suspicious activity is detected and is a safe restoration point. Contact Zerto Support if you wish to adjust the time interval between detecting the abnormal encryption behavior and creating the “clean” checkpoint.

    User Response: User response is required to validate or invalidate the detection event. By design, Zerto does not automatically take action on a VPG in response to detection.

    The final step of the Reaction phase is always user-initiated: recovering and restoring encrypted files, folders, VMs, or the entire site.

    Using the Detection API

    Zerto’s API-first development approach extends to its real-time encryption detection features. By making detection analyses accessible, organizations can strengthen their defense-in-depth strategies by integrating Zerto with existing cybersecurity solutions, such as EDRs, SIEMs, SOARs, and AI/ML toolsets.

    An example of what can be achieved with Zerto’s API is available on GitHub. The Zerto Resilience Observation Console (zROC), an open-source project, leverages Prometheus and Grafana to visualize various Zerto metrics, including those related to encryption detection, as presented in the figure below.

    HPE Zerto provides seven API endpoints for the encryption analyzer:

    Conclusion

    HPE Zerto integrates real-time detection with seamless recovery, delivering a comprehensive threat detection and rapid remediation solution. A real-time, agnostic, and dynamically adaptive encryption analyzer offers instant visibility, enabling swift identification and response to ransomware threats.

    References:

    What Is Real-Time Encryption Detection | Zerto

    Understanding Real-Time Encryption Detection with Zerto – Zerto

    API Integration – Customize your Workflow – Zerto

    An Empirically Comparative Analysis of Ransomware Binaries | Splunk

    Automating Zerto With PowerShell And REST APIs

    GitHub – ZertoPublic/zroc: Zerto REST API based Observability stack

  • HPE Storage Drivers for Kubernetes and related Ecosystem

    HPE Storage Drivers for Kubernetes and related Ecosystem

    HPE offers a comprehensive suite of drivers to integrate its advanced storage solutions with Kubernetes and the related native ecosystem. These drivers ensure seamless, scalable, and reliable storage management for containerized applications. Each driver is tailored to optimize specific storage needs, providing flexibility across various use cases.

    The HPE Storage Container Orchestrator Documentation (SCOD) is a reference guide for the HPE CSI, COSI, and GreenLake for File Storage drivers. This documentation outlines the integration with HPE’s primary storage solutions, including HPE Alletra Storage MP B10000 and X10000, HPE GreenLake for File Storage, Alletra 5000/6000/9000, Nimble Storage, Primera, and 3PAR storage systems.

    HPE CSI (Container Storage Interface) Driver

    The HPE CSI Driver for Kubernetes enables seamless integration of Container Storage Providers (CSPs), allowing you to perform efficient data management operations on storage resources. Its architecture provides block storage vendors to implement a CSP that meets the HPE specification.

    The CSP is a REST API specification that outlines the processes for provisioning, mounting, and deallocating storage resources. It defines how a host client interacts with a storage provider, ensuring smooth workflows for Kubernetes environments. Any storage vendor looking to leverage the HPE CSI Driver must implement this specification to ensure compatibility and functionality.

    The HPE CSI Driver for Kubernetes seamlessly integrates with a wide range of partner solutions tailored to fit specific target cloud-native environments, including:

    • HPE Morpheus Kubernetes Service. You can deploy and manage Kubernetes clusters through the Morpheus hybrid cloud management platform. Since Morpheus is built on a standard Linux distribution and uses upstream Kubernetes, it is fully compatible with and supported by the HPE CSI Driver for Kubernetes.
    • HPE Ezmeral Runtime Enterprise allows for seamless deployment and management of open-source upstream Kubernetes clusters via its intuitive management console. Additionally, it supports the importation and integration of external Kubernetes clusters, providing enhanced flexibility.
    • Amazon Elastic Kubernetes Service (EKS) Anywhere allows customers to deploy Amazon EKS-D (Amazon Elastic Kubernetes Service Distro) on their private infrastructure or non-AWS cloud environments, providing greater flexibility and control.
    • Canonical Kubernetes is a thoroughly upstream solution that seamlessly operates across any cloud environment, including bare metal, public, and edge infrastructure. It enables the deployment of single-node and multi-node clusters using Charmed Kubernetes and MicroK8s, providing robust container orchestration capabilities for everything from testing to production workloads.
    • Cohesity and HPE Alletra, powered by the HPE CSI Driver for Kubernetes, deliver comprehensive data protection solutions that help organizations effectively manage the complexities of containerized environments. This integration enables businesses to ensure data security, reliability, and scalability across their Kubernetes workloads.
    • Commvault Intelligent Data Management Platform. It delivers Kubernetes-native protection, application mobility, and disaster recovery for containerized applications. Paired with the Commvault Command Center, it offers IT operations and DevOps teams a user-friendly, self-service dashboard to streamline the management and protection of Kubernetes environments.
    • Veeam Kasten (K10) is a data management platform designed to run natively on Kubernetes, providing comprehensive protection for containerized applications. It seamlessly integrates with the HPE CSI Driver for Kubernetes, ensuring smooth and reliable data management across Kubernetes environments.
    • Mirantis Kubernetes Engine (MKE) is the next-generation solution that succeeds the Universal Control Plane from Docker Enterprise Edition (Docker EE). With the HPE CSI Driver integration for Kubernetes, users can efficiently provision persistent storage for Kubernetes workloads running on MKE, ensuring robust and scalable storage solutions.
    • Red Hat OpenShift integration enables the seamless provisioning and management of storage resources for HPE Alletra Storage MP Block, Alletra 5000/6000/9000, Nimble Storage, Primera, and 3PAR, ensuring optimal performance and streamlined storage management across environments.
    • SUSE Harvester is a hyper-converged infrastructure (HCI) solution optimized for bare metal servers. It leverages cutting-edge, enterprise-grade open-source technologies, including Linux, KVM, Kubernetes, KubeVirt, and Longhorn, to provide a highly scalable and efficient infrastructure platform.
    • SUSE Rancher delivers a unified platform for deploying Kubernetes as a service across any environment. Through its partnership with SUSE Rancher, HPE simplifies the management of the CSI driver on managed Kubernetes clusters, ensuring smooth and efficient storage orchestration.
    • VMware Tanzu Kubernetes Grid Integrated (TKGI) is a powerful, standalone container orchestration platform based on Kubernetes, designed to streamline the deployment, management, and scaling of Kubernetes clusters with ease.
    • The VMware vSphere Container Storage Plug-in enables Kubernetes users to access vSphere storage and its features. Introduced in vSphere 6.7 U3, it leverages Cloud Native Storage (CNS)—a vCenter abstraction consisting of two key components: the CSI driver for provisioning storage on vSphere and the CNS Control Plane within vCenter, which provides visibility into persistent volumes via the CNS UI.

    The HPE CSI Driver architecture clearly separates responsibilities between the upstream Kubernetes core, SIG Storage (CSI maintainers), the CSI driver author (HPE), and the backend CSP developer, ensuring streamlined collaboration and efficient storage resource management.

    The HPE CSI Driver for Kubernetes 2.5.2 release introduces significant enhancements, such as support for Morpheus Data Services, improved integration with Kubernetes and OpenShift, strengthened platform reliability, and streamlined backup workflows.

    • Support for Morpheus Kubernetes Service
    • New Kubernetes Support: Added support for Kubernetes v1.31 to v1.32 and OpenShift v4.17 to v4.18
    • Name Change: The HPE CSI Operator for Kubernetes is now renamed to HPE CSI Operator for OpenShift in the Red Hat Ecosystem Catalog
    • LDAP Account Support: Now available for HPE Alletra Storage MP B10000 CSP
    • Removed SSH Requirement: SSH is no longer required for HPE Primera and newer HPE Alletra Storage MP B10000 CSP platforms (see Deployment section for details)
    • Platform Improvements: Several reliability, availability, and serviceability enhancements for the HPE Alletra Storage MP B10000 CSP
    • NFS Server Provisioner: Added PersistentVolumeClaim expansion support
    • Backup Support: Support for “volumeMode: Block” backup for Veeam Kasten

    The HPE CSI Driver supports multiple installation methods, including industry-standard approaches like a Helm chart or an Operator. An advanced installation using object configuration files is available as a reference for partners, OEMs, and users requiring customizations or specific deployment strategies.

    You’ll need the Helm chart to work with a vanilla upstream Kubernetes cluster on a supported host OS. The certified OpenShift 4.x cluster CSI operator is required for a Red Hat OpenShift.

    In environments with multiple backends, the Helm chart should be used alongside additional Secrets and StorageClasses. For HPE Ezmeral Runtime Enterprise, the Helm chart is also necessary. You’ll need the CSI operator in an Operator Lifecycle Manager (OLM) environment.

    The advanced install is ideal if you’re working with an unsupported host OS or Kubernetes cluster and prefer a more hands-on approach. Lastly, use the Helm chart with the air-gapped procedure for a supported platform in an air-gapped environment.

    HPE COSI (Container Object Storage Interface) Driver

    The HPE COSI Driver for Kubernetes supports bucket lifecycle operations on object storage resources via the HPE Object Storage Provider (OSP). It implements the Container Object Storage Interface (COSI) specification, enabling HPE Alletra Storage MP X10000 Object Storage integration with COSI-compliant containerized workloads within a Kubernetes cluster.

    The driver conforms to the gRPC API contract defined by the Kubernetes COSI spec, ensuring compatibility with the COSI controller and ecosystem components.

    HPE COSI Driver for Kubernetes v1.0.0 introduces support for Kubernetes versions v1.25 through v1.31, enabling seamless integration with HPE Alletra Storage MP Object Storage. This release delivers core COSI functionality, including bucket provisioning, configuration (e.g., bucket tagging), lifecycle policy management, and access control.

    A log collector script is included to streamline operational visibility. It supports efficient retrieval of driver and provider logs from any node within the cluster.

    This release enhances Kubernetes-native object storage management by leveraging HPE’s enterprise-grade storage capabilities, delivering a robust, scalable, and cloud-native data infrastructure. 

    • Compatible with Kubernetes v1.25 to v1.31
    • Bucket Management: Supports bucket creation, tagging, lifecycle, and access management
    • Log Collection: Includes a log collector script for gathering logs from any node
    • Helm Chart: Available in version v1.0.0 on ArtifactHub
    • Supported Platform: HPE Alletra Storage MP X10000
    • Operating System: HPE Alletra Storage MP X10000 OS R1
    • Protocol: Supports S3
    • Release Notes: Version v1.0.0 is available on GitHub for further details

    The HPE COSI Driver for Kubernetes is deployed using a Helm chart, adhering to industry-standard Kubernetes packaging practices for declarative, version-controlled installation and configuration.

    HPE GreenLake for File Storage CSI Driver

    The HPE GreenLake for File Storage CSI Driver is currently designated as beta and is not covered under HPE support agreements. It is intended for non-production use and has undergone targeted validation in the following functional areas:

    • Kubernetes: 1.28-1.321
    • Helm Chart: v1.0.0-beta3 on ArtifactHub
    • Operators: v1.0.0-beta3 via OpenShift console
    • Worker OS: Red Hat Enterprise Linux2 7.x, 8.x, 9.x, Red Hat CoreOS 4.14-4.17
    • Ubuntu 16.04, 18.04, 20.04, 22.04, 24.04
    • SUSE Linux Enterprise Server 15 SP4, SP5, SP6 and SLE Micro4 equivalents
    • Platforms: HPE GreenLake for File Storage MP OS 1.3 or later
    • Data Protocols: NFSv3 and NFSv4.1

    Conclusion

    The HPE CSI Driver and HPE COSI Driver are foundational to HPE’s Kubernetes and data protection strategy. They enable seamless integration of HPE storage platforms into modern cloud-native ecosystems. While the CSI Driver addresses block and file storage provisioning, the COSI Driver facilitates object storage integration. Together, they support a broad spectrum of workload requirements.

    On the other hand, the HPE GreenLake for File Storage CSI Driver is critical for enabling persistent file storage in containerized Kubernetes environments that leverage HPE’s enterprise-grade file storage capabilities.

    These drivers are purpose-built to meet the demands of hybrid and multi-cloud architectures, serving as key enablers of scalable, resilient, and policy-driven storage orchestration in Kubernetes environments.

    References

    https://scod.hpedev.io

    https://scod.hpedev.io/csi_driver/index.html#features_and_capabilities

    https://scod.hpedev.io/cosi_driver/index.html

    https://scod.hpedev.io/filex_csi_driver/index.html

    https://www.hpe.com/emea_europe/en/solutions/cloud/containers.html

    https://www.hpe.com/br/en/morpheus.html

    GitHub – hpe-storage/scod: HPE Storage Container Orchestrator Documentation

    https://github.com/hpe-storage/container-storage-provider

  • HPE VM Essentials: Key Features and Available Resources

    HPE VM Essentials: Key Features and Available Resources

    HPE VM Essentials is a comprehensive toolset for managing, optimizing, and securing virtualized environments. It is an it´s the starting point for leveraging Morpheus, a recent acquisition of HPE, across the entire HPE portfolio.

    Powered by the KVM-based HPE VME hypervisor, it seamlessly integrates with Hewlett Packard Enterprise’s broader private cloud portfolio. It facilitates effortless scaling and upgrades to platforms like Morpheus for hybrid cloud management. Additionally, it supports Kubernetes (K8s), governance, and FinOps capabilities, ensuring comprehensive management and optimization across cloud infrastructure.

    With HPE VM Essentials, you can efficiently manage existing VMware workloads, migrate to HPE’s KVM-based hypervisor, and deliver a seamless VM provisioning experience across both environments. This enables unified management and simplified VM deployment across the HPE VME hypervisor and VMware ESXi, allowing you to provision workloads on demand to the most suitable environment.

    The HPE VM Essentials Manager, a virtual appliance running on the VME cluster, manages the VM Essentials stack. After deployment, an existing VMware environment can be seamlessly integrated into the VME Manager.

    HPE VM Essentials is designed to be highly cost-effective. Hewlett Packard Enterprise offers standalone HPE VM Essentials Software SKUs, licensed per physical CPU socket, with E-LTUS options of 1, 3, or 5 years, providing flexible pricing to meet various customer needs.

    The HPE VM Essentials version 8.0.4 has been released, and it´s integrated hypervisor has core capabilities like:

    • VM Live Migration. Move active virtual machines between physical hosts within an HPE VM Essentials cluster without downtime, enhancing host utilization or enabling host maintenance.
    • VM High Availability. Ensure workload resilience by automatically restarting virtual machines on a different physical host in case of a host failure, maintaining continuous availability.
    • Distributed Workload Placement. Automatically schedule and place HPE VM Essentials virtual machines within a cluster using intelligent placement logic to determine the optimal host for each virtual machine.
    • VM Storage Migration. Seamlessly move a running virtual machine’s storage disk between data stores without any downtime.
    • External Storage Support. Seamlessly integrate with existing external storage solutions (NFS, iSCSI, Fibre Channel) to maximize the value of current infrastructure investments.
    • Built-in Backup: provides VM, Container, Host, Database, File, Directory, Volume, and Storage Provider Backup, Snapshot, and Replication capabilities. Backups can be automatically configured during provisioning or manually created at any time.

    Many integrations are available, like:

    • VMware vSphere. Seamlessly integrate HPE VM Essentials with a vSphere deployment to discover, provision, and manage existing and newly provisioned virtual machines.
    • Native IP Pools. Leverage HPE VM Essentials’ native IP pool feature to define and manage pool IP addresses, simplifying the assignment of IPs to virtual machine networks.
    • Native Secrets Management. Securely store and retrieve credentials and sensitive information for automation tasks, including bootstrapping and managing virtual machines.
    • IP Address Management (IPAM) Integration. Integrate third-party IPAM solutions such as InfoBlox, BlueCat, SolarWinds, phpIPAM, and EfficientIP to automate IP address reservation and assignment.
    • Domain Name System (DNS) Integration. Integrate with third-party DNS solutions, including PowerDNS, Microsoft DNS, BlueCat, InfoBlox, and EfficientIP, to automate the creation of DNS A and PTR records.
    • Native Data Protection. Utilize HPE VM Essentials’ built-in data protection functionality to create and restore snapshot-based backups for both HPE VM Essentials and VMware virtual machines.
    • Provisioning Task Automation. During virtual machine provisioning, execute Bash and PowerShell scripts to automate software installation and system configuration tasks.
    • HPE Alletra Storage MP Integration. Integrate with the HPE Alletra Storage MP B10000 storage array for direct virtual machine volume mapping, enabling granular performance configuration and array-based snapshotting.

    The list of supported hardware, ISV workloads, and GuestOS for HPE VM Essentials Software can be found in the following link:

    support.hpe.com/hpesc/public/docDisplay?docId=dp00005501en_us

    The document contains the integrations tested and confirmed to support HPE VM Essentials software and HPE VM Essentials clusters at scale. Hardware or ISVs not included in this list may be compatible but are untested.

    At the product launch, compatibility and scale testing were limited to HPE hardware. As time passes, third-party hardware will be supported in addition to HPE hardware.

    In terms of ISV workload, the following have already been tested/validated until this moment:

    • Microsoft SQL Server 2016, 2017, 2019, 2022;
    • Oracle Database 19c;
    • MongoDB Enterprise Advanced 8.0.0;
    • Omnissa Horizon 8.13.1 build 11490723527.

    Integrating HPE VME with Veeam and Cohesity is possible using backup agents.

    Regarding Guest OS, the following were validated until this moment:

    • Windows Server 2022;
    • RHEL 9.3;
    • CentOS 8;
    • SUSE Linux Enterprise Server 15-SP6.

    Ubuntu 22.04 must be installed on all compute hosts before deploying VME standalone. This operating system, along with essential components such as KVM, Ovirt, OvS, and PCS, is the foundation for hosting VME.

    HPE may certify more base/host Operating Systems in the future.

    Technical White Paper: Deploying virtualized Microsoft SQL Server

    HPE VM Essentials offers a cost-effective virtualization platform for SQL Server, featuring socket-based licensing. It ensures on-premises security and accessibility while delivering the high performance typically expected from a local deployment.

    A technical document provides an overview of SQL Server running within HPE VM Essentials, highlighting its user-friendly features and key functionalities. It demonstrates how this virtualization environment can be an affordable and efficient alternative to VMware for managing your SQL Server infrastructure.

    You can access the document here:

    https://www.hpe.com/psnow/doc/a50012536enw?section=Product%20Documentation

    The following figure provides a high-level overview of Microsoft SQL Server running on an HPE VM Essentials stack. In this setup, an HPE Alletra Storage MP B10000 is utilized to deliver both Fibre Channel and iSCSI connectivity to the HPE VM Essentials cluster, enabling either protocol to create virtual machines.

    The future evolution of HPE VM Essentials will likely focus on deeper integration with next-generation cloud technologies, enhanced automation through AI, and greater flexibility to manage a wide range of workloads.

    Stay tuned!

    References and interactive demo:

    https://www.hpe.com/br/en/hpe-vm-essentials.html

    https://www.hpe.com/br/en/hpe-vm-essentials/get-started.html

    https://www.hpe.com/psnow/doc/a50004260enw.pdf?jumpid=in_pdp-psnow-qs

    https://hpevm-docs.morpheusdata.com/en/latest/release_notes/current.html

    https://hpevm-docs.morpheusdata.com/en/latest

  • Disaster Recovery as a Service (DRaaS) trends for Managed Service Providers (MSPs)

    Disaster Recovery as a Service (DRaaS) trends for Managed Service Providers (MSPs)

    As organizations embrace hybrid, multi-cloud, and edge computing architectures in 2025, MSPs must evolve their Data Protection services, including Backup as a Service, to provide more efficient, flexible, affordable, and scalable offerings.

    According to ” The MSP Horizons Report 2024 ” from N-Able, approximately 60% of MSPs already provide managed backup services, complete cloud management, and disaster recovery (DR) as standard services, but these are still ways off.

    In disaster recovery, two critical factors are minimizing downtime and preventing data loss. These are measured by RTO (Recovery Time Objective), which defines how quickly operations can resume, and RPO (Recovery Point Objective), which measures the volume of data that could be lost.

    Backups are necessary for any IT environment, but they must be complemented by a Disaster Recovery solution to meet more strict RPO and RTO recovery demands for critical applications and data. Even newer mechanisms present in backup solutions, such as instant recovery, cannot meet these Disaster Recovery demands.

    Continuous Data Protection (CDP) is the ultimate technology that achieves RTOs in minutes and RPOs in seconds (near-zero RPO), ensuring rapid recovery and minimal data loss. We will discuss CDP in the following paragraphs.

    According to The Business Research Company, the growing need for reliable data protection for critical and strategic applications, alongside the astounding amount of data generated daily, is accelerating the expansion of the Disaster Recovery as a Service (DRaaS) market.

    As more organizations are expected to adopt DRaaS solutions in the coming years, MSPs are expected to increasingly use consumption-based contracting models such as Infrastructure as a Service (IaaS), SaaS (software as a service),  scalable public-hybrid model, and on-demand cloud services. A recent Canalys survey with partners sustains this tendency:

    These new ways of contracting resources will allow MSPs to meet client expectations regarding service consumption and payment. For example, offering pay-as-you-go pricing models, paying only for your disaster recovery resources. It is a critical model as it ensures that DRaaS remains financially accessible for organizations of all sizes.

    DRaaS Market Size in 2025 And Growth Rate

    According to The Business Research Company, the Disaster Recovery as a Service (DRaaS) market has experienced substantial growth in recent years. It is projected to expand from $11.99 billion in 2024 to $15.14 billion in 2025, reflecting a compound annual growth rate (CAGR) of 26.2%. This growth trajectory is expected to continue, with the market reaching $44.2 billion by 2029, driven by a robust CAGR of 30.7%.

    Several factors fuel this remarkable growth during the forecast period, including integrating AI and Machine Learning, continuous data protection (CDP), enhanced resilience through edge computing, advanced ransomware mitigation solutions, multi-cloud recovery capabilities, and increased cloud mobility.

    Key trends shaping the DRaaS landscape over the next few years include cost optimization, scalability, and improved resilience against natural disasters. Additionally, automation and orchestration will be critical in streamlining DR operations, while real-time recovery expectations will become increasingly important.

    Artificial Intelligence Driving DRaaS

    As Managed Service Providers (MSPs) integrate Artificial Intelligence (AI) into their Disaster Recovery (DR) services, they will unlock powerful predictive capabilities that significantly enhance business continuity strategies.

    By leveraging AI and ML-driven Predictive Analytics, MSPs can anticipate and address potential issues before they disrupt operations.

    In general terms, LXT’s recent survey into AI adoption in enterprises, Path to AI Maturity 2023, highlights three key areas where organizations are investing in AI:

    • Client Service Applications: AI-driven chatbots and interactive support tools are prevalent, improving client interaction without constant human oversight.
    • Forecasting and Demand Generation: AI predicts necessary capital expenditures and manages inventory more efficiently in industries with significant logistics and supply chain dependencies.
    • Sales and Marketing Optimization: AI helps pinpoint where marketing efforts should be concentrated, optimize resource allocation, and improve target market identification.

    There are several ways in which these advanced technologies, embedded or not in products,  can improve Disaster Recovery services, including:

    Ransomware and Cyber Threats Identification: AI-powered predictive analytics can assess system behaviors to detect potential cybersecurity threats, including ransomware attacks, in near real-time.

    It enables immediate automated responses, such as isolating affected systems, initiating diagnostic scans, or triggering a recovery process from an air-gapped or immutable environment.

    Monitoring Application Health and Performance: Predictive analytics allows real-time monitoring of the health of essential applications. By analyzing usage patterns and system performance, AI can detect early signs of issues, such as resource exhaustion, that could cause slowdowns.

    Predicting Anomalies and Failures: AI continuously analyzes data from servers, storage devices, and network components to detect early hardware degradation or failure indicators. It includes monitoring for unusual temperature fluctuations, increased error rates in the network, or declining performance metrics in applications.

    By identifying these issues early, businesses can proactively take corrective actions before hardware failures lead to downtime or system disruptions.

    Acknowledging AI and ML’s limitations and avoiding relying on them exclusively for critical processes and decisions like disaster recovery is vital. Human expertise, contextual understanding, and ethical considerations should always be at the core of any MSP’s strategy.

    According to “The MSP Horizons Report 2024,” over 75% of MSPs already use Generative AI in some way in their offerings or processes.

    Automated Recovery Optimization for DRaaS

    According to Kaseya’s 2024 MSP Benchmarking Survey Report, the predominant challenge affecting MSPs’ workload is their inability to fully utilize their software solutions, a concern shared by executives and technicians. Technicians also expressed frustration with the time spent switching between applications.

    Automation is the key to unlocking MSPs’ next stage of growth: the road to higher efficiency, productivity, improved workflows, streamlined operations, and more.

    Furthermore, MSPs prioritize investing in IT management solutions with built-in automation and integration capabilities. About 85% of executives and technicians assert that automation is a must-have.

    Regarding Disaster Recovery services, Automated Recovery Optimization is essential for Managed Service Providers (MSPs) because it improves efficiency, reliability, and scalability:

    Here are some key examples of how to improve the Automation Recovery for DRaaS:

    Prioritization of Critical Workloads: These systems automatically prioritize the recovery of critical applications, allocating resources to bring them online first. Non-essential systems, such as internal reporting tools or administrative dashboards, are deprioritized and can be restored later.

    Orchestrated Failover and Failback: Automated recovery optimization ensures that resources are dynamically adjusted in near real-time on the MSP’s Cloud (or multi-clod). It can scale up virtual machines, storage, networking, and load balancers on actual usage. The DR solution must have this capability natively.

    Cost Optimization: These systems continuously adjust the cloud resources, scaling down when traffic normalizes, ensuring cost efficiency without sacrificing system performance.

    Remote Monitoring and Management (RMM): This is the core of MSP automation. RMM tools allow MSPs to monitor and manage their clients’ Infrastructure remotely.

    In conjunction with other solutions, RMM tools can also monitor the health of disaster recovery systems, ensuring that processes and systems are functioning as intended after a failover or failback.

    Ticketing and Reporting: Automation is widely used to create and manage support tickets. Automation can categorize, prioritize, and route tickets to the appropriate personnel or teams when incidents occur.

    In the context of DRaaS, a ticket can automatically be created within the ticketing system when a disaster recovery issue is detected.

    Integrating automated reporting with DRaaS improves management, transparency, and efficiency of disaster recovery processes.

    This automation provides MSPs and businesses with ongoing visibility into the effectiveness and status of their recovery efforts, helping ensure that recovery objectives are achieved and compliance requirements are met.

    Infrastructure Automation: MSPs can use Infrastructure as Code (IaC) platforms like Terraform and Ansible.

    These platforms allow them, for example, to automate cloud deployments and version control of their disaster recovery environments, making DR more agile and responsive.

    DRaaS and Cybersecurity Services

    According to “The MSP Horizons Report 2024” from N-Able, 81% of MSPs taking the survey said they would see growth in their cybersecurity services in the next three years. The most in-demand solutions are EDR, MDR, XDR, and SOC-aaS.

    Over a third of those surveyed are looking to deliver some of these solutions themselves, and an even more significant proportion are leveraging third parties to provide the majority of the service, often through specialist vendors or Managed Security Service Providers (MSSPs) partners.

    Moving from an MSP (Managed Service Provider) to an MSSP (Managed Security Service Provider) model can be challenging. It is a significant transformation that involves changes across people, processes, tools, and client relationships. It requires careful planning, strategic investment, and a commitment to building expertise in cybersecurity.

    When MSPs transition to an MSSP model, they can typically take three main approaches to make this shift. These approaches depend on the MSP’s existing capabilities, resources, and long-term strategy.

    Partnering with other MSSPs: the MSP collaborates with an established MSSP to offer security services under its brand. This is often a white-label partnership in which the MSP resells the MSSP’s services without having to develop or manage the security infrastructure themselves.

    Partnering with vendors through MSSP programs: by partnering with vendors, MSPs can quickly enhance their security offerings, scale up services, and stay competitive in the evolving cybersecurity landscape. These partnerships allow them to leverage the specialized expertise of leading security companies while avoiding the complexities of building and maintaining these technologies in-house.

    For example, in a co-managed security program, the MSP partners with a vendor to deliver clients operational support and security services. The MSP manages day-to-day operations, while the vendor provides the security tools and expertise for threat monitoring, incident response, and vulnerability management. There are also options like SOC-as-a-Service, where MSPs partner with vendors to outsource the function of a Security Operations Center (SOC).

    Build their own Security Operations Center (SOC): building in-house capabilities involves developing internal cybersecurity expertise and infrastructure. It offers complete control but requires significant investment and time. It is an expensive approach and must be carefully planned.

    Canalys data from channel polls show Cybersecurity has been the strongest pillar of growth for MSPs and other partners building managed services.

    98% of MSPs focused on building cyber security-managed services. Headlines about cyberattacks build awareness and fear, and clients can sometimes feel crushed between the rock of ransomware and the hard place of compliance.

    Disaster Recovery as a Service is critical to deploying a comprehensive cybersecurity policy to clients, particularly for MSPs starting to offer cybersecurity services.

    DRaaS ensures that businesses can recover their data and continue operations during a cybersecurity incident, such as a ransomware attack, data breach, or other disruptions.

    For MSSPs, references such as the NIST Cybersecurity Framework 2.0 and NIST SP 800-61r2 are vital guides for ensuring that their incident response processes are effective, well-documented, and aligned with industry standards.

    Additionally, integrating disaster recovery solutions within the incident response plan can directly support several key aspects outlined in the NIST guidelines, especially recovery, resilience, and continuity during and after an incident.

    The integration of DRaaS is most apparent in the “Containment, Eradication, and Recovery” phase of NIST SP 800-61r2. NIST outlines the importance of containing the incident to prevent further damage, eradicating the threat, and recovering operations to normal.

    DR solutions help MSSPs recover systems, data, and applications quickly after an incident. For instance, if malware or ransomware compromises systems, DRaaS can facilitate the restoration of clean, secure copies of data, minimizing data loss and downtime.

    Conclusion

    As the demand for more resilient, scalable, and cost-effective disaster recovery solutions continues rising, MSPs are in a prime position to evolve and expand their service offerings, particularly with Disaster Recovery as a Service.

    By incorporating DRaaS into their portfolios, MSPs can ensure that businesses protect their critical data/applications and enhance operational continuity in the face of unexpected disruptions.

    Integrating advanced technologies like AI and automation paves the way for MSPs to reach the next growth stage, generating more significant revenue through improved efficiency, productivity, and streamlined operations.

    A holistic service offering for data/application protection, Cybersecurity, and disaster recovery positions Managed Service Providers to meet evolving customer demands. Additionally, Managed Security Service Providers can offer DRaaS to their clients as part of a robust and complete portfolio of Cybersecurity as a Service.

    References

    The MSP Horizons Report – 2024 – N-Able

    https://www.kaseya.com/resource/2024-msp-benchmark-survey-report

    https://cybersmart.co.uk/the-cybersmart-msp-survey-2024

    https://www.thebusinessresearchcompany.com/report/managed-services-global-market-report

    https://csrc.nist.gov/pubs/sp/800/61/r2/final

  • Disaster Recovery (DR) Powered by Continuous Data Protection (CDP)

    Disaster Recovery (DR) Powered by Continuous Data Protection (CDP)

    In Disaster Recovery (DR), two critical factors are minimizing downtime and preventing data loss. These are measured by RTO (Recovery Time Objective), which defines how quickly operations can resume, and RPO (Recovery Point Objective), which measures the volume of data that could be lost.

    Backups are necessary for any IT environment, but they must be complemented by a Disaster Recovery solution to meet more strict RPO and RTO recovery demands for critical applications and data, bypassing the backup window. Even newer mechanisms present in backup solutions, such as instant recovery, cannot meet strict Disaster Recovery´s RPO and RTO demands.

    As a reference, the following table compares the RPO, RTO, and SLA of various data recovery mechanisms, including recovery from image-level backups and failover replicas.

    Continuous Data Protection (CDP)

    Continuous Data Protection is the first-choice technology that achieves RPOs in seconds (near-zero RPO) and low RTOs.

    CDP works by continuously capturing and monitoring data changes in real-time, including any data written, in the client’s production site (tenant) and automatically replicating every data version to a recovery site or cloud; the write-order fidelity of all the block-level changes is maintained.

    It stores these changes in a journal. If restoration is required at a specific time, the journal’s changes can be reverted to that point in time.

    Continuous Data Protection also does not limit the physical distance between the tenant production and recovery environments; the main requirements are minimum guaranteed bandwidth and controlled latency.

    It is essential to know that CDP is not equal to hypervisor-based asynchronous replication, like Veeam Replication and VMware vSphere Replication, or even near-sync snapshot-based replication, which is present in some HCI systems like Nutanix.

    The main difference is that the CDP uses APIs to capture and log every I/O in real-time. When deployed in VMware environments, most CDP solutions integrate with VSphere APIs for the IO Filtering (VAIO) framework.

    On the other hand, in asynchronous and near-sync replication, the data capture frequency is not continuous; the data is captured and replicated in short intervals by crash-consistent or app-consistent snapshots.

    Asynchronous Replication

    When you take snapshots of multiple VMs simultaneously, each VM requires a certain amount of time to capture the state of its disk, memory, and configuration. If the snapshots are taken in parallel, this can delay completing the snapshot process for all VMs.

    The time it takes to process each snapshot, read the data, replicate it, and commit snapshots, especially for VMs with extensive data change rates, can result in a longer replication cycle.

    Due to this, vDisk-based snapshot frequency is traditionally restricted to intervals no shorter than 15 minutes. This interval ensures the replication process has enough time to capture and synchronize changes to the source data, reducing the risk of inconsistencies or corruption during the replication process.

    Below is Veeam’s asynchronous replication architecture for VMware Vsphere.

    It is based on VM snapshots replicated asynchronously. You can configure replication jobs using crash-consistent or application-consistent snapshots.

    In step 6, we can verify that Veeam Backup & Replication requests the vCenter Server or ESXi host to create a VM snapshot.

    The VM disks are set to a read-only state, and each virtual disk receives a delta file. Any changes to the VM during replication are written to these delta files.

    The source proxy starts the replication, reading the VM data from the read-only VM disk.

    The great advantage of CDP overall types of snapshot-based replication is that it significantly lowers the impact on system performance, particularly in primary I/O latency and replication processes.

    Another positive point of CDP is that, like asynchronous replication, it does not limit the physical distance between the sites; the main requirement is a guaranteed minimum bandwidth.

    Near-Sync Replication from HCI systems

    The snapshot mechanism remains on near-synchronous replication solutions of some HCI systems.

    The difference in Nutanix’s case is the use of crash-consistent Lightweight Snapshots (LWS), which allow RPO between 1 and 15 minutes. However, there are limitations, such as the HCI system locking and the inability to perform cross-hypervisor disaster recovery.

    Unlike the traditional vDisk-based snapshots used by asynchronous replication, Nutanix LWS leverages markers and is completely OpLog-based. In Nutanix, vDisk snapshots are done in the Extent Store portion of the system (Persistent Data Storage).

    In this case, Oplog performs a function similar to a filesystem journal. It is built as a staging area to handle bursts of random writes, coalesce them, and then sequentially drain the data to the Extent Store. OpLog is stored on the SSD tier on the CVM to provide extremely fast write I/O performance, especially for random I/O workloads.

    When Near-sync replication is enabled, v-Disk-based seed snapshots are taken and replicated to the remote site before LWSs begin. LWSs are replicated continuously to the remote site. The system creates an intermediate snapshot every hour and retains it for 6 hours as a checkpoint to help with RTO.

    VMware VAIO Architecture

    Below is a CDP architecture for VMware environments using vSphere APIs for IO filtering (VAIO).

    The VAIO framework offers a secure method for integrating third-party software into a VMware environment. It allows it to intercept data as it flows between virtual machines and virtual disks and perform services on that data, such as replication.

    A key component in this framework is I/O filters. I/O filters are software components that can be installed on ESXi hosts to provide additional data services to virtual machines. As presented previously, these filters process I/O requests as data moves between a virtual machine’s guest operating system and the virtual disks. We can enable I/O filtering for an individual virtual disk, and they are entirely independent of the storage tier.

    VMware offers specific categories of I/O filters, and third-party vendors can create them. Typically, they are distributed as packages that provide an installer to deploy the filter components, as with the Veeam solution. The I/O filter itself is installed during the Continuous Data Protection configuration process.

    For example, refer to the following procedure to install Veeam I/O Filters:

    https://helpcenter.veeam.com/docs/backup/vsphere/cdp_io_filter_install.html?ver=120

    Once the I/O filters are deployed, the vCenter Server configures and registers an I/O filter storage provider, also known as a VASA provider, for each host in the cluster. These storage providers communicate with the vCenter Server and make the data services provided by the I/O filters visible in the VM Storage Policies interface. After associating virtual disks with the storage policy, the I/O filters are enabled on those virtual disks.

    In the VAIO framework, User Space and Kernel Space are two separate areas of memory where I/O filters operate. Each serves distinct purposes and offers different levels of access and control.

    • User Space is where user-level applications, including third-party I/O filters, operate. In the VAIO framework, I/O filters developed by third-party vendors typically run in user space. This area is isolated from the core operating system to prevent direct manipulation of the hardware or Kernel, thereby ensuring system stability and security.
    • Kernel Space is where the VAIO framework runs and handles the low-level aspects of I/O filtering. It is responsible for processing I/O requests from virtual machines to virtual disks. The kernel space interacts with user space to execute the filtering logic implemented by third-party I/O filters, like Veeam’s I/O filter.

    The I/O path with VAIO looks like:

    Step 1: A write comes from a guest OS and is handled in User Space by the vSCSI (Virtualized SCSI Interface) of the VM

    Step 2: The vSCSI driver opens a channel to the vSCSI backend in the Kernel Space, which processes the write by opening a location on the File System layer.

    Step 3: The File System layer then hands the write to the File Device layer.

    Step 4: The VAIO framework can see the IO request before the File Device sends the write to a physical device, where the virtual disk is hosted. The VAIO framework has visibility via a kernel module attached to the File Device layer, and it can see if that VM’s IO has a particular data service attached to it.

    Step 5: If there is no policy, the IO commits without filtering and overhead. If there is a policy for that VM’s IO, it is passed back to the User Space of the requesting VM, where the data service executes the filter against the I/O.

    Step 6: If the policy is for replication, the filter records the changes in a change log in memory or cache. The filter then passes the captured write data to a Third-Party CDP service for processing and replication.

    Step 7: The filter returns the write I/O directly to the physical device without needing to return through the entire vSCSI/File System layers again. The changes are applied directly to the Virtual Disk.

    Upcalling IO back to User Space from Kernel Space may seem like a time-consuming process, but this is a specifically designed mechanism that takes microseconds to accomplish. This architecture guarantees minimal overhead, security, and stability for the Kernel.

    Conclusion

    Organizations are under increasing pressure to reduce downtime and safeguard against data loss and application interruptions, ensuring that critical systems and data are consistently protected and can be quickly restored.

    Disaster Recovery powered by Continuous Data Protection (CDP) enables a real-time data protection strategy that saves a copy of every change made to data, which can be restored at any point-in-time in case of system rollback needs. Continuous Data Protection is a replication technology that achieves in seconds (near-zero RPO) and RTOs in minutes.

    Continuous Data Protection’s key strength lies in its real-time block-level data capture and replication, which utilizes APIs and integrates with technologies such as VMware’s VAIO framework using I/O Filters. This enables efficient and seamless recovery for the organizations, even across geographically distributed environments.

    References

    https://techdocs.broadcom.com

    https://blogs.vmware.com/virtualblocks/2015/02/05/vsphere-apis-for-io-filtering

    https://portal.nutanix.com/page/documents/details?targetId=Prism-Element-Data-Protection-Guide-v7_0:wc-cluster-dr-nearsync-limitations-r.html

  • Implementación de la Orquestación de Snapshots para Entornos Críticos

    Implementación de la Orquestación de Snapshots para Entornos Críticos

     

    La orquestación de snapshots es fundamental, especialmente en entornos de TI que buscan agilidad en las operaciones de recuperación y protección de aplicaciones. La capacidad de recuperación rápida desde snapshots también ayuda a reducir el tiempo de inactividad y minimiza el impacto en el negocio.

    Veeam Backup & Replication puede integrarse con sistemas de almacenamiento y crear backups utilizando snapshots basados en almacenamiento, minimizando el impacto de la producción y acelerando el proceso de backup

    Además del traditional Backup Job, Veeam ofrece el Snapshot Orchestration Job. Automatiza la creación, administración y eliminación de snapshots, lo que garantiza backups consistentes, un impacto mínimo en los sistemas de producción y un uso más eficiente del almacenamiento.

    Juntos, Veeam Backup y Veeam Snapshot Orchestration permiten la implementación de una estrategia integral de protección y recuperación de datos.

     

    vSphere Metro Storage Cluster (vMSC)

    En entornos críticos de VMware que requieren alta disponibilidad, VMware High Availability (HA) es una tecnología que proporciona supervisión basada en clúster de máquinas virtuales que se ejecutan en hosts ESXi incluidos. Si el almacenamiento, la red o el host falla, los hosts ESXi restantes se coordinan para reiniciar las máquinas virtuales afectadas en los hosts no afectados.

    El VMware HA es posible a través del almacenamiento compartido. Sin almacenamiento compartido, las máquinas virtuales y sus datos no pueden ser vistos por los hosts supervivientes, y por lo tanto una operación de reinicio de desastre no es una opción.

    VMware vSphere Metro Storage Cluster (vMSC) es una configuración diseñada para permitir la alta disponibilidad, Recuperación ante desastres y tolerancia a fallos para cargas de trabajo virtualizadas mediante la integración de VMware vSphere con una solución de almacenamiento que admite la replicación síncrona en dos centros de datos separados geográficamente.

    Cuando se combina con las características de HA de vSphere, vMSC garantiza que las máquinas virtuales (VMs) que se ejecutan en un sitio puedan reiniciarse rápidamente en el otro sitio en caso de fallo sin perder datos.

    vMSC también es totalmente compatible con las características de vSphere DRS (Distributed Resource Scheduler), que ayudan a garantizar que las máquinas virtuales se recuperen automáticamente y los recursos se equilibren entre sitios.

    Además, vMSC utiliza replicación de almacenamiento síncrono para mantener los datos reflejados en tiempo real entre dos sistemas de almacenamiento, generalmente en centros de datos separados (metro). Esto asegura que ambos sitios tengan una copia idéntica de los datos, proporcionando tolerancia a fallos y minimizando el tiempo de inactividad.

     

    Pure Storage Purity ActiveCluster

    Purity ActiveCluster es una característica de FlashArrays que permite la replicación sincrónica de dos sitios para alta disponibilidad. Es una solución de replicación bidireccional activa/activa, totalmente simétrica, que proporciona replicación síncrona para RPO cero y conmutación por error automática y transparente para RTO cero. Las máquinas virtuales VMware pueden acceder al almacenamiento en ambos sitios simultáneamente sin clustering varios sitios, lo que permite que los hosts y arrays en clúster implementen configuraciones flexibles de centros de datos activo/activo.

    Cuando se combina con la configuración vSphere Metro Storage Cluster (vMSC), las máquinas virtuales de VMware pueden acceder al almacenamiento en ambos sitios simultáneamente, sin interrupción, incluso si un sitio falla.

    Por otro lado, cuando Purity ActiveCluster se combina con VMware High Availability (HA), lo failover automático entre sitios garantiza que las máquinas virtuales mantengan una alta disponibilidad incluso si un centro de datos falla

    Además, la replicación síncrona de Pure Storage permite que los datos se compartan de manera consistente entre dos sitios diferentes, pero la tecnología de acceso al almacenamiento puede configurarse de forma diferente en cada ubicación. Expone rutas a los hosts locales como rutas activas/optimizadas y expone rutas a los hosts remotos como activas/no optimizadas.

    La ruta optimizada se define en base a una conexión de host a volumen usando una opción de matriz preferida; esto asegura que una VM o aplicación tendrá una ruta local optimizada para ese volumen independientemente del host en el que esté ejecutándose, como se muestra a continuación.

     

    Purity ActiveCluster consta de tres componentes principales: el Pure1 Mediator, active/active clustered array pairs, y stretched storage containers.

    Algunas características clave incluyen:

    • Pure1 Cloud Mediator integrado: Un mediador pasivo configurado automáticamente que permite una conmutación por error transparente y evita escenarios de cerebro dividido, eliminando la necesidad de implementar y administrar componentes adicionales.
    • Active/Active Clustered FlashArrays: Utiliza la replicación síncrona para mantener copias idénticas de los datos en ambos arreglos y presentarlas como una copia coherente a los hosts conectados a uno o ambos arreglos.
    • Stretched Storage Containers: Administra contenedores que agrupan objetos de almacenamiento, como volúmenes, y los extienden a través de dos arrays.
    • Synchronous Replication: Los writes si sincronizan entre arrays y almacenado en RAM no volátil (NVRAM) en ambos arrays antes de ser reconocido por el host.
    • Symmetric Active/Active: Esta opción permite operaciones de lectura y escritura en los mismos volúmenes a ambos lados del mirror, con reconocimiento opcional de host-to-array.
    • Failover Transparente: Conmutación por error automática y sin interrupciones entre arrays y sitios de replicación síncrona, incluida la resincronización y recuperación automáticas.
    • No Bolt-ons y no hay licencias: No se requieren hardware adicional ni costosas licencias de software; simplemente actualice el entorno operativo Purity para habilitar la funcionalidad activa.
    • Gestión Sencilla: Esta capacidad permite que las operaciones de gestión de datos, como el aprovisionamiento de almacenamiento, la conexión de hosts, la creación de snapshots y la clonación, se realicen desde cualquier lado del mirror.

     

    Snapshot Orchestration: Pure Storage FlashArray and Veeam Data Platform V12

    El contexto anterior es crucial para entender cómo Veeam Backup & Replication v12 o versiones posteriores pueden orquestar instantáneas de Pure FlashArrays configuradas en modo ActiveCluster.

    La replicación síncrona en modo ActiveCluster proporciona una solución simétrica activo-activo que permite la duplicación de volúmenes en la capa de almacenamiento. Un snapshot de volumen o almacenamiento creada en cualquiera de los arrays se replica sincrónicamente en ambos arrays, lo que garantiza la coherencia de los datos.

    Con el lanzamiento de Veeam Backup & Replication v12, Veeam ha mejorado la funcionalidad de su USAPI v2. Esta nueva versión de API admite la orquestación de snapshots replicados y permite lo offloading o el archivado de snapshots de almacenamiento en su formato nativo al almacenamiento secundario.

    Cuando se integra con Veeam Backup & Replication a través de USAPI v2, el caso de uso principal de Purity ActiveCluster es aprovechar un Veeam Snapshot-Only Job  para crear un snapshot de almacenamiento sincrónico en los FlashArrays local y secundario.

    Este snapshot se utiliza como fuente para un job de backup de Veeam.

    Además, el Veeam’s Application-Aware Image Processing garantiza backups consistentes con las aplicaciones. Esto garantiza que lo snapshot capture todos los datos necesarios, lo que permite la recuperación de aplicaciones a un estado consistente sin corrupción ni pérdida de datos.

    El beneficio más importante es que los snapshots de almacenamiento le permiten acelerar el backup y la replicación de las máquinas virtuales VMware vSphere con discos alojados en sistemas de almacenamiento, lo que reduce la vida útil de los snapshots de las máquinas virtuales de VMware y minimiza el impacto en las aplicaciones.

     

    Configuración del Snapshot-Only Jobs + Backup Jobs from Snapshots

    Veeam ha publicado un documento altamente informativo titulado “Advanced Storage Snapshot Integration with Pure Storage FlashArray and Veeam Platform V12.”

    The document effectively illustrates the scenario described earlier: a Veeam job that orchestrates the creation of storage snapshots on the remote Pure FlashArray, followed by the creation of a Veeam backup job using the storage snapshot from the remote Pure FlashArray in ActiveCluster mode.

    A continuación, el panel de job action muestra que lo snapshot solo para la máquina virtual replicada sincrónica se creó y ejecutó correctamente. Resaltado en rojo, podemos ver que Veeam es consciente de la relación de replicación sincrónica; los snapshots se realizaron simultáneamente en los Pure FlashArrays locales y remotos y la copia de seguridad se creó a partir de lo snapshot.

     

    Puede acceder al documento aquí, en este enlace:

    https://www.veeam.com/resources/wp-pure-storage-veeam-advanced-storage-snapshot.html

     

    Conclusión

    Veeam Backup & Replication v12 y versiones posteriores brindan una solución sólida para orquestar y administrar snapshots de almacenamiento en entornos que utilizan Pure FlashArrays en modo ActiveCluster. En este escenario, Veeam garantiza la creación consistente de snapshots en arrays locales y remotos al aprovechar la replicación sincrónica, minimizando el impacto en los sistemas de producción y mejorando al mismo tiempo la eficiencia del backup y la replicación.

    La integración de los Veeam’s Snapshot-Only Jobs y el Application-Aware Image Processing garantiza la consistencia de las aplicaciones durante los backups, asegurando una protección de datos confiable y eficiente. Además, descargar y archivar snapshots de almacenamiento en un almacenamiento secundario simplifica las operaciones de backup y ofrece una solución escalable y flexible para entornos críticos de VMware vSphere.

    En general, esta integración acelera los procesos de backup, reduce el tiempo de inactividad y garantiza la integridad de los datos, lo que la convierte en una herramienta esencial para las empresas que requieren recuperación ante desastres confiable y alta disponibilidad.

     

    Referencias

    https://support.purestorage.com/bundle/m_user_guides_for_vmware_solutions/page/Solutions/VMware_Platform_Guide/User_Guides_for_VMware_Solutions/ActiveCluster_with_VMware_User_Guide/topics/concept/c_activecluster_introduction.html

    https://helpcenter.veeam.com/docs/backup/storage/snapshot_only_job_perform.html?ver=120

    https://helpcenter.veeam.com/docs/backup/storage/backup_from_storage_snapshots.html?ver=120