Migrate Linux Repo to Hardened Repo in Cloud Connect
I got a request on how to convert a Linux Repo into a Hardened Repository that’s behind Cloud Connect. So, I thought I’d write down the process.
I will caveat this by saying this is not an official process, and you should always perform your own testing before using something in production (PROD).
Process
- Disable tenants that are using the “old Linux Repo” in Cloud Connect
data:image/s3,"s3://crabby-images/4a492/4a492573084a2b56fd7bba78cd1181461065db3c" alt=""
- Navigate to backup infrastructure tab
- managed servers
- Select Linux server and change the account from regular linux credentials to single use creds for LHR
data:image/s3,"s3://crabby-images/02c18/02c18763c51e8620d8028401e5aab1a876d0ddb8" alt=""
- Make sure the permissions etc on the folder in LHR is correct
- Modify the permissions on the existing backup files to be owned by the account that you used for the single use permissions (in my lab I used the Path /backups and the account was lhr)
- chown -R owner:group <dir_path>
- chmod 700 <dir_path>
- perform any additional hardening as reccomended by your security team
- Modify the permissions on the existing backup files to be owned by the account that you used for the single use permissions (in my lab I used the Path /backups and the account was lhr)
data:image/s3,"s3://crabby-images/d7a81/d7a81dda51a4b3bee4cd0b67ba16094e43d0c562" alt=""
- Navigate to Backup Repositories
- Add Hardened Repository
- Map the exact same repo(*Make sure the paths are exactly the same, ex. /backup)
data:image/s3,"s3://crabby-images/231a3/231a3539519500497f1e603edef38a25a6542c03" alt=""
- Navigate to tenants and follow the replace Cloud Repo process(https://vee.am/9y3HHw)
- Configure a new backup repository that you plan to use as a cloud repository.
- Open the Cloud Connect view.
- In the inventory pane, click Tenants.
- In the working area, right-click the tenant account and select Disable.
- Change resource allocation settings for the tenant on the initial cloud repository:
- Open the Cloud Connect view.
- In the inventory pane, click Tenants.
- In the working area, right-click the tenant account and select Properties.
- At the Backup Resources step of the wizard, select the initial cloud repository in the list and click Edit.
- Click Finish to save the changes.
- Configure a new backup repository that you plan to use as a cloud repository.
When you are done with this process your tenant should have the “New” hardened repo mapped.
data:image/s3,"s3://crabby-images/6a41f/6a41ff619fce1530612e2b2262d2ebc8163104b2" alt=""
Now that we have successfully mapped the new backup Hardened Repository, we can safely remove the “old” linux repository, once that has been completed we can simply re-enable the tenant and request they resume backups
data:image/s3,"s3://crabby-images/16622/166223f43a4d54588910485c10c9cdc406649e6d" alt=""
I’ve tested this in my lab and the backup chain kept doing its incrementals. I can also see that it went back and added the immutable flag to the full backup that I took before enabling immutability.
data:image/s3,"s3://crabby-images/7030b/7030bf0c79dd1f859a9806dca0dc901d1b8f2b0d" alt=""
Checking the job we can also confirm that it was an incremental.
data:image/s3,"s3://crabby-images/6af89/6af89181da16abb4469d5497a80bd07c73421d80" alt=""
I hope this has been informative and has always, Keep on learning.