Skip to main content

OADP virtual machine data protection

Use OpenShift API for Data Protection virtual machine data protection (VMDP) to back up and restore user data from within VMs on OpenShift Virtualization. This helps you to protect files and directories without relying on cluster administrators.

About OADP virtual machine data protection​

You can independently back up and restore your own data from within a virtual machine (VM) by using the OADP VM data protection (VMDP) command-line tool. This approach helps you secure specific files and directories in your encrypted repository without requiring cluster administrator privileges.

What problem is VMDP solving​

Cluster administrators manage traditional OADP backups. The administrator owns the backup storage location, controls what to back up, and manages the restore process. This means that VM users must rely on an administrator to recover their data, and the backup scope is limited to the persistent volume claims (PVCs) attached to the VM at the time of backup.

VMDP addresses this gap by shifting data ownership to the VM user. The user creates their own encrypted backup repository, chooses what data to protect, and restores data without administrator involvement. This follows zero-trust architecture principles where the user owns the data, the backup, and the encryption keys. Administrators cannot access or restore the user’s backup data.

What VMDP does​

VMDP is a command-line tool that runs inside virtual machines on OpenShift Virtualization. With VMDP, you can complete the following tasks:

  • Back up and restore files and directories from within the VM by using a single command.
  • Protect data accessible over network file systems such as Common Internet File System (CIFS) and Network File System (NFS) shares, which standard OADP backups typically exclude.
  • Create a personal encrypted repository in S3-compatible or file system storage.
  • Use data deduplication for efficient storage and fast incremental backups.

VMDP is based on Kopia and uses the same repository format.

Who uses VMDP​

VMDP is designed for VM users who need to manage their own backups independently. The user is responsible for:

  • Providing their own credentials to create an encrypted backup repository.
  • Choosing what data to back up and restore.
  • Managing backup lifecycle operations such as listing, deleting, and restoring backups.

Cluster administrators are not involved in the backup and restore process. Their role is limited to deploying the OADP Operator. The OADP Operator has the VMDP CLI available for download.

VMDP and VMFR comparison​

OADP provides two complementary features for VM data recovery:

VMDP (VM data protection)
The VM user, without cluster-admin privileges, owns the data. The user creates encrypted backups of selected files and directories from within the VM. The user holds the encryption keys and manages the backup lifecycle independently.
VMFR (VM file restore)
The cluster administrator manages the backups and file recovery. VMFR enables file-level recovery from admin-created Velero backups of entire VMs, including all PVCs. The administrator controls the backup and restore process.

Supported platforms for OADP virtual machine data protection​

Review the supported guest operating systems and architectures for the OpenShift API for Data Protection virtual machine data protection (VMDP) command-line interface. This helps you to verify that your VM environment is compatible.

VMDP is built for OpenShift Virtualization certified guest operating systems on the following platforms:

Supported guest operating systems

Guest operating systemArchitectures
Red Hat Enterprise Linuxx86_64, AArch64
Microsoft Windowsx86_64, AArch64

Each binary is statically linked and includes a SHA256 checksum for integrity verification.

OADP virtual machine data protection backend storage​

Review the backend storage options for OpenShift API for Data Protection virtual machine data protection (VMDP) backup storage locations. This helps you to configure S3-compatible or file system storage for your backup repository.

S3-compatible storage​

S3 storage options

OptionDescriptionDefault
--bucketName of the S3 bucket.(required)
--access-keyAccess key ID.(required)
--secret-access-keySecret access key.(required)
--endpointS3 endpoint URL.s3.amazonaws.com
--regionS3 region.Auto-detect
--prefixObject prefix in the bucket.None
--session-tokenSession token for temporary credentials.None
--disable-tlsDisable HTTPS.false
--disable-tls-verificationSkip TLS certificate verification.false
--root-ca-pem-pathPath to a custom CA certificate file.None
--root-ca-pem-base64Base64-encoded CA certificate.None
note

VMDP automatically prepends oadp-vmdp/ to your prefix.

Filesystem storage​

Filesystem storage options

OptionDescriptionDefault
--pathAbsolute path to the storage directory.(required)
--owner-uidUser ID for new files.Current user
--owner-gidGroup ID for new files.Current group
--file-modePermission mode for files.0600
--dir-modePermission mode for directories.0700

OADP virtual machine data protection configuration​

Review the environment variables and file locations for the OpenShift API for Data Protection virtual machine data protection (VMDP) command-line interface (CLI). This helps you to configure credentials, logging, and behavioral settings.

Environment variables​

Credential environment variables

VariableDescription
BSLS_PASSWORDBSL encryption password. Set this variable to avoid interactive prompts.
AWS_ACCESS_KEY_IDAccess key for S3 storage
AWS_SECRET_ACCESS_KEYSecret key for S3 storage
AWS_SESSION_TOKENSession token for temporary credentials

Configuration environment variables

VariableDescriptionDefault
OADP_CONFIG_PATHPath to the configuration file~/.config/oadp/repository.config
OADP_CACHE_DIRECTORYPath to the cache directorySystem-dependent
OADP_LOG_DIRDirectory for log files~/.cache/oadp/

Behavior environment variables

VariableDescriptionDefault
OADP_CHECK_FOR_UPDATESEnable or disable update checkstrue
OADP_PERSIST_CREDENTIALS_ON_CONNECTSave credentials after connectingtrue
OADP_USE_KEYRINGUse the system keyring for password storagefalse
OADP_BACKUP_FAIL_FASTFail immediately on the first errorfalse

Logging environment variables

VariableDescriptionDefault
OADP_LOG_DIR_MAX_FILESMaximum number of log files1000
OADP_LOG_DIR_MAX_AGEMaximum age of log files720h
OADP_LOG_DIR_MAX_SIZE_MBMaximum total size of log files in MB1000

File locations​

Default file locations

TypeLinuxWindows
Configuration~/.config/oadp/repository.config%APPDATA%\oadp\repository.config
Logs~/.cache/oadp/%LOCALAPPDATA%\oadp\

Kopia compatibility​

VMDP is based on Kopia and uses the same repository format. Repositories are fully compatible between the two tools.

Command mapping between VMDP and Kopia

VMDP commandKopia equivalent
bslrepository
backupsnapshot

When you connect to a VMDP repository by using the Kopia CLI, include the oadp-vmdp/ prefix that VMDP adds automatically. For example:

$ kopia repository connect s3 \
--bucket <bucket_name> \
--prefix oadp-vmdp/<your_prefix>/ \
...