IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  IVIG backup

    Posted Thu March 27, 2025 12:23 PM
    I was wondering if there is a recommendation, or best practice for backing up IVIG data when deployed in a container.
    I found the backup recommendation for PostgreSQL in the High-Availability support documentation.
    I assume the LDAP backup follows the "ISDS" backup for containers.
    Additionally, I assume it is also necessary to back up the installation kit folder and the master key.
     
    Thank you for any inputs.
     
    Ref:
    https://www.ibm.com/docs/en/sig-and-i/11.x?topic=configuring-utilities
    https://www.ibm.com/docs/en/sig-and-i/11.x?topic=configuring-high-availability-support


    ------------------------------
    Rudy Santos
    ------------------------------


  • 2.  RE: IVIG backup

    Posted Fri March 28, 2025 04:08 AM

    Hi Rudy

    I would actually try to turn around the question somewhat - there is a lot of old school thinking about backup/restore and HA that has changed over the years and really is more of nuisance and creates more problems that is solves....

    First - what is the purpose of the procedure ? There is no procedure that solves all problems in a good way - there is a lot of difference whether you need to restore a complete environment in case your datacenter went down - or whether you need to recover from a stupid administrator error that wiped out half of your policies - and then everything in between...

    When I propose backup/restore strategies I separate them into these buckets : 

    • Database online backup of both the database and the underlying ldap database - this is for data point in time restore
    • Ldap data (ldif export) on at least daily basis - this is for supporting recovery of data in case of bad administration - and the most often used and important IMHO
    • Filesystem online backup - for point in time restore down to individual level - should also cover deployment filesystem (starter kit etc.)
    • Virtualization Infrastructure based backup - in the modern world this is the true HADR solution and should be the primary option. I strongly belive that all HA support should be at this level - the only reason to have additional pods for database/ldap should be scalabiltity/performance - not failover - move that to the infrastructure - that can handle it much simpler and using common methodologies that are not IVIG specific... 

    Does this make sense ? 



    ------------------------------
    Franz Wolfhagen
    WW IAM Solution Architect - Certified Consulting IT Specialist
    IBM Expert Labs
    ------------------------------



  • 3.  RE: IVIG backup

    Posted Fri March 28, 2025 04:11 AM

    And just to add the obvious which is mostly always disregarded - you do not have a backup/restore/failover solution if you do not exercise it regularly....

    My recommendation - depending on size/complexity/effort/risk is 3-6 month as maximum between exercising your HADR solutions... 



    ------------------------------
    Franz Wolfhagen
    WW IAM Solution Architect - Certified Consulting IT Specialist
    IBM Expert Labs
    ------------------------------



  • 4.  RE: IVIG backup

    Posted Fri March 28, 2025 04:42 AM
    Hi Franz,
     
    Thank you very much for your advice and for sharing your experience.
    Your observations are very useful for the scenario I am working on, which requires DR in addition to high availability.


    ------------------------------
    Rudy Santos
    ------------------------------



  • 5.  RE: IVIG backup

    Posted Mon March 31, 2025 06:13 AM

    I have received some feedback from one of my colleagues...

    ISVD (ldap server) with PostgreSQL does not support online support like the Db2 Based ISVD does - it can do a full backup online - but not "with rollforward/point in time recovery" which is what would be the best option.

    From a kubernetes perspective I have learned that real-time incremental backup like what is known from e.g. VMWare may be done based on Container Storage Interface (CSI) depending on the persistent storage a solution implements - but I am absolutely not an expert in that....

    HTH  



    ------------------------------
    Franz Wolfhagen
    WW IAM Solution Architect - Certified Consulting IT Specialist
    IBM Expert Labs
    ------------------------------