Backup policy

更新时间:
复制 MD 格式

OceanBase Database lets you modify backup policies. You can change parameters, such as the backup cycle, backup time, and retention period, and enable or disable archive or geo-redundant backups as needed. When a cluster instance is created, a local level-1 backup policy is created and log backup is enabled by default.

Concepts

  • Archive backup: You can enable archive backup for backup files that require long-term retention and are restored infrequently. This feature incurs additional fees. For more information about billing, see Backup and restoration billing. After you enable archive backup, backup files are migrated to archive storage after the retention period for level-1 backups expires. Backup files in archive storage must be retained for at least 60 days. If you disable this feature before the 60-day period ends, you will be charged for the full 60-day storage cost for any files that have been stored for less than 60 days.

    Note
    • Archive backup depends on local level-1 backups, so you must create a local level-1 backup first. To enable the archive backup feature, contact OceanBase technical support.

    • Archive backup is supported only on OceanBase Database V2.2.77 and later.

    • Archive backup can effectively reduce your backup costs. However, because archive backups use low-speed storage media, restoration is slower than from level-1 backups.

    • Serverless instances do not support archive backup.

  • Geo-redundant backup: Geo-redundant backup depends on local backups, so you must create a local backup first. However, the frequency, cycle, and data retention policy for geo-redundant backups can differ from those for local backups. A geo-redundant backup saves another copy of the backup file in a specified region. The storage space used for the geo-redundant backup is billed separately. For more information about billing, see Backup and restoration billing. You can set only one region for geo-redundant backups for each backup instance. If you change the region or disable geo-redundant backup, the original level-1 geo-redundant backup files are automatically deleted.

    You can choose a weekly or monthly backup frequency. If you choose a weekly frequency, and local backups are performed more than once a week, you can select at least one of those local backups to be used for the geo-redundant backup. If you choose a monthly frequency, you can perform the geo-redundant backup once or twice a month.

    Geo-redundant backup is suitable for scenarios that require high data availability but have low requirements for data consistency, such as large enterprises and multinational corporations. It helps improve data security, ensure data availability, and reduce data restoration time.

    Note
    • Restoring data from a geo-redundant backup requires the most recent data backup taken before the recovery point, along with all log backups created since that data backup. To ensure that data can be restored to any point within the specified retention period, the system may retain backups for longer than the period you set.

    • Serverless instances do not support geo-redundant backup.

  • Sparse backup: Sparse backup lets you set a more flexible backup policy and retain a minimum number of backup sets. This helps minimize your storage costs and is often used for business scenarios that require long-term backup retention, such as for auditing. To ensure that data can be restored to any point in time within the backup interval, you must retain log backups. If you disable this feature, the system immediately deletes the corresponding backup files.

    Note
    • Sparse backup is currently available only to users on the whitelist. To enable this feature, contact OceanBase technical support.

    • You cannot apply a sparse backup policy to expired backup sets.

    • After you enable a sparse backup policy, you can modify or disable it.

      • If you modify the backup cycle or retention policy of a sparse backup, existing sparse backups that do not meet the new policy are deleted.

      • If you disable the sparse backup policy, existing sparse backups are deleted.

    • The billable items and billing method for a sparse backup policy are the same as those for a level-1 backup policy. For more information, see Backup and restoration billing.

    • If a scheduled sparse backup is not successfully generated on a given day (for example, because the backup fails or is not completed until the next day), the backup for that day is skipped. No extra backup set is retained to compensate. For example, if your policy is to back up on the 1st of each month and the backup on August 1 fails, no backup set will be retained for August 1.

    • After you enable sparse backup, you cannot enable archive backup or geo-redundant backup.

    • Serverless instances do not support sparse backup.

Set a backup policy

  1. Log on to the OceanBase Management Console .

  2. In the navigation pane on the left, click Instance List.

  3. In the instance list, find the target cluster instance and click its name to navigate to the Cluster Instance Workspace.

  4. In the navigation pane on the left, click Backup and Restoration. On the Backup and Restoration page, click the Backup Policy tab. Here, you can view the backup policy for the cluster instance. If this is the first time you are backing up the cluster, the default backup policy is displayed.

  5. In the upper-right corner of the page, click Modify Backup Policy to modify the backup policy configuration:

    Parameter

    Default value

    Description

    Backup file storage region

    Local

    The storage region for backup files is the city where the current cluster instance is located.

    Data backup type

    Full

    Currently, only full data backup is supported.

    Log backup

    Enabled by default

    Log backup is enabled by default and cannot be disabled.

    Enabling log backup lets you restore data to any point in time within the log backup time range, in addition to the snapshot points of backup sets.

    Backup cycle

    The day after the cluster instance is created.

    For example, if you create the cluster instance on a Monday, the backup cycle starts on Tuesday.

    You can select the dates for backups to be performed on specified days of the week or month.

    For data security, back up at least once a week.

    Backup time

    04:00

    You can set the specific backup time from the drop-down list.

    • Perform backups during off-peak hours as needed.

    • Avoid setting the time within the data merge window (one hour before and after the data merge time) to prevent backup job delays.

    Data backup retention period / Days for point-in-time recovery

    7 days

    By default, backup data is retained for 7 days. You can set the retention period from 2 to 7,200 days. For more information about the relationship between Backup cycle and Data backup retention period / Days for point-in-time recovery, see Relationship between backup cycle and data backup retention period.

    Sparse backup

    Disabled by default

    You can enable or disable sparse backup as needed.

    • The backup cycle for sparse backup depends on the local level-1 backup. You can select from the dates already chosen for the level-1 backup.

    • You can set a custom retention period for sparse backup data (30 to 7,200 days) or retain it permanently.

    • You can also choose whether to retain log backups.

    Archive backup

    Disabled by default

    You can enable or disable archive backup as needed.

    • By default, the backup cycle for archive backup is the same as that for level-1 backup, but the time can be modified.

    • When a local level-1 backup expires, the system automatically converts it to an archive backup. The retention period for an archive backup is calculated from the creation time of the local level-1 backup. You must set its retention period to be longer than the original retention period of the local level-1 backup.

    • The retention period for archive backup data is 60 to 7,200 days.

    • The data backup type, backup file storage region, and log backup information for archive backups are the same as those for level-1 backups.

    Geo-redundant backup

    Disabled by default

    You can enable or disable geo-redundant backup as needed.

    • The backup cycle can be configured on a weekly or monthly basis.

      Note

      Level-1 geo-redundant backup depends on local level-1 backup. You cannot set a time for a level-1 geo-redundant backup if that time is not set in the local level-1 backup cycle.

    • By default, geo-redundant backup data is retained for 7 days. You can set the retention period from 7 to 7,200 days.

    Geo-redundant storage region for backup files

    No default value

    You can set only one geo-redundant storage region. After the region is confirmed, it cannot be modified.

    Note

    If cross-border backup is involved, you must sign the cross-border data transfer compliance commitment. For more information, see Cross-border data compliance commitment.

    Backup retention policy upon instance release

    Retain all existing data backups and their corresponding log backups

    • When you release an instance, retain all existing data backups and their corresponding log backups. You can view and restore data from the recycle bin. (Instances are not moved to the recycle bin for balance refunds, 5-day unconditional refunds, releases of expired subscription instances, or releases of pay-as-you-go instances with overdue payments.)

      Note

      Retaining backup files when an instance is released incurs fees. For more information about billing, see Backup and restoration billing.

    • Do not retain backups (cannot be restored after release).

    p374160.png

  6. Click OK to complete the configuration.

Relationship between backup cycle and data backup retention period

Terms

  • The backup cycle is the interval at which full data backups are performed. It can be once a week, once a day, or a custom schedule, such as every Monday, Wednesday, and Friday. The backup cycle determines the frequency of backup set generation and affects the recovery granularity.

  • The data backup retention period determines the lifecycle of your backups and is required for point-in-time recovery (PITR). Expired backups are automatically deleted.

Mechanism

  • The backup cycle and the data backup retention period work together to determine the number of data backup sets that are retained and the actual retention period for log backups.

  • The system links data backups with log backups to ensure that PITR is possible for the entire configured retention period.

  • Data restoration requires the most recent data backup taken before the recovery point and all subsequent log backups. To ensure that data can be restored to any point within the specified retention period, the system may retain backups for longer than the period you set.

Example configurations

Example 1: Back up once a week

Backup cycle

Data backup retention period / Days for point-in-time recovery

Maximum number of data backup sets retained

Estimated actual retention period for log backups

Once a week

2 days

2

[2, 10] days

Once a week

7 days

3

[8, 15] days

Example 2: Back up once a day

Backup cycle

Data backup retention period / Days for point-in-time recovery

Maximum number of data backup sets retained

Estimated actual retention period for log backups

Once a day

2 days

3

[2, 4] days

Once a day

7 days

8

[8, 9] days

Example 3: Back up once every Monday, Wednesday, and Friday

Backup cycle

Data backup retention period / Days for point-in-time recovery

Maximum number of data backup sets retained

Estimated actual retention period for log backups

Once every Monday, Wednesday, and Friday

2 days

3

[3, 5] days

Once every Monday, Wednesday, and Friday

7 days

4

[8, 10] days

Cross-border data compliance commitment

If you configure a geo-redundant backup that involves cross-border data transfer, you must agree to the cross-border data compliance commitment. The commitment is as follows:

The region you select or the deployment region of the product may involve cross-border data transfer. By agreeing to and confirming this commitment, you acknowledge that you have full rights to manage this business data and are solely responsible for the data transfer. You must ensure that your data transfer complies with all applicable laws. This includes providing adequate data security protection technologies and policies, and fulfilling legal obligations such as obtaining explicit consent from individuals and completing data export security assessments and declarations. You also promise that your business data does not contain any content that is restricted or prohibited from being transferred or disclosed by any applicable laws. If you fail to comply with these statements and warranties, you will bear all corresponding legal consequences and be liable for any losses incurred by Alibaba Cloud, OceanBase, or their affiliated companies.