Encrypted backups, PBS replication and disaster recovery

Klug

Active Member
Jul 24, 2019
71
5
28
51
Hi.

We're currently running a PVE cluster of a few nodes and a PBS in the same datacenter.
The PBS is used for the backup of the VMs and these backups are encrypted (using integrated encryption feature).

We're going to add another PBS in another datacenter (far from the first one) so we have the backups availaible in case of physical issue in the the datacenter.
We intend to use the integrated replication feature between the two PBS.

I don't see any reason this (replication) would not work because of encrypted backups on the first PBS.

But I have concerns about disaster recovery (restoring the VM from the second PBS): they will be encrypted with the key used for the first PBS (locally stored on PVE nodes).
So this means I have to save (and keep safe outside of first datacenter) the encryption key on PVE side (/etc/pve/priv/storage/*).
And rename them to the second PBS name before deploying them manually on new PVE nodes if I want to disaster recover.

Is there anything else to prepare (save) in this use case?
 
So this means I have to save (and keep safe outside of first datacenter) the encryption key on PVE side (/etc/pve/priv/storage/*).
And rename them to the second PBS name before deploying them manually on new PVE nodes if I want to disaster recover.
Yes, you need to store the encryption keys somewhere.
Is there anything else to prepare (save) in this use case?
No. But I suggest you test restoring data to make sure it works.
 
  • Like
Reactions: Stoiko Ivanov
Great, thank you.

My first sync job is currently running.
Once it's done, I'll do additional tests such as restoring.
 
also is i possible to have 2 datastore on each PBS :
- one for the local backups
- one to store the replicated backups from the other remote PBS ?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!