<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.open-e.com/index.php?action=history&amp;feed=atom&amp;title=Extension%3AVeeam_Hardened_Repository_rev_04</id>
	<title>Extension:Veeam Hardened Repository rev 04 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.open-e.com/index.php?action=history&amp;feed=atom&amp;title=Extension%3AVeeam_Hardened_Repository_rev_04"/>
	<link rel="alternate" type="text/html" href="https://wiki.open-e.com/default/wiki/index.php?title=Extension:Veeam_Hardened_Repository_rev_04&amp;action=history"/>
	<updated>2026-09-21T21:42:44Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.6</generator>
	<entry>
		<id>https://wiki.open-e.com/default/wiki/index.php?title=Extension:Veeam_Hardened_Repository_rev_04&amp;diff=12435&amp;oldid=prev</id>
		<title>Ai-B: Log dataset selection: clarify that the dataset stays in the pool and only its mount point is moved to /var/lib/veeam (veeam-ds-logs.service uses mount -o move). Previous wording implied the dataset itself was relocated.</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-e.com/default/wiki/index.php?title=Extension:Veeam_Hardened_Repository_rev_04&amp;diff=12435&amp;oldid=prev"/>
		<updated>2026-07-21T08:48:14Z</updated>

		<summary type="html">&lt;p&gt;Log dataset selection: clarify that the dataset stays in the pool and only its mount point is moved to /var/lib/veeam (veeam-ds-logs.service uses mount -o move). Previous wording implied the dataset itself was relocated.&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 08:48, 21 July 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l53&quot;&gt;Line 53:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 53:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Log dataset selection ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Log dataset selection ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The script prompts you to select a ZFS pool where the &#039;&#039;&#039;_veeam_logs&#039;&#039;&#039; dataset will be created. This dataset &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;is mounted at &lt;/del&gt;&amp;lt;code&amp;gt;/var/lib/veeam&amp;lt;/code&amp;gt; &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;inside the container and stores Veeam service logs. The container automatically relocates this dataset out of the pool filesystem &lt;/del&gt;and unmounts &amp;lt;code&amp;gt;/Pools&amp;lt;/code&amp;gt; &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;during setup — &lt;/del&gt;no user action is required &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;for this&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The script prompts you to select a ZFS pool where the &#039;&#039;&#039;_veeam_logs&#039;&#039;&#039; dataset will be created. This dataset &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;stores Veeam service logs. The dataset itself remains in the selected pool — during setup the container moves its &#039;&#039;&#039;mount point&#039;&#039;&#039; to &lt;/ins&gt;&amp;lt;code&amp;gt;/var/lib/veeam&amp;lt;/code&amp;gt; and unmounts &amp;lt;code&amp;gt;/Pools&amp;lt;/code&amp;gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. This is automatic; &lt;/ins&gt;no user action is required.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; If a &amp;#039;&amp;#039;&amp;#039;_veeam_logs&amp;#039;&amp;#039;&amp;#039; dataset already exists in the selected pool, back up its contents before proceeding.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; If a &amp;#039;&amp;#039;&amp;#039;_veeam_logs&amp;#039;&amp;#039;&amp;#039; dataset already exists in the selected pool, back up its contents before proceeding.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ai-B</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-e.com/default/wiki/index.php?title=Extension:Veeam_Hardened_Repository_rev_04&amp;diff=12434&amp;oldid=prev</id>
		<title>Ai-B: Create rev 04 extension article: setup script self-elevates to root, package-install fallback removed; adds no-internet-required note and console login instructions. Based on the rev 03 draft (never published).</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-e.com/default/wiki/index.php?title=Extension:Veeam_Hardened_Repository_rev_04&amp;diff=12434&amp;oldid=prev"/>
		<updated>2026-07-21T08:25:39Z</updated>

		<summary type="html">&lt;p&gt;Create rev 04 extension article: setup script self-elevates to root, package-install fallback removed; adds no-internet-required note and console login instructions. Based on the rev 03 draft (never published).&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;__NOTOC__&lt;br /&gt;
Veeam Hardened Repository provides a secure, immutable backup repository for Veeam Backup &amp;amp;amp; Replication. It runs as an isolated LXC container on the storage server, using ZFS-backed ZVOLs formatted with XFS as the backup storage target.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; Veeam Hardened Repository is delivered as an optional Small Update (the &amp;#039;&amp;#039;&amp;#039;xc-veeam-hdrep&amp;#039;&amp;#039;&amp;#039; module). This article describes revision &amp;#039;&amp;#039;&amp;#039;04&amp;#039;&amp;#039;&amp;#039;. If your system was updated to a newer revision, refer to the matching &amp;#039;&amp;#039;Extension:Veeam_Hardened_Repository_rev_NN&amp;#039;&amp;#039; article.&lt;br /&gt;
&lt;br /&gt;
== How the hardening works ==&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;hardened&amp;quot; property is the result of two complementary mechanisms working together:&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Immutable backups&amp;#039;&amp;#039;&amp;#039; — Veeam writes backups to the XFS repository with the &amp;#039;&amp;#039;&amp;#039;Make recent backups immutable for N days&amp;#039;&amp;#039;&amp;#039; setting enabled. While immutability is in effect, backup files cannot be modified or deleted from outside Veeam, protecting them from ransomware and accidental removal. The XFS filesystem is formatted with reflink support, which also enables Veeam&amp;#039;s fast-clone (synthetic backup) optimisation.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Minimal attack surface&amp;#039;&amp;#039;&amp;#039; — the dedicated &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; account is granted elevated privileges only during the initial Veeam onboarding handshake, then sudo is removed immediately afterwards. SSH access on port &amp;#039;&amp;#039;&amp;#039;22522&amp;#039;&amp;#039;&amp;#039; is disabled after onboarding completes, closing the inbound path entirely.&lt;br /&gt;
&lt;br /&gt;
The role of the &amp;#039;&amp;#039;&amp;#039;xc-veeam-hdrep&amp;#039;&amp;#039;&amp;#039; module is to provision the XFS-on-ZVOL repository and orchestrate this temporary-privilege/SSH handshake. Veeam enforces immutability; the module enforces privilege minimisation.&lt;br /&gt;
&lt;br /&gt;
== Prerequisites ==&lt;br /&gt;
&lt;br /&gt;
Before running the setup, ensure the following are in place:&lt;br /&gt;
&lt;br /&gt;
*A ZFS storage pool with sufficient free space.&lt;br /&gt;
*One or more ZVOLs with &amp;#039;&amp;#039;&amp;#039;veeam&amp;#039;&amp;#039;&amp;#039; in the name (the setup script discovers ZVOLs by this keyword).&lt;br /&gt;
*Network access to the storage server from the Veeam Backup &amp;amp;amp; Replication console.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; Setup does not require internet access. All software the repository needs is already included in the container image, and the Veeam Data Mover / transport components used during onboarding are delivered by the Veeam Backup &amp;amp;amp; Replication server itself over the SSH connection on port &amp;#039;&amp;#039;&amp;#039;22522&amp;#039;&amp;#039;&amp;#039;. An isolated or air-gapped storage server deployment is fully supported.&lt;br /&gt;
&lt;br /&gt;
== Accessing the container console ==&lt;br /&gt;
&lt;br /&gt;
The repository container exposes a web-based console at:&lt;br /&gt;
&lt;br /&gt;
  https://&amp;amp;lt;server-ip&amp;amp;gt;:4200/veeam-hdrep&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Login:&amp;#039;&amp;#039;&amp;#039; enter &amp;#039;&amp;#039;&amp;#039;admin&amp;#039;&amp;#039;&amp;#039; as the username and your storage server administrator password.&lt;br /&gt;
&lt;br /&gt;
Accept the self-signed certificate warning if prompted. The console gives direct shell access to the container for running the initial setup and any subsequent maintenance commands.&lt;br /&gt;
&lt;br /&gt;
== Initial setup ==&lt;br /&gt;
&lt;br /&gt;
Setup is performed once, using the interactive &amp;#039;&amp;#039;&amp;#039;make_veeam_repo&amp;#039;&amp;#039;&amp;#039; script included in the container. All steps below are run inside the container console.&lt;br /&gt;
&lt;br /&gt;
=== Running the setup script ===&lt;br /&gt;
&lt;br /&gt;
#Connect to the container console at &amp;lt;code&amp;gt;https://&amp;amp;lt;server-ip&amp;amp;gt;:4200/veeam-hdrep&amp;lt;/code&amp;gt;.&lt;br /&gt;
#Navigate to the tools directory and run the setup script:&lt;br /&gt;
  cd /tools&lt;br /&gt;
  sudo ./make_veeam_repo&lt;br /&gt;
#Follow the interactive prompts described in the sections below.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The script needs root privileges to modify system files (SSH configuration, fstab, cron) and automatically elevates itself if it is not already running as root. &amp;lt;code&amp;gt;sudo ./make_veeam_repo&amp;lt;/code&amp;gt;, as shown above, remains the recommended way to start it.&lt;br /&gt;
&lt;br /&gt;
=== User account creation ===&lt;br /&gt;
&lt;br /&gt;
The script creates the dedicated &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; account (UID 1000) used exclusively for Veeam access. If the account does not yet exist, you will be prompted to set a password for it.&lt;br /&gt;
&lt;br /&gt;
=== Log dataset selection ===&lt;br /&gt;
&lt;br /&gt;
The script prompts you to select a ZFS pool where the &amp;#039;&amp;#039;&amp;#039;_veeam_logs&amp;#039;&amp;#039;&amp;#039; dataset will be created. This dataset is mounted at &amp;lt;code&amp;gt;/var/lib/veeam&amp;lt;/code&amp;gt; inside the container and stores Veeam service logs. The container automatically relocates this dataset out of the pool filesystem and unmounts &amp;lt;code&amp;gt;/Pools&amp;lt;/code&amp;gt; during setup — no user action is required for this.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; If a &amp;#039;&amp;#039;&amp;#039;_veeam_logs&amp;#039;&amp;#039;&amp;#039; dataset already exists in the selected pool, back up its contents before proceeding.&lt;br /&gt;
&lt;br /&gt;
=== ZVOL selection and formatting ===&lt;br /&gt;
&lt;br /&gt;
The script lists all ZVOLs whose path contains &amp;#039;&amp;#039;&amp;#039;veeam&amp;#039;&amp;#039;&amp;#039;. Enter the numbers of the ZVOLs you want to use as backup repositories, separated by spaces.&lt;br /&gt;
&lt;br /&gt;
For each selected ZVOL:&lt;br /&gt;
&lt;br /&gt;
*If the ZVOL is already XFS-formatted, it is used as-is.&lt;br /&gt;
*If the ZVOL is &amp;#039;&amp;#039;&amp;#039;not&amp;#039;&amp;#039;&amp;#039; XFS-formatted, the script will warn that &amp;#039;&amp;#039;&amp;#039;all data on the ZVOL will be erased&amp;#039;&amp;#039;&amp;#039;. Type &amp;lt;code&amp;gt;format&amp;lt;/code&amp;gt; to confirm, or anything else to cancel.&lt;br /&gt;
&lt;br /&gt;
Formatting uses optimised XFS parameters for backup workloads:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Parameter !! Value !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| Block size || 4096 bytes || Standard block size&lt;br /&gt;
|-&lt;br /&gt;
| Reflink || enabled || Efficient data deduplication at the XFS level&lt;br /&gt;
|-&lt;br /&gt;
| CRC || enabled || Metadata integrity checksums&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Mount point configuration ===&lt;br /&gt;
&lt;br /&gt;
For each formatted ZVOL, the script:&lt;br /&gt;
&lt;br /&gt;
*Creates a mount point at &amp;lt;code&amp;gt;/mnt/&amp;amp;lt;zvol_name&amp;amp;gt;&amp;lt;/code&amp;gt;.&lt;br /&gt;
*Adds an entry to &amp;lt;code&amp;gt;/etc/fstab&amp;lt;/code&amp;gt; with the following XFS options:&lt;br /&gt;
**&amp;lt;code&amp;gt;noatime,nodiratime&amp;lt;/code&amp;gt; &amp;amp;mdash; disables access-time updates to reduce write overhead&lt;br /&gt;
**&amp;lt;code&amp;gt;nodiscard&amp;lt;/code&amp;gt; &amp;amp;mdash; disables TRIM for ZFS-backed storage compatibility&lt;br /&gt;
**&amp;lt;code&amp;gt;logbufs=8,logbsize=32k&amp;lt;/code&amp;gt; &amp;amp;mdash; XFS journal tuning for write-heavy workloads&lt;br /&gt;
**&amp;lt;code&amp;gt;nofail&amp;lt;/code&amp;gt; &amp;amp;mdash; system boots even if the mount is unavailable&lt;br /&gt;
*Sets ownership to &amp;lt;code&amp;gt;locveeam:locveeam&amp;lt;/code&amp;gt; and permissions to &amp;lt;code&amp;gt;700&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Maintenance scheduling ===&lt;br /&gt;
&lt;br /&gt;
The script configures automated filesystem trimming (&amp;lt;code&amp;gt;fstrim&amp;lt;/code&amp;gt;) via cron. You will be prompted to choose a schedule:&lt;br /&gt;
&lt;br /&gt;
*Daily&lt;br /&gt;
*Weekly (Mondays)&lt;br /&gt;
*Monthly (1st of the month)&lt;br /&gt;
&lt;br /&gt;
A custom start time in 24-hour format can be selected for each option.&lt;br /&gt;
&lt;br /&gt;
=== SSH configuration ===&lt;br /&gt;
&lt;br /&gt;
SSH is enabled on port &amp;#039;&amp;#039;&amp;#039;22522&amp;#039;&amp;#039;&amp;#039; and configured to allow access for the &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; user. The non-standard port is intentional &amp;amp;mdash; it avoids conflicts with the host SSH service and is required in the Veeam Backup &amp;amp;amp; Replication repository configuration.&lt;br /&gt;
&lt;br /&gt;
=== Temporary sudo privileges ===&lt;br /&gt;
&lt;br /&gt;
After the repository volumes are prepared, the script temporarily grants &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; sudo access. This allows the Veeam agent to perform its initial configuration steps (such as installing transport components) when you connect from the Veeam console.&lt;br /&gt;
&lt;br /&gt;
The script pauses and waits for you to complete the Veeam-side setup (described in the next section). Once you confirm, sudo access is removed and SSH is disabled to harden the repository.&lt;br /&gt;
&lt;br /&gt;
== Configuring the Veeam side ==&lt;br /&gt;
&lt;br /&gt;
With the storage prepared and &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; temporarily elevated, complete the Veeam Backup &amp;amp;amp; Replication wizard to register the repository. These steps are performed in the Veeam Backup &amp;amp;amp; Replication console on your Windows backup server.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; Do not press &amp;#039;&amp;#039;&amp;#039;Enter&amp;#039;&amp;#039;&amp;#039; in the container console until you have completed all steps in this section and Veeam has finished deploying its transport components. The &amp;#039;&amp;#039;&amp;#039;make_veeam_repo&amp;#039;&amp;#039;&amp;#039; script is waiting at that prompt — pressing Enter removes sudo and disables SSH, which will interrupt a Veeam deployment still in progress.&lt;br /&gt;
&lt;br /&gt;
=== Step 1 — Add Backup Repository ===&lt;br /&gt;
&lt;br /&gt;
#In the Veeam Backup &amp;amp;amp; Replication console, navigate to &amp;#039;&amp;#039;&amp;#039;Backup Infrastructure&amp;#039;&amp;#039;&amp;#039; &amp;amp;rarr; &amp;#039;&amp;#039;&amp;#039;Backup Repositories&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#Right-click &amp;#039;&amp;#039;&amp;#039;Backup Repositories&amp;#039;&amp;#039;&amp;#039; and select &amp;#039;&amp;#039;&amp;#039;Add Backup Repository&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#When prompted for the repository type, select &amp;#039;&amp;#039;&amp;#039;Direct attached storage&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
[[File:Veeam_add_backup_repository.png|frameless|upright=1.4|Veeam: Add Backup Repository — choose Direct attached storage.]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 — Select Linux (Hardened Repository) ===&lt;br /&gt;
&lt;br /&gt;
On the next screen, select &amp;#039;&amp;#039;&amp;#039;Linux (Hardened Repository)&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
[[File:Veeam_linux_hardened_repository.png|frameless|upright=1.2|Veeam: select Linux (Hardened Repository).]]&lt;br /&gt;
&lt;br /&gt;
=== Step 3 — Name the repository ===&lt;br /&gt;
&lt;br /&gt;
Enter a display name for the repository and click &amp;#039;&amp;#039;&amp;#039;Next&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
=== Step 4 — Add the Linux server and credentials ===&lt;br /&gt;
&lt;br /&gt;
#Click &amp;#039;&amp;#039;&amp;#039;Add New&amp;#039;&amp;#039;&amp;#039; next to the server field and enter the IP address or hostname of the storage server.&lt;br /&gt;
#When prompted for credentials, click &amp;#039;&amp;#039;&amp;#039;Add&amp;#039;&amp;#039;&amp;#039; and choose &amp;#039;&amp;#039;&amp;#039;Single-use credentials for hardened repository&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#Enter the following:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Username&amp;#039;&amp;#039;&amp;#039;: &amp;lt;code&amp;gt;locveeam&amp;lt;/code&amp;gt;&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Password&amp;#039;&amp;#039;&amp;#039;: the password set during &amp;lt;code&amp;gt;make_veeam_repo&amp;lt;/code&amp;gt;&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;SSH port&amp;#039;&amp;#039;&amp;#039;: &amp;lt;code&amp;gt;22522&amp;lt;/code&amp;gt;&lt;br /&gt;
#Leave &amp;#039;&amp;#039;&amp;#039;Elevate account privileges automatically&amp;#039;&amp;#039;&amp;#039; enabled. The &amp;#039;&amp;#039;&amp;#039;make_veeam_repo&amp;#039;&amp;#039;&amp;#039; script has already granted temporary sudo to &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; — no root password and no permanent sudoers entry are required.&lt;br /&gt;
#When prompted, review and trust the server&amp;#039;s SSH fingerprint.&lt;br /&gt;
&lt;br /&gt;
Veeam will connect over SSH and install its Transport and Installer services on the container.&lt;br /&gt;
&lt;br /&gt;
=== Step 5 — Select the backup directory ===&lt;br /&gt;
&lt;br /&gt;
#Click &amp;#039;&amp;#039;&amp;#039;Populate&amp;#039;&amp;#039;&amp;#039; to load the available storage.&lt;br /&gt;
#Select &amp;lt;code&amp;gt;/mnt/&amp;amp;lt;zvol_name&amp;amp;gt;&amp;lt;/code&amp;gt; — the XFS repository created by the script.&lt;br /&gt;
:You may optionally append a subdirectory, for example &amp;lt;code&amp;gt;/mnt/&amp;amp;lt;zvol_name&amp;amp;gt;/backups&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Step 6 — Repository properties ===&lt;br /&gt;
&lt;br /&gt;
On the &amp;#039;&amp;#039;&amp;#039;Repository&amp;#039;&amp;#039;&amp;#039; step of the wizard, verify the following settings:&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Use fast cloning on XFS volumes&amp;#039;&amp;#039;&amp;#039; — ensure this is checked. It is supported because the repository uses XFS with reflink enabled, and it reduces storage consumption for synthetic full backups.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Make recent backups immutable for&amp;#039;&amp;#039;&amp;#039; — set this to the number of days matching your retention requirement. Backups will be protected from modification or deletion for this period.&lt;br /&gt;
[[File:Veeam_fast_cloning_immutability.png|frameless|upright=1.4|Veeam: enable fast cloning on XFS and set backup immutability. The path shown is an example — yours will be /mnt/&amp;amp;lt;zvol_name&amp;amp;gt;.]]&lt;br /&gt;
&lt;br /&gt;
Click &amp;#039;&amp;#039;&amp;#039;Next&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
=== Step 7 — Mount server and finish ===&lt;br /&gt;
&lt;br /&gt;
#On the &amp;#039;&amp;#039;&amp;#039;Mount Server&amp;#039;&amp;#039;&amp;#039; step, the Veeam Backup &amp;amp;amp; Replication server is pre-selected as the default mount server — click &amp;#039;&amp;#039;&amp;#039;Next&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#Review the summary and click &amp;#039;&amp;#039;&amp;#039;Apply&amp;#039;&amp;#039;&amp;#039;, then &amp;#039;&amp;#039;&amp;#039;Finish&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
=== Step 8 — Finalize and harden ===&lt;br /&gt;
&lt;br /&gt;
Return to the container console where &amp;#039;&amp;#039;&amp;#039;make_veeam_repo&amp;#039;&amp;#039;&amp;#039; is still waiting. Confirm that Veeam has finished deploying its transport components (the wizard completed without errors), then press &amp;#039;&amp;#039;&amp;#039;Enter&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
The script will:&lt;br /&gt;
*Remove sudo from &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
*Disable SSH on port &amp;#039;&amp;#039;&amp;#039;22522&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
The repository is now hardened. The &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; account remains active for Veeam&amp;#039;s internal data-path use, but no interactive login path remains open.&lt;br /&gt;
&lt;br /&gt;
== Updating the Veeam Backup Server ==&lt;br /&gt;
&lt;br /&gt;
When you later update the Veeam Backup Server, Veeam may need to update the Veeam Data Mover service on this repository over SSH. Because the repository is hardened — SSH is disabled and &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; has no sudo — that connection is blocked. You need to open a temporary maintenance window before running the Veeam Backup Server update.&lt;br /&gt;
&lt;br /&gt;
Open the container console at &amp;lt;code&amp;gt;https://&amp;amp;lt;server-ip&amp;amp;gt;:4200/veeam-hdrep&amp;lt;/code&amp;gt;, then run:&lt;br /&gt;
&lt;br /&gt;
  cd /tools&lt;br /&gt;
  sudo ./update_veeam_repo&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;update_veeam_repo&amp;lt;/code&amp;gt; script re-enables SSH on port &amp;#039;&amp;#039;&amp;#039;22522&amp;#039;&amp;#039;&amp;#039; and grants &amp;#039;&amp;#039;&amp;#039;locveeam&amp;#039;&amp;#039;&amp;#039; temporary sudo (the Data Mover update requires the same elevated privileges as the initial onboarding), then waits. With the maintenance window open, run the Veeam Backup Server update from the Veeam console. When the update completes, return to the container console and press &amp;#039;&amp;#039;&amp;#039;Enter&amp;#039;&amp;#039;&amp;#039; — the script re-hardens the repository by removing sudo and disabling SSH.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; For security reasons, do not leave SSH enabled after the update is complete. Use &amp;lt;code&amp;gt;update_veeam_repo&amp;lt;/code&amp;gt; for this purpose — do not re-run &amp;lt;code&amp;gt;make_veeam_repo&amp;lt;/code&amp;gt;, as its SSH-enable step is gated behind ZVOL re-selection.&lt;br /&gt;
&lt;br /&gt;
== Storage and access reference ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Path (inside container) !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/mnt/&amp;amp;lt;zvol_name&amp;amp;gt;&amp;lt;/code&amp;gt; || Backup data storage (XFS on ZVOL)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/var/lib/veeam&amp;lt;/code&amp;gt; || Veeam log dataset (ZFS dataset)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/var/lib/veeam/log/&amp;lt;/code&amp;gt; || Veeam service log files&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/etc/fstab&amp;lt;/code&amp;gt; || Volume mount configuration&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt; || SSH daemon configuration (port 22522)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/etc/cron.d/fstrim_*&amp;lt;/code&amp;gt; || Automated trim schedules&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance ==&lt;br /&gt;
&lt;br /&gt;
=== Monitoring disk space ===&lt;br /&gt;
&lt;br /&gt;
From the container console:&lt;br /&gt;
&lt;br /&gt;
  df -h /mnt/&amp;amp;lt;zvol_name&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Manual filesystem trim ===&lt;br /&gt;
&lt;br /&gt;
  sudo fstrim /mnt/&amp;amp;lt;zvol_name&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Checking mount status ===&lt;br /&gt;
&lt;br /&gt;
  mountpoint /mnt/&amp;amp;lt;zvol_name&amp;amp;gt;&lt;br /&gt;
  mount | grep /mnt/&amp;amp;lt;zvol_name&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Viewing logs ===&lt;br /&gt;
&lt;br /&gt;
  journalctl -u ssh&lt;br /&gt;
  journalctl -u veeam-ds-logs&lt;br /&gt;
  tail -f /var/log/auth.log&lt;br /&gt;
&lt;br /&gt;
=== Updates ===&lt;br /&gt;
&lt;br /&gt;
Do not run system package updates inside the container. The container has limited disk space, and updates are delivered as new container revisions through the standard small-update mechanism.&lt;br /&gt;
&lt;br /&gt;
== Known issues and limitations ==&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;ZVOLs must include &amp;quot;veeam&amp;quot; in the name.&amp;#039;&amp;#039;&amp;#039; The setup script discovers ZVOLs by searching for this keyword in their device path. ZVOLs without it will not appear in the selection list.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Formatting is destructive.&amp;#039;&amp;#039;&amp;#039; Selecting a non-XFS ZVOL and confirming with &amp;lt;code&amp;gt;format&amp;lt;/code&amp;gt; irreversibly erases all data on that ZVOL. Verify your selection before confirming.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;No in-container package updates.&amp;#039;&amp;#039;&amp;#039; Due to disk space constraints, running &amp;lt;code&amp;gt;apt upgrade&amp;lt;/code&amp;gt; or similar inside the container is not supported. Updates are delivered as new container revisions.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;SSH is a transient onboarding channel only.&amp;#039;&amp;#039;&amp;#039; Veeam connects once over SSH on port &amp;lt;code&amp;gt;22522&amp;lt;/code&amp;gt; using the password set for &amp;lt;code&amp;gt;locveeam&amp;lt;/code&amp;gt; (single-use credentials) to deploy its Data Mover. Backup traffic afterwards does not use SSH. The setup script automatically disables SSH at the finalize step (after you press &amp;#039;&amp;#039;&amp;#039;Enter&amp;#039;&amp;#039;&amp;#039; to confirm onboarding is complete), so SSH key authentication is not required for normal operation. If you later need manual shell access, re-enable SSH and add public keys to &amp;lt;code&amp;gt;/home/locveeam/.ssh/authorized_keys&amp;lt;/code&amp;gt; inside the container.&lt;br /&gt;
&lt;br /&gt;
== Changelog ==&lt;br /&gt;
&lt;br /&gt;
=== rev 04 ===&lt;br /&gt;
&lt;br /&gt;
*The setup script (&amp;lt;code&amp;gt;make_veeam_repo&amp;lt;/code&amp;gt;) now automatically elevates itself to root if it is not already running as root, so it completes reliably even if you forget to prefix it with &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;. Running it as &amp;lt;code&amp;gt;sudo ./make_veeam_repo&amp;lt;/code&amp;gt;, as shown above, remains correct and is still the recommended way to start it.&lt;br /&gt;
*Removed a leftover package-installation check that could misfire and, on a storage server without internet access, print a long series of spurious connection errors. The required XFS tools have always shipped inside the container image, so this change only removes noise — it does not add or change any requirement.&lt;br /&gt;
&lt;br /&gt;
=== rev 03 ===&lt;br /&gt;
&lt;br /&gt;
*SSH is now automatically disabled at the finalize step (Step 8) when onboarding completes, hardening the repository immediately without requiring manual intervention.&lt;br /&gt;
*New &amp;lt;code&amp;gt;update_veeam_repo&amp;lt;/code&amp;gt; maintenance script to safely open and close the SSH and sudo window when updating the Veeam Backup Server — re-enables SSH on port 22522 and grants &amp;lt;code&amp;gt;locveeam&amp;lt;/code&amp;gt; temporary sudo, then re-hardens on confirmation.&lt;br /&gt;
&lt;br /&gt;
=== rev 02 ===&lt;br /&gt;
&lt;br /&gt;
*Initial release of Veeam Hardened Repository container.&lt;br /&gt;
*Interactive setup script (&amp;lt;code&amp;gt;make_veeam_repo&amp;lt;/code&amp;gt;) for user account, ZVOL selection, XFS formatting, and SSH configuration.&lt;br /&gt;
*Automated &amp;lt;code&amp;gt;fstrim&amp;lt;/code&amp;gt; scheduling via cron.&lt;br /&gt;
*Temporary sudo workflow for Veeam transport component installation.&lt;br /&gt;
*Log dataset support (&amp;lt;code&amp;gt;_veeam_logs&amp;lt;/code&amp;gt; ZFS dataset mounted at &amp;lt;code&amp;gt;/var/lib/veeam&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
For further customization or troubleshooting, refer to the [https://www.veeam.com/documentation-guides-datasheets.html upstream Veeam documentation] or contact Open-E support.&lt;br /&gt;
&lt;br /&gt;
[[Category:Help topics]]&lt;br /&gt;
[[Category:Extensions]]&lt;/div&gt;</summary>
		<author><name>Ai-B</name></author>
	</entry>
</feed>