Backup strategies for SAP HANA on IBM Power Virtual Server

IBM Cloud offers a robust IBM® Power® Virtual Server infrastructure to run SAP HANA, and this document outlines the steps and best practices for performing backups of SAP HANA database.

When you deploy SAP HANA on an Power Virtual Server instance, implement a reliable and efficient backup strategy to help ensure data availability and recoverability. Two primary backup methods are available for SAP HANA databases that run on Power Virtual Server:

  1. IBM SAP HANA Backint Agent for IBM Cloud Object Storage
  2. Secure automated backup with Compass for SAP HANA

These methods provide flexible, secure, and scalable backup options for SAP HANA. The method that you choose depends on your infrastructure and requirements.

IBM SAP HANA Backint agent for IBM Cloud Object Storage

The IBM Backint Agent for SAP HANA with IBM Cloud Object Storage is an SAP-certified backup agent that IBM developed. It implements the SAP Backint API and connects SAP HANA directly to IBM Cloud Object Storage for data, log, and catalog backups. The agent runs on IBM Power servers (ppc64le) and supports both SUSE Linux Enterprise Server (SLES) and Red Hat Enterprise Linux (RHEL).

For documentation, installation steps, and the latest release, see the ibm-sap-hana-backint-cos GitHub repository.

Prerequisites

Before you begin, ensure that following prerequisites are met:

  • You have an active IBM Cloud Object Storage instance with a bucket that uses Regional resiliency and has Object Versioning and Object Lock enabled. Cross-region resiliency is not supported.
  • The IAM identity that the agent uses has the required permissions on the bucket. For the complete list, see the prerequisites in the GitHub README.
  • You have downloaded the latest release from the GitHub releases page.

For better backup performance and security, create a Virtual Private Endpoint gateway of type Cloud Object Storage in an IBM Cloud VPC. Then, attach both the VPC and the Power Virtual Server workspace to the same Transit Gateway. Add the VPE IP address and hostname to /etc/hosts on the Power Virtual Server instance.

Installing and configuring the agent on the host

For installation and configuration instructions, see the GitHub README. The README describes how to download and install the agent, choose an authentication method, create the configuration file, and set the required SAP HANA global.ini parameters. For IBM Power Virtual Server, OAuth trusted profile authentication is recommended.

This agent is also referenced in SAP Note 3644731 - Install and Configure IBM Backint agent for SAP HANA with IBM Cloud Object Storage.

Secure automated backup with Compass for Linux

The Backup Offering is powered by Cobalt Iron Compass and is accessible from the IBM Cloud catalog. The Backup Offering provides enterprise-class backup and restore features in a cloud-centric SaaS solution. Compass capabilities and security features, along with many other security functions provides protection and self-assessments to protect enterprise data and applications.

For more information, see Cobalt Iron documentation.

Cobalt Iron Compass protects various platforms, applications, and data classes. The Backup Offering includes the following unique features and functions for SAP HANA on Power Virtual Server:

  1. HDBackInt-integrated backup and restore of SAP HANA databases
  2. HDBackInt-integrated backup and restore of SAP HANA redo log files
  3. Support for the SAP HANA Cockpit for configuration, monitoring, and scheduling of backups

The Backup Offering provides various integrated security and operational features that includes:

  1. Alerting, notifications, and ticketing features and integration
  2. Automated auditing and validation of backup server landscape
  3. Backup server automation that includes hands-free automation of all backup server tasks
  4. Centralized policy management
  5. Complete governance
  6. Data reduction through compression and deduplication
  7. Data replication across regions in IBM Cloud
  8. Encryption of data in all phases from in-transit, to-storage, and at-rest
  9. Extensive support for encryption, data immutability, and other security access controls
  10. Multitenancy and unlimited sub-organizations
  11. Role-based access control management.

undefined

Provisioning the Backup Offering service in IBM data center

Complete the following steps to set up the Backup Offering from the IBM Cloud catalog:

  1. For Compass to create or manage VPCs, Transit Gateways, and other cloud networking resources, provide an IBM Cloud API key with the following cloud resource permissions for your IBM Cloud account:

    • Transit Gateway (Resource Group specific) : transit.gateway.edit
    • VPC Infrastructure (All Resources): is.vpc.vpc.list and is.vpc.vpc.read
    • VPC Infrastructure (Resource Group specific): is.vpc.vpc.create
  2. In the search box, type "Compass Backup" and click Secure Automated Backup with Compass for PowerVS tile.

  3. Select a deployment location for your backup target.

    Do not to deploy any additional resources to the Backup Offering VPC.

  4. Specify the Pricing plan, Service name, Resource group, your IBM Cloud API key, and Compass organization name according to your business needs. Also, specify the VPC subnet IP address range that you want to use to access the Compass Vaults.

  5. Click Create.

  6. Compass creates and connects the Backup VPC to the Power Virtual Server workspace that you want to back up by using the local Transit Gateway. A local Transit Gateway is created if it does not exist.

    For more information, see Ordering IBM Cloud Transit Gateway and Using virtual private endpoints for VPC to privately connect to IBM Cloud Transit Gateway.

  7. Click Launch Compass UI that will redirect you to the Cobalt Iron Compass Commander page where you need to complete the setup. For more information, see Cobalt Iron documentation.

Connectivity between Power Virtual Server instances and the backup servers is established via a Transit Gateway connection to the backup VPC. Name resolution is for the backup server connections, which is also required. You can accomplish this using the agent system's /etc/hosts file, or by adding CNAME entries to your agent system's DNS server. These elements need to be deployed in your account (Transit Gateway and VPC provisioning and setup happens through automation when the Backup Offering is provisioned).

Installing and configuring the agent on the host

For detailed installation and configuration steps refer to the SAP HANA agent setup process PDF

Pricing

When you use the Backup Offering, you are billed monthly through IBM Cloud for the amount of data backed up for the region and are billed hourly. For more information about pricing plans, see Cobalt Iron - Secure Automated Backup page accessible from the IBM Cloud catalog. You can generate an estimate of the cost based on your expected usage from the Summary pane.

Supported data centers

The single copy Backup Offering is available in the following data centers:

  • DAL10
  • DAL12
  • DAL13
  • FRA04
  • FRA05
  • LON04
  • LON06
  • MAD02
  • MAD04
  • OSA21
  • SAO01
  • SAO04
  • SYD04
  • SYD05
  • TOK04
  • WDC04
  • WDC06
  • WDC07

The dual copy Backup Offering is available in the following data center pairs:

Data center pairs that are availibile for Backup Offering
Data Center 1 Data Center 2
DAL10 WDC07
DAL12 WDC06
MAD02 FRA04
MAD04 FRA05
SAO01 SAO04
OSA21 TOK04
SYD04 SYD05
DAL13 WDC04
LON04 LON06

Additional support

Support for the Backup Offering is provided by Cobalt Iron.

  • For more information about the offering, see the Cobalt Iron documentation.
  • For issues related to backup and restore, contact Cobalt Iron by opening a service ticket through support.cobaltiron.com.