Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Veeam: Backup & Recovery for PGVector Databases on OpenShift

Veeam
06/16/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


with Veeam Kasten. This environment is an OpenShift cluster running container and VM workloads. For this demo, the key workload is a cloud-native Postgres cluster with the PG Vector extension enabled. PG Vector is commonly used by AI applications to store embeddings for Retrieval Augmented Generation, or RAG. The database is running as a highly available Postgres cluster in its own namespace. Kasten is also installed on the cluster and has already discovered the applications running across OpenShift. Now we'll protect the PG Vector workload. In the Kasten UI, I'll open the policy for the PG Vector demo and run it on demand. I'll also set an expiration date so this recovery point does not live forever and consume unnecessary storage. This policy is doing more than a basic snapshot. It is configured to protect the PG Vector namespace, create a backup, and export that backup off the cluster to object storage. That gives us a real recovery point outside the local OpenShift environment. The important part is application consistency. This policy uses a Kasten blueprint to run a pre- and post-action around the backup. In this case, the backup is taken from the secondary Postgres replica, not the primary. The pre-action pauses the replica, Kasten captures the data, and the post-action resumes it. That helps avoid impact to the production writer while still giving us a clean backup of the database. Now the backup has completed successfully. Before we simulate a failure, let's confirm the database has data. Here we can see document embeddings stored in PG Vector. Next we'll simulate a bad event. This could be an accidental deletion, a rogue administrator, or even an AI-driven workflow that changes or deletes the wrong data. I'll drop the embeddings table and confirm the data is gone. At this point, the RAG application would lose access to the context stored in the vector database. Now we'll recover with Kasten. I'll go to the restore points for the PG Vector demo and select the most recent recovery point. For this demo, I'll use the local restore point, but the exported copy could also be used if the cluster copy was unavailable. During restore, we use the same blueprint to run a before action that deletes the cluster resource first. This is important because the operator will otherwise try to recreate pods and persistent volumes while Kasten is restoring them. Removing the cluster resource, or CR, first allows Kasten to perform a clean recovery. Kasten restores the Kubernetes metadata and persistent volumes, then the Postgres cluster comes back online. Finally, we'll verify the result. The restore is completed successfully, the Postgres cluster is running again, and the PG Vector embeddings are back. This is how Veeam Kasten can protect and recover PG Vector databases running on OpenShift AI, including application-consistent backup, off-cluster export, and clean recovery for AI and RAG workloads.

TL;DR

  • Veeam Kasten provides application-aware backup for PGVector databases on OpenShift, using blueprints to orchestrate pre/post-actions that ensure consistency without impacting production workloads.
  • The solution backs up from secondary Postgres replicas rather than primary instances, pausing replication during snapshot capture to maintain data integrity for AI RAG applications.
  • Recovery includes automated handling of Kubernetes operator conflicts by removing cluster resources before restoration, enabling clean recovery of both metadata and persistent volumes for AI workloads.

Summary

This technical demonstration shows how Veeam Kasten protects PGVector databases running on Red Hat OpenShift for AI Retrieval Augmented Generation (RAG) workloads. The demo walks through creating an application-consistent backup of a cloud-native Postgres cluster with the PGVector extension enabled, which stores embeddings critical to AI applications. Kasten's approach uses blueprints to orchestrate pre- and post-backup actions that pause the secondary Postgres replica during backup to avoid production impact while ensuring data consistency. The demonstration includes simulating a data loss event by dropping the embeddings table, then performing a complete recovery using Kasten's restore capabilities. The solution exports backups off-cluster to object storage for true disaster recovery protection, and handles the complexity of Kubernetes operator-managed workloads by removing cluster resources before restoration to prevent conflicts during recovery.

Chapters

0:00 - Environment Overview
0:42 - Creating Application-Consistent Backup
1:35 - Verifying Data and Simulating Failure
2:04 - Restoring PGVector Database

Key Quotes

1:10 "The important part is application consistency."
1:18 "In this case, the backup is taken from the secondary Postgres replica, not the primary."
1:29 "That helps avoid impact to the production writer while still giving us a clean backup of the database."

FAQ

Why does Kasten back up from the secondary Postgres replica instead of the primary?

Backing up from the secondary replica allows Kasten to pause replication and capture a consistent snapshot without impacting the primary database that is actively serving production AI application writes. This approach maintains application performance while ensuring backup consistency.

What happens if the local OpenShift cluster is completely unavailable during a disaster?

Kasten exports backups off-cluster to object storage, creating a true recovery point outside the local OpenShift environment. This exported copy can be used for disaster recovery even if the entire cluster is lost, providing protection beyond local snapshots.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Cloud Security
  • AI & Machine Learning
  • Demo
  • Technical Deep Dive
  • Kubernetes backup
  • AI workload protection
  • PGVector database
  • Red Hat OpenShift
  • RAG applications
  • Application-consistent backup
  • Disaster recovery
  • Vector database protection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Veeam: Backup & Recovery for PGVector Databases on OpenShift

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    14

                    Crafting a Championship-Caliber Security Team for Lasting Defense

                    07/14/202601:00 PM ET
                    • Jul
                      14

                      Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                      07/14/202602:00 PM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/14/2026
                          01:00 PM
                          07/14/2026
                          Crafting a Championship-Caliber Security Team for Lasting Defense
                          https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-caliber-security-team-for-lasting-defense/
                        • 07/14/2026
                          02:00 PM
                          07/14/2026
                          Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                          https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
                        • 07/21/2026
                          04:00 AM
                          07/21/2026
                          Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                          https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                        • 07/22/2026
                          06:30 AM
                          07/22/2026
                          Insights and Strategies in Data Protection and Privacy Management
                          https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
                        • 07/22/2026
                          01:00 PM
                          07/22/2026
                          Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                          https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights from Cyera's Expertise
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version