Cross-region backup

Updated at:

Cross-region backup continuously replicates your backup data to a vault in a different region, providing a disaster recovery mechanism against regional failures. Configure cross-region backup to replicate data to a replication target vault under the same account in a different region, and restore data from the replication target vault when needed.

How it works

A backup vault is a cloud storage repository provided by Cloud Backup to store backup data.

After you configure cross-region backup, all existing backup data in the standard tier of the source backup vault, and all data generated afterward, is continuously and securely replicated to the replication target vault by an asynchronous replication mechanism. The replication target vault serves as a read-only replica of the source backup vault and is dedicated to disaster recovery and high availability.

The replication process runs automatically in the background and requires no manual intervention. The mechanism balances cross-region network latency against transfer efficiency, maintains data consistency, and achieves an acceptable Recovery Point Objective (RPO) that meets the disaster recovery requirements of most business scenarios.

When a regional failure or a major disaster occurs, such as a data center outage or a natural disaster, you can restore data from the replication target vault in the remote region and rebuild critical applications and data to maintain business continuity.

Note

The term "mirror vault" has been upgraded to "replication target vault" automatically. You do not need to update anything manually. Unlike a mirror vault, which cannot be managed independently, a replication target vault is retained after you stop replication. After replication stops, you can manage the backup points in the vault and enable backup lock for the vault.

image

Supported data sources

Cross-region backup supports the following data sources: ECS files, OSS, on-premises NAS, Apsara File Storage NAS, Tablestore, CPFS, local files, and SAP HANA.

Important

For ECS whole-instance data sources, you can configure cross-region backup only in a backup policy. See Enable cross-region replication.

Quotas and limits

The following constraints apply to cross-region backup.

Regional availability — For the regions that support cross-region backup, see Feature availability by region.

Vault restrictions — Cross-region backup is not supported for OSS Backup (free for 30 days), NAS Backup (free for 30 days), and Tablestore Backup (free for 30 days) vaults, replication target vaults, archive vaults, database backup vaults, container backup vaults, or vaults in an abnormal state, such as ERROR.

Account quota — Each account can create a maximum of five replication target vaults in each region.

VMware limitation — You cannot restore a VMware virtual machine backup from a replication target vault.

Replication rules — The following replication rules apply:

  • A backup vault can synchronize data to only one replication target vault. Even after the previous replication relationship is stopped, that replication target vault cannot be used for another replication relationship.

  • A replication target vault can store and restore only data that is already replicated. You cannot configure a backup plan in it to create backups.

  • After you configure cross-region backup, the backup point lifecycle of a destination backup vault in the replicating state stays consistent with the source account and cannot be modified.

    Lifecycle and retention — The following lifecycle rules apply:

  • If you enable automatic archiving for the source backup vault, data in the archive tier of the source backup vault is not synchronized to the replication target vault. After data in the standard tier of the source backup vault moves to the archive tier, the corresponding data in the replication target vault is deleted.

  • Before you delete a source backup vault, you must stop cross-region backup. Deleting the source backup vault afterward does not delete the replication target vault.

  • Because the backup points in a replication target vault are not associated with any backup policy, they are automatically deleted based on the retention period configured in the source backup vault after the replication relationship stops. You can also delete them manually before then. Even if the backup policy associated with the source backup vault specifies "Retain at least one version", that setting does not take effect in the replication target vault. Modifying the retention period of backup points in a replication target vault is not supported.

    Encryption — Regardless of whether the source backup vault uses the Cloud Backup-managed or KMS encryption method, the replication target vault must use the same encryption method.

Prerequisites

The Storage Vault Type of the source backup vault is General Backup, and the Storage Vault Type of the destination backup vault is Replication Target vault. To view the types of the vaults that you created, see Manage storage vaults. You can create a backup vault on the Storage Vaults page, when you create a backup policy, or when you configure a backup vault for a backup source.

Configure cross-region backup

You can enable cross-region backup on the Storage Vaults page or in Policy Center. After you enable it, all existing backup data in the standard tier of the source backup vault and all new backup data generated after that point in time is automatically synchronized to the replication target vault.

Note

For ECS whole-instance data sources, you can configure cross-region backup only in a backup policy. For other data sources, you can use either entry point.

Note: For how to enable Backup Vault Replication when you create or edit a policy, see Policy Center.

  1. Go to the Cloud Backup console - Storage Vaults page. On the Storage Vaults page, select the region of the source backup vault.

  2. In the Actions column of the target backup vault, click Configure Vault Replication.

  3. In the Initiate Vault Replication panel, configure the replication target vault:

    • If a replication target vault is already available, click Select Replication Target Vault and then select the destination region and the replication target vault.

    • If you have not created a replication target vault, or the existing replication target vault does not meet your requirements, click Create Replication Target Vault and then configure the parameters described in the following table.

    Parameter

    Description

    Destination Region

    Select the region of the replication target vault. The region must be different from the region of the source backup vault.

    Vault Name

    Enter a name for the replication target vault.

    Vault Description

    Enter a description for the replication target vault.

    Vault Resource Group

    Select the resource group to which the replication target vault belongs.

    Vault Encryption Method

    The encryption method of the replication target vault must be the same as the encryption method of the source backup vault. Select the encryption method of the replication target vault. The default value is Cloud Backup-managed, which uses the encryption method provided by the backup service. If the source backup vault is encrypted with a custom key of Alibaba Cloud KMS, click KMS and then select a KMS Key ID. For more information, see Instance selection.

  4. Click OK.

    After you complete the configuration, Cloud Backup starts to synchronize the historical data of the source backup vault. You can view the synchronization progress in the destination region. After the synchronization is complete, all data in the source backup vault is backed up. In the vault list, the status column of the destination vault displays Active, and Replicating to vault and the ID of the destination backup vault appear below it, which indicates that cross-region backup replication is in progress. The Actions column provides the Stop Vault Replication link, which you can use to stop the replication task.

Restore data from a replication target vault

You can restore data from a replication target vault for the following data source types. Select the section that matches your data source.

Data source

Section

ECS files

Restore ECS files

OSS

Restore OSS data

Apsara File Storage NAS

Restore Apsara File Storage NAS data

SAP HANA

Restore an SAP HANA instance

Tablestore

Restore Tablestore data

On-premises NAS

Restore on-premises NAS data

Local files

Restore local files

CPFS

Restore CPFS data

Restore ECS files

  1. Create an Elastic Compute Service (ECS) instance in the console to use for data restoration.

    The region of the ECS instance must be the same as the region of the replication target vault.

  2. Create an Restore files to an ECS instance job in the Cloud Backup console.

    For the source backup vault, select the replication target vault. For the object to restore, select the ECS instance that you created in Step 1. Configure the other settings in the same way as you configure a backup job. After the restoration is complete, the data is restored to the corresponding data source in the region of the replication target vault.

Restore OSS data

  1. Create an OSS bucket to use for data restoration.

    The region of the OSS bucket must be the same as the region of the replication target vault.

  2. In the Cloud Backup console, Create an OSS restore job.

    For the source backup vault, select the replication target vault. For the object to restore, select the OSS bucket that you created in Step 1. Configure the other settings in the same way as you configure a backup job. After the restoration is complete, the data is restored to the corresponding data source in the region of the replication target vault.

Restore Apsara File Storage NAS data

  1. Create an Apsara File Storage NAS file system to use for data restoration.

    The region of the Apsara File Storage NAS file system must be the same as the region of the replication target vault.

  2. In the Cloud Backup console, create a restore job for a single NAS file system in the same region.

    For the source backup vault, select the replication target vault that you created. For the object to restore, select the Apsara File Storage NAS file system that you created in Step 1. Configure the other settings in the same way as you configure a backup job. After the restoration is complete, the data is restored to the corresponding data source in the region of the replication target vault.

Restore an SAP HANA instance

  1. Prepare an SAP HANA instance to use for data restoration.

    The region of the SAP HANA instance must be the same as the region of the replication target vault.

  2. In the Cloud Backup console, complete Register an SAP HANA instance.

  3. Create an Restore an SAP HANA database job in the Cloud Backup console.

    For the source backup vault, select the replication target vault. For the object to restore, select the SAP HANA instance that you prepared in Step 1. Configure the other settings in the same way as you configure a backup job. After the restoration is complete, the data is restored to the corresponding data source in the region of the replication target vault.

Restore Tablestore data

  1. Create a Tablestore instance to use for data restoration.

    The region of the Tablestore instance must be the same as the region of the replication target vault.

  2. Create a Restore a Tablestore table job in the Cloud Backup console.

    For the source backup vault, select the replication target vault. For the object to restore, select the Tablestore instance that you created in Step 1. Configure the other settings in the same way as you configure a backup job. After the restoration is complete, the data is restored to the corresponding data source in the region of the replication target vault.

Restore on-premises NAS data

  1. Prepare an on-premises NAS to use for data restoration.

  2. Install a backup client, which is required to run the restore job.

  3. Create an Restore a local NAS job in the Cloud Backup console.

    For the source backup vault, select the replication target vault. For the object to restore, select the on-premises NAS that you prepared in Step 1. Configure the other settings in the same way as you configure a backup job. After the restoration is complete, the data is restored to the corresponding data source in the region of the replication target vault.

Restore local files

  1. Prepare a local server to use for data restoration.

    The restored files are saved on that local server. Create a restore folder on the server.

  2. Install a backup client, which is required to run the restore job.

  3. Create an Restore on-premises files job in the Cloud Backup console.

    For the source backup vault, select the replication target vault. For the object to restore, select the local server that you prepared in Step 1. Configure the other settings in the same way as you configure a backup job. After the restoration is complete, the data is restored to the corresponding data source in the region of the replication target vault.

Restore CPFS data

  1. Prepare a CPFS file system to use for data restoration.

    The region of the CPFS file system must be the same as the region of the replication target vault.

  2. Create a Restore CPFS job in the Cloud Backup console.

    For the source backup vault, select the replication target vault. For the object to restore, select the CPFS file system that you prepared in Step 1. Configure the other settings in the same way as you configure a backup job. After the restoration is complete, the data is restored to the corresponding data source in the region of the replication target vault.

Stop cross-region backup

Important

After you stop cross-region backup, the current replication relationship cannot be restored. Proceed with caution. After it is unbound, the replication target vault can be used only for data restoration.

To stop the cross-region backup feature, go to the region of the source backup vault, click Stop Vault Replication in the Actions column of the source backup vault, and complete the confirmation.

After you stop cross-region backup, new data in the source backup vault is no longer replicated to the destination, and the data that is already replicated to the replication target vault can still be used for restoration.

Important

A delete operation deletes all backup data in the backup vault, and the corresponding backups cannot be restored. Proceed with caution.

After you stop cross-region backup, perform the following operations as needed:

  • Delete the data in the replication target vault: Go to the restore job creation page, select this replication target vault, and delete the data.

  • EnableImmutable backupfor the replication target vault: This prevents the backup data in the vault from being deleted by mistake or attacked by ransomware before the retention period expires.

  • Delete the data in the source backup vault: Go to the region of the source backup vault, move the pointer over the ┇ icon in the Actions column of the source backup vault, and select Delete. Complete the confirmation to delete the data.

Billing

  • When you use cross-region backup, you are charged a storage capacity fee and a cross-region replication traffic fee.

    To offset the storage capacity fee, we recommend that you refer to Purchase resource plans and purchase a subscription resource plan. The cross-region replication traffic fee supports only pay-as-you-go.

  • When you use a replication target vault to restore data to the corresponding resource in the same region, Cloud Backup does not charge a restoration fee.

    When you restore data to an on-premises NAS or a local server over the Internet instead of a VPN or an Express Connect circuit, you are charged an outbound Internet traffic fee. The traffic fee is calculated based on the amount of data that is actually restored. For more information, see On-premises NAS restoration fees and Local server file restoration fees.

    For pricing details, see Cloud Backup pricing.

References