Ekuqaleni kukaDisemba, isisombululo esitsha sakhululwa Veeam Backup ye-AWS ukugcinwa kunye nokubuyisela i-Amazon Elastic Compute Cloud (i-Amazon EC2) iziseko zamafu.
Ngoncedo lwayo, unokwenza iikopi ezigciniweyo zeemeko ze-EC2 kwaye uzigcine kwindawo yokugcina ilifu i-Amazon Simple Storage Service (i-Amazon S3), kwaye wenze amatyathanga ee-EC2 ezifinyeziweyo kwifomathi yemveli.
Ukufumana kwakhona idatha, iVeeam Backup ye-AWS ibonelela ngolu khetho lulandelayo:
- Ukufumana kwakhona umzekelo we-EC2 wonke
- Ukubuyisela imiqulu yemizekelo
- Ukubuyisela iifayile kunye neefolda ze-OS yeendwendwe zomzekelo
Ukongeza, ekubeni isisombululo senza i-backups kwifomathi yeVeeam, ungasebenzisa iVeeam Backup & Replication ukugcina iikopi ze-EC2 ezigciniweyo kwindawo yokugcina indawo, kwaye emva koko uhambise idatha phakathi kwelifu, i-virtual kunye ne-infrastructures.
Kwaye, ngokuqinisekileyo, abasebenzisi baya konwaba ukuba isisombululo esitsha sinenguqulelo yasimahla. Ukuqhelana ngakumbi neVeeam Backup ye-AWS, wamkelekile kwikati.
Iimpawu eziphambili
Ukongeza kubuchule obusele bukhankanyiwe bokwenza ngokuzenzekelayo izifinyezo ze-Amazon EBS kunye nokugcina ii-backups kwilifu le-Amazon S3, isisombululo siyasebenza:
- Multi-factor ungqinisiso kubalawuli backup
- Ukhuseleko lwedatha esekwe kumgaqo-nkqubo
- IAM inkxaso yokwahlulwa kwendima
- Inkxaso yoqwalaselo lwengingqi
- I-algorithm eyakhelwe-ngaphakathi yovavanyo lokuqala lweendleko zeenkonzo, ezinceda ukulawula iintlawulo.
Ewe, njengoko sele kukhankanyiwe, kukho ilayisenisi yamahhala, i-BYOL (yakha ilayisenisi yakho), kunye nelayisenisi esekelwe ekusebenziseni ubutyebi - wonke umntu unokukhetha okulungileyo.
Amanqanaba omsebenzi
Ngokufutshane, izigaba eziphambili zezi zilandelayo:
- Sijonga iziseko zethu zoncedo ukuthobela iimfuno zenkqubo ezichaziweyo
apha . - Faka iVeeam Backup ye-AWS njengoko kuchazwe ngezantsi.
- Cacisa iindima ze-IAM. Ziyafuneka ukufikelela kwizixhobo ze-AWS ezisetyenziselwa ukugcina nokubuyisela:
- Ukuba uceba ukuxhasa iimeko ze-EC2 ngaphakathi kwe-akhawunti efanayo ye-AWS, ungasebenzisa indima Ukubuyisela iSigaba esihlala sihleli - yenziwe ngexesha lofakelo lweVeeam Backup ye-AWS. Le ndima inamalungelo ayimfuneko okufikelela kuzo zonke iimeko ze-EC2 kunye neebhakethi ze-S3 ngaphakathi kwe-akhawunti ye-AWS apho i-Veeam Backup ye-AWS isetyenziswe (i-akhawunti ye-AWS yasekuqaleni).
- Ukuba uceba ukwenza i-backup okanye ukubuyisela idatha kwiimeko ze-EC2 phakathi kwee-akhawunti ezimbini ezahlukeneyo ze-AWS, okanye ufuna ukusebenzisa indima ye-IAM ezinikeleyo kunye neseti encinci yamalungelo kumsebenzi ngamnye, kuya kufuneka udale iindima ze-IAM eziyimfuneko ngaphakathi kwe-akhawunti ye-AWS yokuqala. kwaye ke wongeze kwiVeeam Backup ye-AWS. Oku kuxoxwe ngokweenkcukacha kwi
amaxwebhu .
- Siqwalasela ugcino lweziseko ezingundoqo, ezizezi:
- Ukuqwalasela indawo yokugcina ye-S3.
Qaphela: Ukuba uza kusebenzisa izifinyezo ezenziwe ngokwendalo endaweni ye-backups ukukhusela idatha yakho, ngoko ungatsiba le ngongoma, kuba Indawo yokugcina ye-S3 ayidingeki kule meko.
- Ukucwangcisa useto lwenethiwekhi kumacandelo ancedisayo iimeko zabasebenzi.
abasebenzi - Ezi zezehlo ezincedisayo zeEC2 eziqhuba iLinux OS. Ziqaliswa kuphela ngexesha lokugcinwa (okanye ukubuyisela) kwaye zisebenze njenge-proxy yokugcina. Kwizicwangciso zabasebenzi, kuya kufuneka uchaze i-Amazon VPC, i-subnet kunye neqela lokhuseleko apho le mizekelo incedisayo iya kudibanisa. Unokufunda ngako konke okuapha .
- Ukuqwalasela indawo yokugcina ye-S3.
- Emva koko senza umgaqo-nkqubo ngesiseko sokuba iikopi ezigciniweyo okanye ii-snapshots zeziganeko ze-EC2 ziya kwenziwa. Ndiza kuthetha ngale ngokufutshane apha ngezantsi.
- Ungabuyisela kwikopi yogcino - ngakumbi kule ingezantsi.
Ukusasazwa kunye noqwalaselo
IVeeam Backup ye-AWS iyafumaneka
Isisombululo sibekwe ngolu hlobo:
- Siya kwi-AWS Marketplace phantsi kwe-akhawunti ye-AWS esiceba ukuyisebenzisa ukufaka isisombululo.
- Vula iVeeam Backup yephepha le-AWS, khetha uhlelo esiludingayo (ihlawulwe okanye isimahla). Funda ngakumbi malunga namahlelo
apha .- IVeeam Backup ye-AWS yasimahla
- IVeeam Backup ye-AWS eHlawulweyo yoHlelo
- IVeeam Backup ye-AWS BYOL Edition
- Cofa phezulu ekunene Qhubekeka uBhalisa.
- Kwiphepha lomrhumo, yiya kwicandelo Migaqo nemiqathango (imigaqo yokusetyenziswa) kwaye nqakraza apho Bonisa iinkcukacha, landela ikhonkco Isivumelwano seLayisensi yomsebenzisi wokugqibela funda isivumelwano selayisensi.
- Emva koko cofa iqhosha Qhubekela kuLungiselelo kwaye uqhubeke kuqwalaselo.
- Kwiphepha Qwalasela le software seta useto lokuhlohla:
- Ukusuka kuluhlu Indlela Yokuzaliseka (ukhetho lobeko) khetha ukhetho lwemveliso yethu - I-VB yokusasazwa kwe-AWS.
- Kuluhlu lweenguqulelo Inkqubo yesoftware khetha inguqulelo yamva nje yeVeeam Backup ye-AWS.
- Ukusuka kuluhlu lwemimandla Ummandla khetha indawo ye-AWS apho umzekelo we-EC2 kunye ne-Veeam Backup ye-AWS iya kuthunyelwa.
Qaphela: Unokufunda ngakumbi malunga nemimandla ye-AWS
apha . - Emva koko cofa iqhosha Qhubekeka ngokuQalisa ukuqhubeka nokusungula.
- Kwiphepha Qalisa le software landela la manyathelo:
- Kulo candelo Iinkcukacha zoqwalaselo khangela ukuba zonke iisetingi zichanekile.
- Kuluhlu lwezenzo Khetha Isenzo khetha Qalisa CloudFormation.
- IVeeam Backup ye-AWS ifakwe kusetyenziswa i-AWS CloudFormation stack.
Qaphela: Apha, i-stack yingqokelela yemithombo yefu enokulawulwa njengeyunithi eyahlukileyo: yenziwe, isusiwe, isetyenziselwa ukuqhuba izicelo. Unokufunda ngakumbi kuxwebhu lwe-AWS.
Push Qalisa kwaye uqalise iwizadi yokudala istaki Yenza iwizadi yestaki.
Ukwakha i-AWS CloudFormation StackUkwenza istaki se-AWS CloudFormation:
- Ekuhambeni Chaza itemplate Uyakwazi ukushiya useto lwetemplate yesitaki esihlala sikhona.
- Ekuhambeni Chaza iinkcukacha zemfumba Sifaka iisetingi zesitaki sethu.
- Kwintsimi Igama lesitaki ngenisa igama; Ungasebenzisa oonobumba abakhulu nabancinci, amanani kunye nodwi.
- Kwicandelo leseto Uqwalaselo loMzekelo:
Ukusuka kuluhlu Uhlobo lwemeko yeVeeam Backup ye-AWS iseva kufuneka ukhethe uhlobo lwe-EC2 apho iVeeam Backup ye-AWS izakufakwa khona (emva koku siyakuyibiza Veeam Backup ye-AWS iseva). Kuyacetyiswa ukuba ukhethe uhlobo t2.phakathi.
Ukusuka kuluhlu Izibini ezingundoqo zeVeeam Backup ye-AWS Server Kufuneka ukhethe iperi yezitshixo eziza kusetyenziselwa uqinisekiso kulo mncedisi mtsha. Ukuba isibini esibalulekileyo esifunekayo asikho kuluhlu, kufuneka udale njengoko kuchaziweapha .
Cacisa ukuba uyafuna na ukwenza ugcino oluzenzekelayo lwemithamo ye-EBS yeVeeam Backup ye-AWS iseva (ngokungagqibekanga, okt. oyinyaniso).
Cacisa ukuba iVeeam Backup ye-AWS iseva ifuna ukuqaliswa kwakhona kwimeko yokusilela kwesoftware.
Cacisa ukuba iVeeam Backup ye-AWS iseva ifuna ukuqaliswa kwakhona kwimeko yokusilela kweziseko zophuhliso.
- Kwicandelo lezicwangciso zenethiwekhi Uqwalaselo lwenethiwekhi:
- Cacisa ukuba uyafuna na ukwenza idilesi ye-IP ye-Elastic yeVeeam Backup ye-AWS iseva. Bona apha ngeenkcukacha ezithe vetshe.
- Kwintsimi Iidilesi ze-IP ezivumelekileyo zoMthombo zoqhagamshelwano kwi-SSH cacisa uluhlu lweedilesi ze-IPv4 apho ukufikelela kwiVeeam Backup ye-AWS iseva nge-SSH kuya kuvunyelwa.
- Kwintsimi Iidilesi ze-IP ezivumelekileyo zoMthombo zoqhagamshelwano kwi-HTTPS cacisa uluhlu lweedilesi ze-IPv4 apho ukufikelela kwiVeeam Backup ye-AWS ujongano lwewebhu luya kuvunyelwa.
Ikhefu ledilesi ye-IPv4 lichazwe kwi-CIDR (umzekelo, 12.23.34.0/24). Ukuvumela ukufikelela kuzo zonke iidilesi ze-IPv4, ungangenisa 0.0.0.0/0. (Nangona kunjalo, olu khetho alukhuthazwa kuba lunciphisa ukhuseleko lweziseko ezingundoqo.)
- Ngokusekelwe kwiidilesi ze-IPv4 ezikhankanyiweyo, i-AWS CloudFormation idala iqela lokhuseleko le-Veeam Backup ye-AWS, kunye nemithetho efanelekileyo ye-traffic engenayo nge-SSH kunye ne-HTTPS. (Ngokungagqibekanga, i-port 22 isetyenziselwa i-traffic engenayo nge-SSH, kunye ne-port 443 ye-HTTPS.) Ukuba uya kukhankanya iqela lokhuseleko elahlukileyo le-Veeam Backup ye-AWS ngexesha lofakelo lwesisombululo, ungalibali ukongeza ngesandla. imigaqo efanelekileyo kweli qela kwaye ukhangele ukuba kuvunyelwe ukufikelela kwiinkonzo ze-AWS (ezidweliswe kwicandelo leeMfuno kwisikhokelo somsebenzisi).
- Kwicandelo VPC kunye ne-Subnet kufuneka ukhethe i-Amazon Virtual Private Cloud (Amazon VPC) kunye ne-subnet apho iVeeam Backup ye-AWS iseva iya kudibaniswa.
- Ekuhambeni Qwalasela iinketho zokupakisha khankanya iithegi ze-AWS, iimvume zendima ye-IAM, kunye nezinye iisetingi zesitaki.
- Ekuhambeni Review khangela zonke iisetingi, khetha ukhetho Ndiyavuma ukuba i-AWS CloudFormation inokudala izixhobo ze-IAM kwaye ucinezele Yenza isitaki.
Emva kokufakela, vula ikhonsoli yewebhu ngokukhomba kwisikhangeli kwi-DNS okanye idilesi ye-IP yomzekelo we-EC2 apho iVeeam Backup ye-AWS ifakiwe, umzekelo:
https://ec2-135-169-170-192.eu-central-1.compute.amazonaws.com
I-console ibonisa izixhobo ezilungiselelwe ukukhusela idatha usebenzisa iVeeam Backup ye-AWS:
Ukusetwa kweziseko zophuhliso eziyimfuneko, iindima, njl. zichazwe ngokweenkcukacha kwi
Imigaqo-nkqubo yogcino
Ukukhusela iimeko, sidala imigaqo-nkqubo.
Ungaqwalasela imigaqo-nkqubo eyahlukeneyo yeentlobo ezahlukeneyo zezinto: umzekelo, umgaqo-nkqubo olungiselelwe ukukhusela izicelo ze-3 (ezona zibalulekileyo), okanye imigaqo-nkqubo ye-tier 2 kunye ne-tier 1. Kwizicwangciso zomgaqo-nkqubo, khankanya:
- Iakhawunti enendima ye-IAM
- Imimandla - ungakhetha ezininzi
- Yintoni ecetywayo ukukhuselwa - oku kunokuba zonke izixhobo okanye iimeko ezikhethiweyo okanye (iithegi)
- Izibonelelo zokukhutshelwa ngaphandle
- Iisetingi ze-snapshot, kubandakanywa nokuba kusetyenziswe iisnapshots kunye nokuba loluphi ubude bexesha lokugcinwa
- Izicwangciso zogcino: indlela eya kwindawo yokugcina, ishedyuli kunye nobude bexesha lokugcinwa
- Uqikelelo lweendleko zeenkonzo (ngaphezulu malunga nalo ngezantsi)
- Ishedyuli kunye nesetingi zesaziso
Uvavanyo lweendleko zenkonzo eyakhelwe-ngaphakathi
I-Veeam Backup ye-AWS iye yakha uqikelelo lweendleko ezizenzekelayo ukubala ngokukhawuleza iindleko zeenkonzo zokulondoloza ngokusekelwe kumgaqo-nkqubo othile. Ubalo lubandakanya ezi metrics zilandelayo:
- Ixabiso lokugcina
- Iindleko zomfanekiso
- Iindleko zezithuthi - oku kubaluleke ngakumbi ukuba indawo yokugcina ifumaneka ngaphandle kommandla apho izinto zesiseko zisebenza khona (i-Amazon AWS ihlawulisa i-traffic kwezinye iindawo)
- Iindleko zentengiselwano
- iindleko zizonke
Idatha ingathunyelwa kwi-CSV okanye ifayile ye-XML.
Amacandelo aNcedisayo-Abasebenzi
Ukunciphisa iindleko zendlela, unokuqwalasela ukudalwa okuzenzekelayo kwezinto ezincedisayo - sebenzi - kwindawo efanayo ye-AWS njengezinto ezikhuselweyo. Abasebenzi baqaliswa ngokuzenzekelayo kuphela ngexesha lokudluliselwa kwedatha ukusuka / ukuya kwifu le-Amazon S3 okanye ngexesha lokubuyisela, kwaye emva kokugqiba imisebenzi bayacinywa kwaye bacinywe.
Ugcino
Ukwenza imisebenzi yokugcina, iVeeam Backup ye-AWS isebenzisa izifinyezo zendalo (bona.
Iifoto zomthonyama
IVeeam Backup ye-AWS yenza izifinyezo zomthonyama zomzekelo weEC2 ngolu hlobo lulandelayo:
- Okokuqala, izifinyezo zemiqulu ye-EBS eqhotyoshelwe kulo mzekelo ziyathathwa.
- Ii-snapshots ze-EBS zabelwe iithegi ze-AWS xa zenziwe. Izitshixo kunye namaxabiso ezi thegi ziqulathe metadata efihliweyo. Ugcino lweVeeam lwe-AWS luphatha ii-EBS ezikhawulezayo ngemetadata njengee-snapshots zendalo zomzekelo we-EC2.
- Ukuba umzekelo we-EC2 sele uxhomekeke kumgaqo-nkqubo wokulondoloza, i-Veeam Backup ye-AWS ihlola inani lamanqaku okubuyisela kwi-snapshot chain. Ukuba idlula umda wepolisi, eyona ndawo indala iyacinywa. Qaphela: Umgaqo-nkqubo wokugcina kunye nokucima ngokuzenzekelayo (ukugcinwa) akusebenzi kwii-snapshots ezenziwe ngesandla (sithetha nge-snapshots ezenziwe ngokwahlukileyo). Unokuzicima ezo zifinyezo njengoko kuchaziwe
apha . (Ukuba ngokuthi "ngesandla" sithetha ukusungula ngesandla umgaqo-nkqubo ngaphandle kweshedyuli, i-retouch iya kusebenza kwi-snapshot eyenziwe ngolu hlobo.)
Iikopi zomgangatho womfanekiso
Nantsi indlela iVeeam Backup ye-AWS eyenza ngayo i-backups yenqanaba lomfanekiso:
- Okokuqala, izifinyezo zemiqulu ye-EBS eqhotyoshelwe kulo mzekelo ziyathathwa.
- IVeeam Backup ye-AWS isebenzisa ii-snapshots ze-EBS njengemithombo yokugcina. Nje ukuba inkqubo yogcino igqityiwe, ezi snapshots ziyacinywa.
- Umsebenzi oncedisayo uqaliswa kwingingqi ye-AWS apho umzekelo ukhoyo ukunceda ukucubungula idatha ye-EC2 yomzekelo.
- Imiqulu ye-EBS yenziwe ngokusuka kwimifanekiso yethutyana kwaye iqhotyoshelwe kumzekelo wabasebenzi.
- Idatha ifundwa kwimiqulu ye-EBS kumzekelo wabasebenzi, emva koko idatha idluliselwa kwindawo yokugcina i-S3, apho iya kugcinwa kwifomathi yeVeeam.
- Ngexesha leseshini eyongezelelweyo, i-Veeam Backup ye-AWS ifunda imethadatha yokulondoloza kwi-S3 yokugcina kwaye iyisebenzise ukuchonga iibhloko ezitshintshileyo ukususela kwiseshoni yangaphambili.
- Xa i-backup igqityiwe, iVeeam Backup ye-AWS icima izifinyezo ze-EBS zethutyana kunye nemizekelo yabasebenzi kwiAmazon EC2.
Ukubuyisela idatha
NgeVeeam Backup ye-AWS, unokubuyisela idatha ngezi ndlela zilandelayo:
- Kwindawo yokuqala, bhala ngaphezulu umzekelo wokuqala. Yonke idatha kulo mzekelo iya kubhalwa ngaphezulu ngabo bagcinwe kwi-backup, kwaye uqwalaselo lomzekelo luya kugcinwa.
- Kwindawo entsha, ukwenza umzekelo omtsha. Kule meko - ukuba ukhetha ukubuyisela kwindawo entsha okanye ngezicwangciso ezintsha - kuya kufuneka uchaze izicwangciso zoqwalaselo eziza kusetyenziswa kumzekelo xa ukubuyisela kugqityiwe:
- Ummandla
- Iisetingi zoguqulelo oluntsonkothileyo
- Igama lomfanekiso kunye nohlobo
- Izicwangciso zenethiwekhi: I-Virtual Private Cloud (VPC), i-subnet, iqela lokhuseleko
Ukubuyisela umthamo
Ukubuyisela imiqulu yemizekelo ye-EC2 ukusuka kwisnapshot okanye kwi-backup, ukuya kweyokuqala okanye kwindawo entsha, nayo iyaxhaswa. Kwimeko yesibini, kwindawo entsha kufuneka ucacise ummandla we-AWS, uMmandla wokuFumana kunye nezinye iiparitha.
Inkqubo yokubuyisela kwakhona ibandakanya abasebenzi.
Inkqubo ngokwayo ngokufutshane ijongeka ngolu hlobo (usebenzisa umzekelo wokubuyisela kwi-backup):
- IVeeam Backup ye-AWS isungula abasebenzi kwindawo efunwayo ye-AWS, yenza inani elifunekayo lemiqulu ye-EBS engenanto kwaye incamathele kumzekelo wabasebenzi.
- Ibuyisela idatha ukusuka kwi-backup ukuya kule miqulu.
- Ikhupha imiqulu ye-EBS kwaye iyifudusele kwindawo efunwayo (umthombo okanye omnye ummandla we-AWS), apho imiqulu igcinwa njengemiqulu eyahlukileyo.
- Ucima umzekelo womsebenzi xa umsebenzi ugqityiwe.
Qaphela: Ungalibali ukuba emva kokubuyisela umthamo awuyi kuqhotyoshelwa ngokuzenzekelayo kwimeko ye-EC2 (iya kugcinwa nje kwindawo echaziweyo njengomthamo we-EBS owahlukileyo).
UkuBuyiselwa kweFayile
Ikuvumela ukuba ubuyisele iifayile ezizimeleyo ngaphandle kokubuyisela wonke umzekelo.
Xa uqalisa ukubuyiswa kwenqanaba lefayile, ufumana i-URL (esekelwe kwigama lomsebenzisi likawonke-wonke le-DNS) apho unokubona khona ifayile yefayile kwi-OS yeendwendwe, ufumane iifayile eziyimfuneko kuyo, kwaye uzilayishe kumatshini wendawo.
Kwakhona, ukuqinisekisa ukhuseleko, unokujonga isatifikethi kunye neminwe yaso ukuze uqiniseke ukuba akukho MiTM.
Ukudityaniswa neVeeam Backup & Replication
Ukuba uneVeeam Backup & Replication efakwe kwisiseko sakho, unokuqwalasela ukubuyiswa koomatshini bayo kwilifu le-Amazon EC2 usebenzisa i-Restore ngqo kwi-AWS ukusebenza, kwaye emva koko ukhusele le datha yefu ngeVeeam Backup ye-AWS.
IVeeam Backup & Replication ikwaxhasa ukusebenza kunye neAmazon S3 yokugcina iiVeeam Backup ye-AWS idala - unokubuyisela iikopi ezigciniweyo ze-Amazon EC2 iimeko kwisiseko sendawo.
Iimpawu zenguqulelo yasimahla
Inguqulelo yasimahla yeVeeam Backup ye-AWS ikuvumela ukuba wenze i-backup ukuya kwi-10 EC2 iimeko; Ukubuyisela kwii-backups kwenziwa ngaphandle kwezithintelo.
Qaphela: Usetyenziso olucetyiswayo t2.phakathi.
Ixabiso eliqikelelweyo lezibonelelo yi-9.8 USD / ngenyanga, ngokusekelwe kusetyenziso lwe-XNUMX/XNUMX kunye nezicwangciso ezilandelayo ezisisiseko:
- EC2 - 1 t3.micro umzekelo
- I-EBS - 1 GP2 ivolumu ye-8 GB
- Uqwalaselo lwe-S3 repository - 50 GB Standard S3 yokugcina, 13 S000 PUT izicelo, 3 S10 GET izicelo, 000 GB S3 Khetha ukusetyenziswa
amakhonkco aluncedo
Veeam Ugcino lwe AWS isisombululo kwi
umthombo: www.habr.com