Transcript
As always, the latest release of the Service Provider Console is packed with some amazing features. However, for this video, we're going to focus on what is probably the biggest feature of this release, and that is the Vault plugin. We now have an integration with Veeam Data Cloud Vault directly inside of the Service Provider Console. If you're not familiar, Veeam Data Cloud Vault is Veeam's immutable out-of-the-box cloud storage, and previously, the process of creating and deploying those vaults, then assigning those vaults to tenant Veeam servers was a manual process. There was a lot of jumping back and forth between screens and servers. The plugin seeks to eliminate the confusion and the manual processes and give you end-to-end data protection. So before we get started, let's go over a few things. There still is one step that you have to do outside of the Service Provider Console, and that is create the customer and assign them a Veeam Data Cloud subscription in Pulse. Now, it's important to consider how you create these subscriptions and assign them to your tenants. There's really two ways that you can go about this. The first is the traditional way of you create a customer or you choose an existing customer in Pulse, and you assign a vault subscription to that customer individually, and you rinse and repeat for every customer. This is a good use case for large customers or if your preference is to see the usage report for all of your SaaS workloads and have a breakdown of each tenant in terms of points and usage. The second option is for a bulk creation. This is a little bit of a quicker process, but it's got some things to consider as well. So inside of your Pulse account, Veeam has created a customer entry for you as the service provider. This allows you to treat yourself as a customer for license purposes. This could be for your own internal licenses and the option of assigning the same subscription to multiple customers. If you do this option, you'll still have each tenant in Veeam Data Cloud with their own vault. You'll still see usage per tenant breakdown. You can assign different vaults to different Veeam servers. The only thing is in your monthly usage report for SaaS, you'll see a single line item for your company for all of the points that are consumed. However, doing it this way has some benefits in the vault plugin because rather than creating or assigning a tenant to a subscription one at a time, you'll be able to select 100 customers, 200 customers, whatever you need, and create vaults in mass for all of those customers by assigning them to a single subscription. That's really up to you and how you want to do that. The next thing is that this update, version 9.2 of the plugin, only supports Veeam Data Cloud Vault for Azure. There is two cloud options. That's Azure and AWS. The AWS vault integration for the plugin is not there yet. Hopefully, it will be in the future. The tenant Veeam server supports a lot of this new functionality in terms of authorizing the vaults and some of the steps we're going to get into. Not only do you need to be on console 9.2, you also have to make sure that your tenant Veeam servers are on at least version 13.0.1.2. Lastly, my.veeam is no longer used for authorizing the Veeam servers. This is really a big step. This functionality comes in the latest version of the Veeam server, the VBR server. The console just takes advantage of this. In previous versions, when you create your vault, you go to the customer Veeam server, you add the vault storage, and then you authorize the Veeam server so that it has permission to see your vaults. This is a security measure. You would have to use your my.veeam credentials. You would have to be a certain role of license administrator. Also, the Veeam backup server support ID had to match the vault support ID. There was a lot of scenarios that were causing confusion. You'd also have to do this on every Veeam server. It was, like I said, a manual process. We've removed that. Now all the authorization is done in Veeam Data Cloud, and you just have to be the vault admin. You can assign that to people in your organization very quickly. As I mentioned, the theme of this video is end-to-end data protection. Outside of the Pulse subscription, everything is done from the console. I can create new Veeam Data Cloud tenants, or I can map existing tenants to my service provider console companies, and I can specify the initial vault creation. Once I've got those customers created, I can create additional vaults or buckets. I can assign those vaults to the customer Veeam servers, configure read-write access and soft and hard quotas on the amount of storage used. I can remove those vaults, and finally, I can create the backup repository. You have your vault, and then you create a folder, which is the actual repository that Veeam interacts with and sends the Veeam backup files to. This is also where you'll specify your immutability. A little outside the scope of this feature in this video, but just to stay on this end-to-end data protection theme, you could also use the latest version of console for the WebUI proxy. This allows you to create basic backup jobs for your customer Veeam servers without leaving the console. Again, that end-to-end data protection, all from the console, is really what we're focusing on here. Now that we've got this out of the way, let's jump into the lab, and we're going to walk you through a demo from start to finish. Here we are in the lab, and the first thing we're going to do is click on configuration on the top right. Click on catalog on the left under plug-in library, and we're going to search for the Veeam Vault plug-in here. Click on that on the top right, and this is going to take us to a place where we can get a token. We're going to copy and paste that token in to cloud.veeam.com to register our service provider console. Here we have the code. We'll copy that to clipboard and simply click the link. This will take us to cloud.veeam.com. If your credentials are not cached, you may have to sign in to cloud.veeam.com. If you're a member of more than one organization, make sure that you choose the service provider level of the organization, and we'll simply paste the registration token in and click register. It'll take you back, and just click confirm. This should take less than a minute to complete, and we'll get a green check and know that we are successfully connected. Now that we are connected, we're going to start creating some new tenants in Veeam Data Cloud. Of course, if you have some existing tenants that you've already created, you can map those to companies and service provider console. You can create new vaults. You can unassign and reassign, but we're going to start from scratch with all new. Let's click Veeam Data Cloud, and I'm going to select a new tenant here. I can select one or multiple companies, because if you remember from earlier, we talked about this idea of single deployment and bulk deployment, and let me show you a little bit of both. Let's say this Axiom Robotics is a very large customer, and for whatever reason, I want them to have their own subscription. I want the names to be customized. I want to make sure that when I look at my monthly usage in Pulse, I see this customer clearly listed with their total number of points. I'm just going to do a single vault deployment, a single tenant deployment, so I'll select Axiom Robotics, and again, that's my service provider console company. Click Next, and the tenant name, if I want, I can change this to something different. By default, it's just going to be the same name as the service provider console company. I will select a subscription, and you can see that I've got my subscriptions under my service provider, and I've got client subscriptions for these individual tenants, so I would select Axiom Robotics, and then I would continue on and create a storage vault, but what I want to do is I want to pause here, and I want to go back. Now I'm going to select all three of these companies, and what you'll notice is when I click Next here, I've got some additional information, and it basically says that, hey, if you're going to create bulk tenants all at once, the name of the tenant is just going to be default to whatever the service provider console company name is, right? So this is faster, but it takes away a little bit of choice. If you can live with that, and you want to just get this going, like, you know, I could have like a hundred different companies create tenants in bulk, create vaults in bulk, all with a few clicks, right? You just have to remember that the way it looks in your licensing and some of the choices that are removed, like, you know, this subscription, I'm just going to, so for this subscription, I wouldn't select Axiom Robotics, because this is for, in this case, three different tenants, and since I can't establish a subscription for all of them at the same time, I will just simply pick a subscription that I've created for myself as the service provider, and just what edition of the product they need. Now, obviously the tenants will all have to have the same edition of the product, so for this one, let's just say we're going to choose Advanced Core Azure Edition, okay? Click Next, and once again, for bulk vault creation, all vaults will have default names based on the name of the tenant. So with the single creation, you can change the name of the buckets. For this, it's going to be named after the tenant, and the country and region will be the same for all of them as well. So you kind of start to see some of the pros and cons of doing a single deployment versus a bulk. For this one, let's keep going with the bulk deployment. So I want these to be in the United States, and I want them all to be in East US. I want to specify a quota. Now this is interesting. This storage quota is based on Veeam Data Cloud usage, where traditionally it's managed by the Veeam backup server. So if your customer, let's say they have a one terabyte limit, but that's set on the Veeam server, and if they're doing multiple backups a day very frequently, they could go past their quota before Veeam Data Cloud tells the Veeam server that they've reached that. This gives you a much better way to enforce the quota. You can also do a soft and hard quota, right? So the soft will just tell you, hey, you're reaching the limit, whereas a hard quota will make the vault become read-only if they go over that quota. Let's set this to the hard quota, and again, this is going to all the tenants under this bulk creation. We'll click Summary, and finally Finish. So that only took a few moments, all right? And if I look here, Axiom Robotics is right here, and you can see that we are currently creating that tenant inside of Veeam Data Cloud. So I've got my tenant successfully created. There is a tenant for all three of the companies that I did, but we're just going to stick with this Axiom Robotics for a moment, and when we created the tenant, it also created their initial storage vault. If I wanted to, I could create additional storage vaults, so let's go to Storage Vaults over here. We'll start by looking up Axiom, and we can see the initial storage vault that was created, and I've got a quota, all right? Now, let's say Axiom Robotics needs another storage vault, right? I created three tenants, but just this one, they need another vault for whatever reason. Another Veeam server, different settings, so let's choose them, and let's click New. Now, when I go to Subscription, because this is a new vault that I'm creating for this tenant, if I select Axiom Robotics, what do you think is going to happen? Well, nothing's coming up, right? And that's because this subscription was not used to create that initial tenant. Remember, we created a bulk deployment, so all those tenants are under my service provider subscription, which was the advanced core up here under my subscriptions. Now, I can see all of those companies that have been created under this subscription. I want to choose Axiom Robotics specifically. Now, here's the cool thing. When we did the bulk creation of the tenants, the initial vaults were all created with the same settings. If I select multiple companies here, it's going to do the same thing. However, I could select a single tenant, and now I can have a little more flexibility, right? So that first tenant gets created with all of the default settings that go to all of the users with the bulk, but now I'm going back into that tenant, creating a second vault, and I'm going to change the name of some things or put them in a different region or even country if I wanted to. So I could call this Axiom Robotics Vault DR, and maybe this one needs to be in West US 3, right? They're in a different data center, different location. They need a different quota, right? Let's actually not put a quota on here. Let's just click Next and Finish. So now Axiom Robots has two vaults, one that was created with everybody else in bulk, and the second one that I went back in and created as an individual vault. So you can see here we have some choice, some ways that we can do this, both single and bulk creation. Let's move on to creating a backup repository and assigning it to the VM server. So let's click on Backup Servers, and I'll show you the bulk and the single creation. Now before I do that, I want to register a vault to my VM server. So let's select this one that's not registered yet and click Vault Management, and we're going to assign a vault. So this is giving Veeam Data Cloud permission so that my VM server and the vault can talk to each other, right? So we'll click Assign Vault, and we can see the one here for the subscription for this specific company. So we're going to click that, we're going to click Assign. Now this is doing a couple things. This is registering the Veeam server so that it has permission to see my Veeam Data Cloud vaults, and then it is also assigning the vault. So it's registering and assigning a vault. Now a quick note here, if I want to, I can unassign this vault, however, it will not unregister the Veeam backup server from Veeam Data Cloud. So it'll still show as registered, but you can choose to unassign the vault if you wish. So I'm going to leave this as is, and we're going to go back, and I'm going to start by selecting multiple backup servers and click New Repository. You see here that I've only got a few options. I can review the servers, I can select the immutability period for these repositories, and click Next and Finish. If I go back and I select only one Veeam server, click New Repository, I now have the Simple and Advanced. If I stick with Simple, it's the same thing. Choose the server or review the server, choose your immutability, Next and Finish. However, if I go to the Advanced tab, now I've got some options. I can change the name of the repository, how it appears in Backup and Replication. I can make a description here. For the storage vault, I'll choose one of the vaults that I assigned to this Veeam server. I've only got one here. I can select a folder. So with the Simple mode, Veeam will create this folder for you. Here you can configure the folder, we'll create a name for the folder. I can choose this folder, I can create a new folder. Let's do that. We'll just call this Test. That's going to actually create the folder space inside of my repository. This may take just 30 seconds to a minute. For that to finish, we will select the folder that we want the backups to go to. Let's click Next. Here we're just selecting the immutability period. How long do you want your backups to be unable to be deleted? It's great for ransomware protection. We'll just say for the entire duration of the retention. It's pretty common. Alright, we'll just review and then we'll click Finish. And that should just take a minute. So we're good now. We've got our tenants created. We've got our vaults created. We created an additional vault for an individual customer. We then walked through creating the repository and the backup servers. We can do the simple, we can do the advanced. I'm not going to get into it in this video, but again, just kind of ending on that theme of end-to-end data protection. If I wanted to, I could then go to the backup copy job area and I could create a new backup job on one of these machines. And so that would give me, again, that ability for end-to-end data protection. That's it for this video. Hope you enjoy it. Hope you find that console plugin useful and we'll see you next time.