Getting started with Backup and Recovery for VPC (VSIs) workloads
IBM Cloud® Backup and Recovery is a managed service that provides backup solutions for various IBM Cloud® services and customer workloads running on IBM Cloud.
This topic shows you how to get started with IBM Cloud Backup and Recovery to protect data in a Virtual Server Instance that is running Ubuntu Linux. The intended audience is first-time users of the service where you learn to deploy and configure a IBM Cloud Backup and Recovery instance, and create a Data Source Connector or Connector Agent that links your Virtual Server and the instance. Then you can create a new protection group and apply a custom policy that defines backup schedules and retention. Once the policy is applied to the protection group, your data is protected.
Use code VPC1000 and get USD 1,000 in no-charge credits to use toward different offerings on IBM Cloud VPC, including: Confidential computing with Intel® SGX®, Bare Metal for VPC, IBM Cloud Backup and Recovery, or any Block and File storage or networking components. Valid until 31 December 2026.
Boost your Backup Budget: Unlock USD 5000 in credits to use toward IBM Cloud Backup and Recovery services. Apply Code BUYBRS.
Before you begin
You need the following to get started with IBM Cloud Backup and Recovery:
- An IBM Cloud® Platform account
- An active instance of IBM Cloud Backup and Recovery that is covered in Set up a IBM Cloud Backup and Recovery deployment
- You need to start the dashboard of your backup service instance to create, manage, and monitor backup policies
Workload availability
| Workload | VPC VSI | VMware | Regions supported |
|---|---|---|---|
| File system | Yes | Yes | - North America: United States - Washington DC us-east, Dallas us-south, Canada - Toronto ca-tor- South America: Brazil - São Paulo br-sao- Europe: Europe - Frankfurt eu-de,
Europe - London eu-gb, Europe - Madrid eu-es- Asia: Japan - Tokyo jp-tok, Osakojp-osa- Australia - Sydney au-syd |
| MS SQL | Yes | Yes | - North America: United States - Washington DC us-east, Dallas us-south, Canada - Toronto ca-tor- South America: Brazil - São Paulo br-sao- Europe: Europe - Frankfurt eu-de,
Europe - London eu-gb, Europe - Madrid eu-es- Asia: Japan - Tokyo jp-tok, Osakojp-osa- Australia - Sydney au-syd |
| SAP HANA | Yes | Yes | - North America: United States - Washington DC us-east, Dallas us-south, Canada - Toronto ca-tor- South America: Brazil - São Paulo br-sao- Europe: Europe - Frankfurt eu-de,
Europe - London eu-gb, Europe - Madrid eu-es- Asia: Japan - Tokyo jp-tok, Osakojp-osa- Australia - Sydney au-syd |
| Oracle | No | Yes | - North America: United States - Washington DC us-east, Dallas us-south, Canada - Toronto ca-tor- South America: Brazil - São Paulo br-sao- Europe: Europe - Frankfurt eu-de,
Europe - London eu-gb, Europe - Madrid eu-es- Asia: Japan - Tokyo jp-tok, Osakojp-osa- Australia - Sydney au-syd |
| Kubernetes/OpenShift | Yes | No | - North America: United States - Washington DC us-east, Dallas us-south, Canada - Toronto ca-tor- South America: Brazil - São Paulo br-sao- Europe: Europe - Frankfurt eu-de,
Europe - London eu-gb, Europe - Madrid eu-es- Asia: Japan - Tokyo jp-tok, Osakojp-osa- Australia - Sydney au-syd |
| Db2 | Yes (Linux only) | No | - North America: United States - Washington DC us-east, Dallas us-south, Canada - Toronto ca-tor- South America: Brazil - São Paulo br-sao- Europe: Europe - Frankfurt eu-de,
Europe - London eu-gb, Europe - Madrid eu-es- Asia: Japan - Tokyo jp-tok, Osakojp-osa- Australia - Sydney au-syd |
High-level overview of getting started
This section assumes you’re starting from scratch without any existing resources. It guides you through creating new instances; however, you can choose to use your existing resources instead if you have them. If you create new instances, note that this increases your monthly costs. To avoid additional charges, be sure to stop your VSI at the end of the getting started steps.
| Step | Environment | Task | Note |
|---|---|---|---|
| Step 1: Set up a IBM Cloud Backup and Recovery instance | |||
| UI | Deploy your IBM Cloud Backup and Recovery instance. | ||
| UI | Create a Data Source Connection (for a VPC) in IBM Cloud Backup and Recovery. | Data source connection is a tunnel between the IBM Cloud Backup and Recovery instance and the source server. The Data Source Connector is the component that forms that tunnel. | |
| UI | Create the Data Source Connector instance for the VSI. | Connector VSI instance. | |
| UI or CLI | Reserve (or bind) Floating IP for the Connector VSI. | ||
| UI | Configure the Connector VSI in the IBM Cloud Backup and Recovery UI. | Set up password and token: First, add the domain: ‘cloud.ibm.com’ works as a default. Then, paste the claim token from the Create source connection modal. | |
| UI or CLI | Deploy (or identify) a Virtual Private Endpoint gateway instance. | ||
| Step 2: Set up a Source Virtual Server Instance (VSI) | |||
| Optional | UI or CLI | Set up (or identify) the Source Virtual Server Instance. | Source Virtual Server Instance |
| UI or CLI | Reserve (or bind) Floating IP | ||
| Step 3: Set up a IBM Cloud Backup and Recovery agent to Source VSI | |||
| UI | Download and install the Linux-based IBM Cloud Backup and Recovery script installer from the IBM Cloud Backup and Recovery > Sources page. | Securely copy the agent installer from your local environment to the Source VSI. | |
| Optional | Terminal | Verify copying | Note: The installer is not yet executable. |
| Terminal | Configure the Source Server to manage NFS (minimum requirement). | Install NFS (file handler) | |
| Terminal | Install agent to Source VSI | ||
| Step 4: Register a Source VSI into IBM Cloud Backup and Recovery | |||
| UI | Register the Source VSI in IBM Cloud Backup and Recovery UI (Source page). | Add Source VSI’s Reserved IP address | |
| Step 5: Set up a Protection group in IBM Cloud Backup and Recovery | |||
| UI - need to check plug-in | Create and configure a new Protection group in IBM Cloud Backup and Recovery UI (Protection page) | Physical server > File - Add object. | |
| Optional | UI - need to check plugin | Verify backup up creation and progress on the IBM Cloud Backup and Recovery instance subpage. |
Set up a IBM Cloud Backup and Recovery deployment
-
Deploy a Backup and Recovery instance.
- Create a IBM Cloud Backup and Recovery instance.
- Information: By default your instance is automatically encrypted. Optionally, you can bring your own key by supplying the key CRN.
- Information: When following best practices, it is recommended that you create your IBM Cloud Backup and Recovery instance in the same location as your source server.
- Open your IBM Cloud Backup and Recovery instance and Launch Dashboard.
- Create a IBM Cloud Backup and Recovery instance.
-
Create a Data Source Connection in IBM Cloud Backup and Recovery
For this step, you are setting up a Data Source Connection from inside your IBM Cloud Backup and Recovery instance.
- In the IBM Cloud Backup and Recovery Dashboard, navigate to System > Data Source Connections and click New Connection.
- Select VPC in the Deployment Platform dropdown.
- Copy or download the token as you need this later.
- Then click Create a VPC Data Source Connector, which opens the IBM Cloud catalog in a new tab.
-
Deploy a IBM Cloud Backup and Recovery Data Source Connector (Connector VSI)
In this step, you to need to create a Data Source Connector instance (Connector VSI) for the previous step’s Data Source Connection.
- The Data source connector is a Virtual Server deployed that uses a custom image, which contains the connector software. The first catalog page shows the details about this image. Click Continue to progress to the Virtual Server provisioning page.
- On the VSI provisioning page:
- Set the same location as you set for the IBM Cloud Backup and Recovery instance.
- Enter details and Server configs (you can leave it on the default).
- Create or select an SSH key.
- Create or select a VPC, which contains the workload that you are backing up.
- Click Create virtual server.
-
Make the connector for VSI accessible from your local machine [Non production only]
- Reserve or bind an existing Floating IP address to the Connector VSI to allow public access to the Connector configuration UI.
- Create a new security group rule to open the following ports to the VSI connector:
- On the VSI instance, navigate to the Networking tab,
- Open Security group link and change the inbound rule to Any.
- Copy and paste the Floating IP in a new browser tab to open the UI. This can take up to five minutes to be ready.
- It is possible that your browser flags the IP being insecure due to not using https, continue through this.
-
Access and configure Connector VSI in IBM Cloud Backup and Recovery UI
- From the login page, use username: admin, password: admin to start, then set up a new username and password. Password requirements are: must be at least 8 characters long and cannot include the word admin.
- From the Connector Configuration view, enter a Domain name (for example, cloud.ibm.com).
- Paste the connection claim token from the modal in a previous step into the connection claim text input.
- You should not need to change any other configuration parameters.
- Click Save.
-
Create a Virtual Private Endpoint gateway (VPE) instance for the IBM Cloud Backup and Recovery instance
While the Connector VSI can connect to the Backup and Recovery instance, a VPE gateway provides a better performance. To create a VPE gateway, follow these steps.
- Create a VPE instance.
- Give a service name, select the correct VPC.
- In the Cloud Service Offering dropdown, select Backup and Recovery.
- Select the previously created IBM Cloud Backup and Recovery instance from the list.
- Click Create.
Set up the Source VSI
-
Create a Virtual Server Instance for VPC For this step, you are creating a new Ubuntu VSI.
- Provision a new VSI instance.
- Specify a server name.
- In the Image tile, click Change image and select any version of Ubuntu linux.
- You can change the profile if required; however, the default works.
- Create or select an SSH key: you need it to access the virtual server later.
- In Networking, select the VPC you deployed the Data Source Connector.
- Click Create.
- Provision a new VSI instance.
Next, make the Source VSI accessible from your local machine by reserve or bind an existing Floating IP address to the Source VSI.
Set up a IBM Cloud Backup and Recovery agent to the source VSI
-
Download and install the IBM Cloud Backup and Recovery agent
- Now that you have configured the Connector with the token you can close the dialog in the Backup and Recovery Dashboard. Navigate to the Data Protection > Sources page.
- Click the Download Agent button and in the dialog select the Linux - Script installer. This will download the agent to your local machine but we will copy it to your source Virtual Server in the next step.
-
Install the IBM Cloud Backup and Recovery agent to Source VSI
-
From the terminal, go to the Downloads folder (cd/Downloads) or wherever the agent installer from the previous step was downloaded.
-
Copy the agent installer from your local environment to your source VSI using scp. For example:(Substitute necessary information in the commands.)
scp -i .ssh/SOURCE_SSH_KEY_NAME Downloads/AGENT_FILE_NAME root@FLOATING_IP_ADDRESS_OF_SOURCE_VSI:/ -
(Optional) Verify a copy by going to the root folder (cd) and listing files (ls). You should be able to see the IBM Cloud Backup and Recovery agent installer.
-
-
Format and install an agent
-
Make the installer file an executable with the command:
chmod +x cohesity_agent_VERSION__linux_x64_installerMake sure to update the VERSION placeholder with the correct version of your installer file:(Substitute necessary information in the commands.)
-
Installing the agent requires the use of NFS. Install it on your Source VSI by running the command:
apt install nfs-common -
Install the IBM Cloud Backup and Recovery agent:
sudo ./cohesity_agent_VERSION__linux_x64_installer -- --install
When the installation has been completed successfully, you should see a confirmation in your Terminal window.
-
Register the source VSI to IBM Cloud Backup and Recovery
-
Select type and register Source VSI
- Return to the IBM Cloud Backup and Recovery instance Dashboard, and navigate to the Data Protection > Sources page.
- Click the Register Source button.
- Select Physical from the dialog.
- From the dropdown, select the Data Source Connection that is created earlier.
- Click Continue.
- Copy the Reserved IP address of the Source VSI and paste in the modal. This can be found in the IBM Cloud navigation by Infrastructure → Compute → Virtual Server Instances.
- Click Complete.
Set up Data Protection in IBM Cloud Backup and Recovery
-
Set up a new Protection group
- In the IBM Cloud Backup and Recovery instance Dashboard, navigate to the Data Protection > Protection page
- Click Protect and select Physical server then File based.
- In the New Protection popup, Add Object, select your Physical Servers. It is listed as the reserved IP from the previous step.
- Click Continue.
- Add a name for the Protection Group.
- Select the Bronze protection policy.
- Bronze policy includes: taking a backup every day, retains it for 30 days and a 90 days DataLock. Learn more about policies.
- Click Protect
-
Verify protection group by navigating to the subpage.
- Open the protection group and check that a backup has started.
Next steps
Now that you are familiar with your IBM Cloud Backup and Recovery instance from the web-based console, you might be interested in doing a similar workflow from the command line. Check out using the ibmcloud backup-recovery command-line
utility to create a service instance and interacting with IAM. And you can further use curl for accessing Cloud Object Storage directly. Check out the API overview to get started.
Additionally, explore the IBM Backup and Recovery Service (BRS) Module for production-ready infrastructure automation.