A Linux repository that locks backups for a defined time so nobody, root included, can delete, change or move them, which sets it apart from governance mode.
Also called Linux hardened repository.
Read more: Veeam Help Center
In the Ultra Transcenders books
Each book explains hardened repository in context, with comparison tables and the common traps.
Terms in this definition
- LAMP
Short for Linux, Apache, MySQL and PHP (Perl and Python also fill the P): a widely used open-source stack for web applications whose database is frequently Azure Database for MySQL.
- Repository
A group of images or artefacts in a container registry that share one name and differ by tag. Names can include slash-separated namespaces, but every repository is handled separately.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Governance
Keeping cloud deployments in line with an organisation's rules on technology, security and compliance, helped by Azure Policy, tags and resource locks.
Related terms
- Application Backup Repository
Added in 13.1 and built on the Veeam Hardened Repository, it exposes an NFS share to applications, takes immutable snapshots of it, treats those as restore points and applies retention. Backup copy jobs can convert the contents into a normal chain.
- governance-mode immutability
Added in 13.1, this locks files on a Linux repository using governance retention. Root users on that machine can still remove or overwrite them, which a hardened repository prevents.
- single-use credentials
Used just once, to install the Veeam Data Mover when adding a Linux server such as a hardened repository, and not saved afterwards. An attacker who takes over the backup server therefore has nothing to reuse.
- tape server
Moves data from its source to a tape device and back, as a dedicated part of the backup infrastructure. Because root access is required, neither Veeam appliance nor a hardened repository can host it.
- VAB
The file in which a Veeam Plug-in stores compressed database backup data, whether full, incremental or log. When kept on a hardened repository it turns immutable a day after it is written.
- VACM
Written once for each Veeam Plug-in backup job to describe that job. Whereas VAB and VASM files can become immutable on a hardened repository, this metadata file never does.