Transcript
Hello and welcome to episode 243, I almost forgot the number, of the Veeam Community Recap. That's crazy, almost 250. I am Rick Vanover, the Rickitron. In normal circumstances this week, even though I might have wore the same shirt combination last week, I just thought about that. Don't judge if that's the case. But I'm back with my partner in crime, Maddalena Cristil. Maddy, how you doing? Hello, Rick. Hello, community. It's great to be back in normal circumstances. I'm for the rescue and I wear a t-shirt with hackathon that we are going to talk about a bit later. So yeah, all good to talk Veeam community. We have so many great stuff. It was difficult to pick one, two, three. I was like, should we break the rule? And then I was like, maybe not. And last week we're thinking, oh, it's getting to be the quiet time of the year. We're not going to have stuff. Well, the VUG events are quieting, but we have different special department news to bring. So the community never disappoints. You ready to jump in? Yeah, let's do it. All right. First up is a new name, K Ciolek. He is a third post or such. He's jumping in with first blog steps to integrate Data Domain 640 with VBR 13. I can tell you right off the bat for a first blog, this is pretty good. Yes, absolutely. So welcome to the hub. Actually, it's easier than you think. His name is Ken. Oh, okay. Ken, there you go. So first time mentioning his name as well in the recap. So that's great to have you. And of course, I was looking at a little bit in the profile to see the name. And also, I observed that Ken is the object first day. So good stuff. And yeah, this is a really good post, actually. Ken walks us through how to integrate Dell Power Protect Data Domain 6410 with Beam Data Platform v13. And this is just something that many users asked about. But you know, it's not that often documented. So that's really good stuff. And of course, he starts with the essentials on the data domain side, making sure the DD boost license is enabled, setting up VM trees, verifying network connectivity, and then he's moving further into the Beam Backup Replication Console. And from there, he guides readers through adding the data domain as a DDAP based backup repository. And he says, select the right storage unit, then tune to advanced settings. And then last but not least, server configuration. And that's very straightforward. It's just step by step tutorial and is very useful for anyone working with the DDAP appliances. And I am glad to see that he plans a part two in there. Because he's going to show us, I guess how he builds and maps jobs on top of this configuration. And this is going to be valuable for the community as well. So good job. Yeah, thank you, Ken. It's been a long time since I personally have configured a data domain with Veeam. We had one back in the day. And when I switched labs, we kind of separated, I let support have this lab, and I built a different lab. And the data domain stayed there just for support reasons, because I have a couple other storages up in the mix. But this is really cool. And yeah, deduplication appliances, they are very prevalent in the market. I love the click through. And as you say, right here, part two is on the way. We look forward to that, Ken. Thank you for sharing. Yeah. And I want to mention, Rick, I can hear voices from the office. You can tell it's December and people are happy, celebrating or something. No, it's just there's a meeting out there. And I never shut my door. Sorry about the background noise. I'll put mute on. I paid big, fancy money for this nice microphone. Actually, I'll just show everybody here real quick. We can't even get it on camera. But basically, it's an articulated microphone, supposed to knock out the background noise, but apparently not. But we'll figure that out. Okay. Next up, really cool post from Michael Melter on Brickstorm. What caught your eye with that one, Maddy? I think this is a super interesting topic. You know, we always want to know when there's a new Discover malware. And in this case, Michael Melter explains how threat intelligence agencies, including CISA, NSA, the Canadian Center for Cybersecurity, they jointly warned about this new Discover extremely sophisticated backdoor called Brickstorm. And this one targets VMware Center and XC environments. And Mandiant provided a deep technical analysis earlier this year. And Michael says Brickstorm isn't just another piece of malware. It's built for long term persistence, credential theft, snapshot exfiltration, rug VMS, stealthy command and control, and even lateral movement across Windows and Linux systems. So that's dangerous. And it hides in the core VMware directories, and it uses an encrypted DNS over HTTPS and web sockets to stay undetected. So I think this is good that Michael shared this with us. You know, I was not aware of it. So that's really good information. And Michael also highlights why this is relevant to the backup community and the backup world in general. Because if Brickstorm compromises vCenter, it can basically contaminate your backups or just render them unreliable. So he says also, fortunately, Veeam can help because v13 now supports Yara scanning, as we know, of Linux backups using Linux mount server. So Michael also shows us how to combine the Yara rules from CISO, Mandiant, and then uploading them to Veeam, scanning vCenter, restore points too. And then with that, you can detect traces of the backdoor. So I think this is good that Michael shared that with us. Fantastic job. It's good that the community is aware of it. Thank you, Michael. I think you are on mute now. Yes, we're professionals here. I did hit mute. Yes, this is absolutely fantastic. Thank you, Michael. And this works into so many different things. I love that there's a Yara rule that we can then put into Veeam backup and replication and execute a scan. This is really, really a good point. So for VMware environments, this is probably something that you should look into. And actually, it's just kind of nice to have a backup of your vCenter anyways. So thank you so much for sharing this, Michael. I'm actually going to pick this one up and share it on the team. I think this one's got to be our top pick, but we'll come back to that. Yeah, really good. Awesome. Thank you, Michael. All right. Next up is Marcel with preparing a smart one-time custom Veeam appliance ISO for vSphere with a variable injection. Holy buckets, what's going on here? I know, right? So he developed this super cool, very practical solution for anyone that is going to deploy Veeam's Linux-based appliances at scale. And since the Veeam software appliance doesn't include cloud in it, Marcel created a method to inject all the needed configuration variables, IP, DNS, hostname, NTP credentials, right at the install time by building one custom ISO, and then letting vSphere guest info or OVF properties feed Veeam-specific data into it. So then he explains how they extended the kickstart, pre and post sections to mimic cloud in it behavior. And it's really smart how they temporarily extracted Veeamware RPC tool from the open Veeam tools RPM, just long enough to pull OVF or guest info variable. So that's really smart. And then the script generates a temporary network config, stores the values like NTP in an environment file, and hands everything off to the post install phase. So that's really creative and hands-on engineering. And I always love to see this kind of stuff at the community. Thank you, Marcel, for doing that, you and your colleague, because I saw you did it together with your colleague. Pretty cool stuff. Yeah, this is pretty awesome in the sense of, you know, I'd put this in the advanced practitioner category. And it's just, you've got the starter scripts here to do it all. So, you know, Marcel's not from Germany, but he's writing content that would fit in Germany. So yeah, I love it. Love it. Awesome. Anyways, check this one out. Thank you so much, Marcel. And actually, it looks like a shout out to DoubleZedko here on the help out here. So because they worked in conjunction, you know, it's kind of tricky, because we don't have the mechanism on the platform to have a blog written by two people, right? But first sentence, Marcel's giving thanks to Zzoka. So maybe Zzoka, drop your own content. We'll be happy to feature that as well. Absolutely. Looking forward to it. All right, that concludes our featured content now we're going to switch over to the Vanguard blog spotlight. And actually, there's this guy named Jeff, maybe you've heard of him here on our community. And he has never been to his blog, I feel horrible. But he just Jeff of all things here. What is he talking about now? Yeah, right. We always, we always mentioned Jeff, from the community post, we never really mentioned his blog. So this is actually the first time we are mentioning him in the VBS. So that's great to have you and great to see what you put in your blog. And happy to to mention your name. And this is actually a really, really good, very personal kind of style blog. And quite straightforward. Jeff is looking at the rising trend of vibe coding, which is basically a new AI driven development style where creators describe what they want. And the AI generates the code without the user necessarily reviewing or understanding it. And it happens more than you think. And Jeff says this approach can be great for fast prototyping or brainstorming, which I definitely agree Jeff with, but it introduces huge security risks. Because AI generated code already has a high rate of vulnerabilities, which we all know, and when developers kind of skip the reviews, or you know, they just don't take that very seriously, those risks multiply. And I must I must say how I definitely agree on that, Jeff. And of course, Jeff here connects this directly to the backup security. With the threat actors increasingly targeting backups, most organizations are struggling to recover quickly. And the combination of a weak AI generated code and overlooked backup practices. It's just a very worrying picture, as Jeff says, that with the vibe coding becoming more common immutability becomes even more essential and true object log based immutability, end to end encryption, segmentation, adherence to best practices like three to one rule are now like foundational defenses organization need, if they plan to embrace AI driven development safely. And this is a very good article, I must say. And yes, AI is changing everything. But I like Jeff's approach that looks at the real impact on security, especially around backups, because that's what he talks about. And yes, it is a race, but speed without control, it's always or it can be a Yeah, I don't know what's your thought on that, Rick? Well, my thought is I was just mesmerized by this picture. It's just like, it's probably AI generated, but I'm like, it's just really cool. So I couldn't stop looking at that. So sorry. I'm a squirrel. Sometimes many knows that. No, I think Jeff, this is a great kind of balanced perspective, some some data points, some analyst assets, some security reports, this is really important to kind of just get the get the right vibe for, you know, your technology practice. And, you know, you have me at immutable, right? So that's a good place to start. So thanks, Jeff. Nice to feature you here on this and you got all kinds of stuff. You got looks like I've got all kinds of stuff. So going on on this website. So thank you, Jeff. All right. Next up special department trick play. Yes, I'm playing something. I'm being a little sneaky here. So basically, what we're looking at is our not who's new, not yet. What we're looking at is just the main community.me.com. Now we think we feature so many blogs and podcasts and stuff like that. But I want to draw your attention to this little drop down widget right here, the community widget. So let's go back full screen here. So if we go down here, I want to draw everyone's attention to the security blueprints section here. This is becoming the most amazing part of Veeam.com that a lot of people don't know about. So I want to make sure you know about it. So if you click on security blueprints, now we've called this guy named Joe before, Joe with the hat. He does a lot of content that we featured. But Joe also writes up these incredible architecture diagrams. So here's one. One data center with the Veeam software appliance backing up to a SAN attached volume with the hardened right? But what this is, and let me just go right into it. All of them have the summary, and then they have these PDFs. Where did the PDF go? Oh, it's being scanned. Security. All right. So all of them have these PDFs. Now, Maddy, he's done a lot of work on this site, I think. He did, exactly. And I feel like when you said, let's mention this in special department news, yeah, that's a great idea, because we haven't done it much this year, and we should definitely highlight all this great work that Joe and team are putting together. Thank you very much for contributing, and thank you very much for engaging with the community, Joe. Great job in here. Yeah, and they are, just to give you a sense, I'm going to walk us through this architecture document here. These are field validated from Joe and his colleagues. So basically, the architecture team, this is, when they go to implement something, this is what they'll start with. And the additional really cool part about it is, it's validated from our product management team, right? So it's not just some tricky sales play. It's literally a validated solution from our R&D team, field proven from Joe and his colleagues around the world as the architects. And the best part, there's no login required. I am logged in, but you can get it free on the internet as well. So let me walk you through this. So it always starts with like the summary. So like a main data center, and we got 5000 VMs, we've got some direct attached storage, and we're going to go to vault, right? So this is the overall kind of diagram of what this looks like. And he's using some of the good stuff like HA, using that, using enterprise manager, hardened repository, got some agents in the mix. So, you know, those of you who are practicing IT folks, this is going to sound really, really familiar. But then we get into a little bit more of a verbalized description of the environment. And then there's some requirements, constraints, and assumptions, and all of them have the same format. And this is super important, the one I want to draw your attention to is this, and that we should also at least get two to one data reduction. So and this is also a really good safeguard here, all these things really good. And then eight hour backup window, okay, so some assumptions, etc. Then you get into the sizing, this is like what we would need to deploy with the to make it work to the level expected. This is awesome. Very practitioner heavy field proven environments. And then you can get down a little bit more deep on the fiber channel, right, some some configuration. And then the last part here is just some more guidance on the configuration, right? These are the things that really, really will make the difference. So and this is just one, there's over 70 in here, right? And there's not just being backup and replication, there's a cast in product, there's the sales product, there's some Alliance type place, like, I think I remember I've seen some pure storage net app. Let's see here, object first is in their proxmox. So it's really awesome. So, Joe, Charles, all of you, I want to give a big thanks for this. This is actually more valuable than you know, but we wanted to make sure that the broader community knows about this resource. Totally. Awesome. All right, last up is kind of a special thing coming up. Actually, now, right now. Yeah, it's gonna start December 13. We said like, okay, it's gonna be quiet December, no more VUG events. But guess what? We're going to have to be in community hackathon. And yeah, you cannot register anymore for this. You cannot participate if you haven't subscribed. But I think I'm really looking forward to see the projects. Because both of us, Rick, we're going to judge and we're gonna have firsthand access to, you know, to the project. So really looking forward to see who's going to win this Veeam community hackathon. As you know, we, the ones that participated, the projects that participated in this year, we mentioned it in the Veeam 100 show. So we're going to do the same in 2026. So you're going to find out about it. But really good projects. I do know some people that are participating in this year, like Marcus, Lucas, Charlie from our community. And yeah, I just want to thank Maurice and Jonah, because this is a lot of work to put in to organize the Veeam community hackathon. Yeah. And you know, Jonah and Maurice, you know, have a lot going on. They've had a very good successful momentum here. Big thank you also to Yos and Tom, who have also stepped up with leadership roles and executive sponsor. Well, congratulations, Maddie and Sophia for your own it. Go for it. That's great. We are supporting as much as we can with this. So yeah, I guess that's what we are, executive sponsors. Executive sponsors. Represent. Love it. All right. Last up, speaking of Sophia, is the Who's New. We're back with Who's New this week, and we have plus 154 members to welcome. It looks like a Juan Carlos. Juan Carlos, yeah. With a 4A, A4. I wonder if 4A, isn't A4 a type of paper? I don't know, Juan Carlos. I don't know. And then Cadillac, I like to say Cadillac. That's cool. And Mimo. And 7A. I'm just going to call it 7A. So those are cool usernames. And then Alfred's pick is Storage Man. That's pretty cool. You know, I think that A is actually a shout for help. A! No? Yeah. I'll just call it 7A. Or is it 8? Hold on. I can't count. It's hard to count. So that's 4. So 8. 8A. 8A. 8Alpha. 7A sounds better than 8A. Yeah. So if it's 8Alpha, I don't know. Maybe I'm thinking too hard. I do that a lot. Let us know. Just let us know. Yeah. Let us know, A, what's the story of 8As. I think it's honestly something just like I want to be first in the alphabet. I think it's probably something like that. So we'll see. Yeah. All right, Maddy, thank you so much for curating the content here this week. As always, Rick. I think we have one more week coming, right? Can do next week. Can do. And then it gets a little weird and holiday-like. Yeah. I mean, that's Christmas. Yeah. New Year's. And we have a special, looking quite far ahead into February, we got a little special something up our sleeve. We'll just leave it at that. Yeah. That's going to be long until then. We're going to still do some recaps in January. So yeah. Awesome. All right, everyone. Thanks for watching. We will see you next week on 244. But until then, have a great weekend.