<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>SnapMirror — NetApp Community</title>
        <link>https://community.netapp.com/community/</link>
        <pubDate>Tue, 25 Aug 2026 19:09:27 +0000</pubDate>
        <language>en</language>
            <description>SnapMirror — NetApp Community</description>
    <atom:link href="https://community.netapp.com/community/discussions/tagged/snapmirror/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>ONTAP Tools for VMware vSphere 10.6: More Control, Less Overhead, and Stronger Operations</title>
        <link>https://community.netapp.com/community/discussion/468330/ontap-tools-for-vmware-vsphere-10-6-more-control-less-overhead-and-stronger-operations</link>
        <pubDate>Wed, 19 Aug 2026 20:17:05 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>ChanceBingen</dc:creator>
        <guid isPermaLink="false">468330@/community/discussions</guid>
        <description><![CDATA[<p>For years, protecting VMware datastores with ONTAP tools meant an all-or-nothing choice: protect an entire host cluster, or protect nothing at all. With ONTAP Tools for VMware vSphere 10.6, that trade-off goes away. This release introduces Granular Datastore Protection, a new right-sized deployment option for smaller environments, expanded audit logging for security-conscious teams, and networking and lifecycle improvements that make day-to-day operations simpler.</p><p>Let’s get into it.</p><h2 data-id="granular-datastore-protection-protect-only-what-needs-protecting">Granular Datastore Protection: Protect Only What Needs Protecting</h2><p>The headline feature in 10.6 is Granular Datastore Protection (GDP), which shifts both SnapMirror active sync (SMas) and most traditional SnapMirror replication policies from only protecting entire host clusters down to individual VMFS datastores. Instead of protecting every datastore in a cluster whether it needs it or not, vCenter administrators can now choose exactly which datastores belong in a protection group — and add, remove, or delete them one at a time without disturbing the rest.</p><p>What is a protection group? It’s a vCenter-local representation of a consistency group (CG) in ONTAP 9 on AFF, ASA, FAS, and software-defined systems. We chose to use the term “protection group” in ONTAP tools to be aligned with VMware’s terminology. What this ultimately means is that you can now create and manage CGs directly in the vCenter UI.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/0Z7P4QC8VHB5\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:110736,&quot;width&quot;:545,&quot;height&quot;:549,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F0Z7P4QC8VHB5%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5553,&quot;dateInserted&quot;:&quot;2026-08-19T19:56:26+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F0Z7P4QC8VHB5%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/0Z7P4QC8VHB5/image.png" alt="image.png" height="549" width="545" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/0Z7P4QC8VHB5/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/0Z7P4QC8VHB5/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/0Z7P4QC8VHB5/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/0Z7P4QC8VHB5/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/0Z7P4QC8VHB5/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/0Z7P4QC8VHB5/image.png 2000w, https://us.v-cdn.net/6038798/uploads/0Z7P4QC8VHB5/image.png" sizes="100vw" /></a>
    </span>
</span>
<p>So, what does this mean for new ONTAP tools users?</p><ul><li>Selective protection — mix protected and unprotected datastores freely within the same host cluster.</li><li>Operational flexibility — modify protection groups without tearing down protection for an entire cluster.</li><li>Multiple protection groups per cluster — replicate different datastores to different storage virtual machines (SVMs) or targets as business needs dictate.</li><li>Incremental adoption — protect new datastores as they’re created, or bring existing ones into a group over time.</li></ul><p>Ok, what if you are an existing user of ONTAP tools? It's simple — upgrades from ONTAP tools 10.4 and 10.5 seamlessly migrate existing host-cluster protection settings to the new model, no manual reconfiguration or import required.</p><p>GDP supports SnapMirror active sync's "Automated Failover Duplex (AFD)" policy across uniform and non-uniform vSphere Metro Storage Cluster (vMSC) topologies — giving architects far more precision when designing business continuity for mixed-criticality workloads. GDP can also use traditional asynchronous SnapMirror policies, though that would not be a vMSC configuration. </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/9AAQ7FUTBWZ9\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:60231,&quot;width&quot;:975,&quot;height&quot;:555,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F9AAQ7FUTBWZ9%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5555,&quot;dateInserted&quot;:&quot;2026-08-19T19:58:17+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F9AAQ7FUTBWZ9%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/9AAQ7FUTBWZ9/image.png" alt="image.png" height="555" width="975" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/9AAQ7FUTBWZ9/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/9AAQ7FUTBWZ9/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/9AAQ7FUTBWZ9/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/9AAQ7FUTBWZ9/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/9AAQ7FUTBWZ9/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/9AAQ7FUTBWZ9/image.png 2000w, https://us.v-cdn.net/6038798/uploads/9AAQ7FUTBWZ9/image.png" sizes="100vw" /></a>
    </span>
</span>
<span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/2GBWWU3EBVCD\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:61517,&quot;width&quot;:975,&quot;height&quot;:406,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F2GBWWU3EBVCD%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5554,&quot;dateInserted&quot;:&quot;2026-08-19T19:57:17+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F2GBWWU3EBVCD%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/2GBWWU3EBVCD/image.png" alt="image.png" height="406" width="975" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/2GBWWU3EBVCD/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/2GBWWU3EBVCD/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/2GBWWU3EBVCD/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/2GBWWU3EBVCD/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/2GBWWU3EBVCD/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/2GBWWU3EBVCD/image.png 2000w, https://us.v-cdn.net/6038798/uploads/2GBWWU3EBVCD/image.png" sizes="100vw" /></a>
    </span>
</span>
<p>For a deep dive into GDP, check out the blog that Rajiv and I wrote about it: <a href="https://community.netapp.com/community/discussion/468300/snapmirror-active-sync-ontap-tools-for-vmware-vsphere-granular-datastore-protection-otv10-6#latest" target="_blank" rel="nofollow noopener ugc">SnapMirror Active Sync + ONTAP tools for VMware vSphere Granular Datastore Protection (OTV10.6) - NetApp Community</a></p><h2 data-id="a-lighter-footprint-right-out-of-the-box">A Lighter Footprint, Right Out of the Box</h2><p>Not every environment needs a heavyweight appliance. ONTAP tools 10.6 introduces an Extra Small (XS) deployment size — just 6 vCPUs and 12 GB of RAM per node — and makes it the default Day-0 deployment profile for traditional provisioning and protection workloads. That’s a noticeable reduction from the previous Small footprint (9 vCPU / 18 GB), removing a resource barrier that had kept smaller environments and edge sites from adopting ONTAP tools. </p><p>Also new in this release, CPU hot add and memory hot plug are now enabled by default, so scaling up to <strong>small</strong>, <strong>medium</strong>, or <strong>large</strong> later requires no manual reconfiguration on fresh 10.6 deployments, nor do you have to shut down the appliance to reconfigure it if you forgot to do so during the initial deployment.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/XQU0BGJZFP5B\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:35182,&quot;width&quot;:975,&quot;height&quot;:363,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FXQU0BGJZFP5B%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5556,&quot;dateInserted&quot;:&quot;2026-08-19T20:05:52+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FXQU0BGJZFP5B%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/XQU0BGJZFP5B/image.png" alt="image.png" height="363" width="975" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/XQU0BGJZFP5B/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/XQU0BGJZFP5B/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/XQU0BGJZFP5B/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/XQU0BGJZFP5B/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/XQU0BGJZFP5B/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/XQU0BGJZFP5B/image.png 2000w, https://us.v-cdn.net/6038798/uploads/XQU0BGJZFP5B/image.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="stronger-security-visibility-with-expanded-audit-logging">Stronger Security Visibility with Expanded Audit Logging</h2><p>Security and compliance teams get a significant upgrade in 10.6. ONTAP tools now captures detailed audit logs (including full request and response bodies), discovery and cleanup jobs, and maintenance console operations — complete with username, timestamp, and correlation IDs for full traceability. Logs are retained for 30 days by default (configurable), protected by automated integrity checks that raise alerts on tampering or deletion, and can be forwarded to external systems like VCF Operations for Logsvia syslog. Enterprise security teams increasingly require this level of visibility. With ONTAP tools 10.6, it’s now built directly into the appliance.</p><h2 data-id="faster-nfs-datastores-with-nconnect-support">Faster NFS Datastores with nconnect Support</h2><p>NFS performance got a major boost with nconnect support back in 8.0u2. But it lacked any kind of GUI or API (I wrote a blog about it here: <a href="https://community.netapp.com/community/discussion/455598/automate-nconnect-and-snapshot-offload-for-nfs-datastores-and-turn-your-vmware-storage-up-to-11" target="_blank" rel="nofollow noopener ugc">Automate nconnect and snapshot offload for NFS datastores and turn your VMware storage up to 11 - NetApp Community</a>). It is now configurable directly during NFSv3 and NFSv4 datastore provisioning. By establishing multiple TCP connections over a single IP address, nconnect lets ESXi hosts distribute file operations across those connections in round-robin fashion — unlocking more of the available network bandwidth for NFS workloads without any change to the storage network topology. With nconnect, NFS datastores deliver SAN-level performance with NAS-level simplicity.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/88DESPKAUSNV\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:78677,&quot;width&quot;:619,&quot;height&quot;:412,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F88DESPKAUSNV%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5557,&quot;dateInserted&quot;:&quot;2026-08-19T20:08:35+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F88DESPKAUSNV%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/88DESPKAUSNV/image.png" alt="image.png" height="412" width="619" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/88DESPKAUSNV/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/88DESPKAUSNV/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/88DESPKAUSNV/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/88DESPKAUSNV/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/88DESPKAUSNV/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/88DESPKAUSNV/image.png 2000w, https://us.v-cdn.net/6038798/uploads/88DESPKAUSNV/image.png" sizes="100vw" /></a>
    </span>
</span>
<p>ONTAP tools 10.6 can even modify the maximum nconnect limit of your ESXi hosts from the default limit of 4 up to the maximum supported 8.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/2W8H6Z2JQL7K\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:54903,&quot;width&quot;:975,&quot;height&quot;:495,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F2W8H6Z2JQL7K%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5558,&quot;dateInserted&quot;:&quot;2026-08-19T20:09:12+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F2W8H6Z2JQL7K%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/2W8H6Z2JQL7K/image.png" alt="image.png" height="495" width="975" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/2W8H6Z2JQL7K/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/2W8H6Z2JQL7K/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/2W8H6Z2JQL7K/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/2W8H6Z2JQL7K/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/2W8H6Z2JQL7K/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/2W8H6Z2JQL7K/image.png 2000w, https://us.v-cdn.net/6038798/uploads/2W8H6Z2JQL7K/image.png" sizes="100vw" /></a>
    </span>
</span>
<p>When it comes to nconnect integration, there is one caveat to be aware of: due to a limitation in the vCenter SDK, a plugin can’t modify nconnect settings <strong>after</strong> the datastore is mounted. However, starting with vSphere 9.0, you can change these settings in the datastore's host connectivity menu. Additionally, you can use the script that I shared earlier.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/F4L8ELF1AY3I\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:116757,&quot;width&quot;:975,&quot;height&quot;:345,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FF4L8ELF1AY3I%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5559,&quot;dateInserted&quot;:&quot;2026-08-19T20:10:41+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FF4L8ELF1AY3I%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/F4L8ELF1AY3I/image.png" alt="image.png" height="345" width="975" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/F4L8ELF1AY3I/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/F4L8ELF1AY3I/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/F4L8ELF1AY3I/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/F4L8ELF1AY3I/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/F4L8ELF1AY3I/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/F4L8ELF1AY3I/image.png 2000w, https://us.v-cdn.net/6038798/uploads/F4L8ELF1AY3I/image.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="cleaner-lifecycle-management">Cleaner Lifecycle Management</h2><p>Even good old-fashioned housekeeping gets easier with ONTAP tools 10.6. A new force-delete flag for vCenter removal lets administrators clean up stale or unreachable vCenter entries — including automatic ONTAP tools plugin unregistration — without being blocked by lingering storage backend or datastore associations, provided no vVol datastores or active protection are involved.</p><p>Under the hood, ONTAP tools 10.6 also dynamically switches from ntpd to chronyd for time synchronization (with automatic migration on upgrade), re-implements and optimizes the authentication service for a smaller resource footprint and faster startup, and reorganizes log storage under a dedicated /var/log/otvng directory for cleaner troubleshooting and log rotation.</p><h2 data-id="availability">Availability</h2><p>ONTAP Tools for VMware vSphere 10.6 launched on July 24, 2026, and supports ONTAP 9.16.1 through 9.19.1 alongside VMware Cloud Foundation (VCF) 5.2.1 through 9.0, and vSphere 8.0U3 through 9.0(the appliance can be deployed on ESXi 9.1). More version qualifications may be coming, so stay tuned for further updates. Direct upgrades are supported from ONTAP tools 10.4 and 10.5, with existing host-level protection settings automatically migrated to the new Granular Datastore Protection model.</p><p><em>In summary, whether you’re running a lean single-site deployment or a stretched, multi-site VMware environment protected by SnapMirror Active Sync, ONTAP tools 10.6 gives you finer control, a smaller footprint, and better visibility — all without compromising on the enterprise-grade protection NetApp customers count on.</em></p>]]>
        </description>
    </item>
    <item>
        <title>Mirrored Consistency group creates snapshot. It creates in background but not visible in GUI</title>
        <link>https://community.netapp.com/community/discussion/468328/mirrored-consistency-group-creates-snapshot-it-creates-in-background-but-not-visible-in-gui</link>
        <pubDate>Mon, 17 Aug 2026 18:12:02 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>kamalsharma6</dc:creator>
        <guid isPermaLink="false">468328@/community/discussions</guid>
        <description><![CDATA[<p>Mirrored Consistency group creates snapshot. It creates in background but not visible in GUI</p>]]>
        </description>
    </item>
    <item>
        <title>SnapMirror Active Sync + ONTAP tools for VMware vSphere 10.6 Granular Datastore Protection</title>
        <link>https://community.netapp.com/community/discussion/468300/snapmirror-active-sync-ontap-tools-for-vmware-vsphere-10-6-granular-datastore-protection</link>
        <pubDate>Thu, 06 Aug 2026 05:01:45 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>RajivJain</dc:creator>
        <guid isPermaLink="false">468300@/community/discussions</guid>
        <description><![CDATA[<ul><li>Co-Author: <a data-username="ChanceBingen" data-userid="12714" rel="nofollow" href="https://community.netapp.com/community/profile/ChanceBingen">@ChanceBingen</a> </li></ul><p><strong>Active-Active VM Storage at Datastore Granularity: SnapMirror Active Sync meets ONTAP tools Granular Datastore Protection</strong> </p><p><strong>The two things to remember</strong> </p><ol><li><strong>Active-active with synchronous SnapMirror (SnapMirror active sync / SM-as)</strong> — ONTAP TOOLSONTAP tools Granular Datastore Protection (GDP) lets you hand-pick VMFS-FC or VMFS-iSCSI datastores inside an ESXi host cluster and protect them with <strong>zero recovery time objective (RTO)/zero recovery point objective (RPO)</strong>replication backed by ONTAP SnapMirror Active Sync. VMs can read and write from either site. </li><li><strong>Load balancing across sites: </strong>Workloads can actively use I/O from either location.  </li><li>With <strong>uniform host proximity</strong>, peered datastores at both sites are mapped to ESXi hosts at <strong>both</strong> sites. If one ONTAP cluster becomes unreachable, VMs continue serving I/O from the surviving site with <strong>typical failover latency on the order of ~11 ms</strong> (the actual I/O resumption time [IORT] will be environment-dependent).  </li><li>With <strong>non-uniform host proximity</strong>, ESXi hosts are only mapped to the local copy of the datastore. I.e. If a VM migrates or fails over to a host on the other site, that host only accesses the local ONTAP cluster. If one ONTAP cluster becomes unreachable, the VM will use vSphere HA to failover to the other site since it can only access its local copy.  </li></ol><p>Everything else in this article explains <em>how</em> ONTAP tools 10.6 provisions and governs that experience. </p><p><strong>Why GDP changes the protection conversation</strong> </p><p>Before ONTAP TOOLS 10.6, <strong>Host Cluster Protection (HCP)</strong> was all-or-nothing: protecting a cluster meant protecting <strong>every</strong> eligible VMFS datastore on that cluster together. </p><p><strong>Granular Datastore Protection (GDP)</strong> shifts the unit of protection from the <strong>host cluster</strong> to <strong>individual VMFS datastores</strong> — while still operating within a single ESXi host cluster boundary. </p><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p><strong>Aspect</strong> </p></th><th><p><strong>HCP (pre-10.6)</strong> </p></th><th><p><strong>GDP (ONTAP TOOLS 10.6)</strong> </p></th></tr><tr><td><p>Protection unit </p></td><td><p>Entire host cluster </p></td><td><p>Selected VMFS datastores </p></td></tr><tr><td><p>Mixed protected / unprotected DSs </p></td><td><p>No </p></td><td><p>Yes — same cluster can mix </p></td></tr><tr><td><p>Unprotect one datastore </p></td><td><p>Not supported </p></td><td><p>Supported (non-last DS) </p></td></tr><tr><td><p>Multiple protection groups/cluster </p></td><td><p>One group for all DSs </p></td><td><p>Multiple groups allowed (one SVM per group) </p></td></tr><tr><td><p>Write-order consistency </p></td><td><p>One consistency group (CG) per host cluster </p></td><td><p>Multiple CGs can be configured with different combinations of datastores </p></td></tr></table></div><p> </p><p><strong>Customer value:</strong> Protect only the datastores that matter, add/remove datastores over time, and run different SnapMirror targets per SVM, without forcing every datastore in the host cluster into the same protection group. </p><p><strong>What ONTAP SM-as brings to GDP</strong> </p><p><strong>SnapMirror Active Sync (SM-as)</strong> is ONTAP’s synchronous, active-active replication mode used by the Automated Failover Duplex (AFD) policy. Combined with GDP, it delivers: </p><ul><li><strong>RPO = 0</strong> — writes are synchronously committed to NVRAM on both sites before acknowledgment </li><li><strong>RTO = 0 </strong>— because both copies are always available, IO can resume as soon as the mediator initiates the failover and the host multipath driver can retry any required I/Os </li><li><strong>Active-active data path</strong> — both copies are read/write capable (policy and proximity permitting) </li><li><strong>Consistency group (CG) backed protection</strong> — multiple LUNs/datastores in one atomic replication unit </li><li><strong>Automatic host access orchestration</strong> — ONTAP TOOLS manages igroups, LUN maps, mounts, and HBA rescans </li></ul><p>GDP is the <strong>ONTAP TOOLS control plane</strong>; SM-as is the <strong>ONTAP replication engine</strong>. ONTAP TOOLS creates and lifecycle-manages: </p><ul><li><strong>Protection Settings</strong> — which datastores are protected, CG membership, SnapMirror relationship </li><li><strong>Cluster Configuration</strong> — fault domains, host-to-SVM mapping, uniform vs non-uniform proximity </li><li><strong>Initiator groups (igroups)</strong> — host IQNs/WWPNs mapped to protected LUNs at each site </li></ul><p><strong>ONTAP TOOLS 10.6 constructs that you configure</strong> </p><p><strong>1. Protection Setting</strong> </p><p>A protection group ties together: </p><ul><li>One or more <strong>VMFS datastores</strong> (same host cluster, same SVM) </li><li>An ONTAP <strong>consistency group</strong> </li><li>A <strong>SnapMirror Active Sync</strong> relationship (for AFD) </li><li><strong>Initiator groups</strong> for host access </li></ul><p><strong>Typical workflows:</strong> Protect · Modify (add/remove datastore) · Unprotect · Delete </p><p><strong>2. Cluster Configuration (required for AFD / SM-as)</strong> </p><p>Maps an ESXi host cluster to <strong>two fault domains</strong> (Site A / Site B): </p><ul><li>Each fault domain lists ESXi hosts + peered source/target SVMs </li><li>The uniform_host_config attribute is set at <strong>create time</strong> and is <strong>immutable</strong> </li></ul><p>The following table illustrates the two protection constructs. </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Object</strong> </p></th><th><p><strong>Purpose</strong> </p></th></tr><tr><td><p>Cluster Configuration </p></td><td><p>Topology — fault domains, hosts, SVM peers, uniform vs non-uniform </p></td></tr><tr><td><p>Protection Setting </p></td><td><p>Data — which datastores, CG, SnapMirror, igroups </p></td></tr></table></div><p><strong>Prerequisite:</strong> Create Cluster Configuration <strong>before</strong> protecting datastores with AFD/SM-as. Async-only SnapMirror does not require cluster configuration. </p><p><strong>Uniform vs Non-Uniform Host Proximity</strong> </p><p>This is the architectural fork that determines the system behavior during various modes of failure in different fault domains. </p><p><strong>Uniform proximity (uniform_host_config = true)</strong> </p><p><strong>Behavior:</strong> Peered datastores from <strong>both sites</strong> are mapped to ESXi hosts at <strong>both sites</strong>. All hosts in the cluster can access all protected datastores. ONTAP TOOLS manages <strong>igroup replication</strong> and host proximity settings across both SVMs. </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/96HOF24CH44X\/vmsc-uniform-2026-white-bg.png&quot;,&quot;name&quot;:&quot;vMSC Uniform 2026 white bg.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:128564,&quot;width&quot;:1809,&quot;height&quot;:1782,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F96HOF24CH44X%2Fvmsc-uniform-2026-white-bg.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5490,&quot;dateInserted&quot;:&quot;2026-08-06T16:16:04+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F96HOF24CH44X%2Fvmsc-uniform-2026-white-bg.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png" alt="vMSC Uniform 2026 white bg.png" height="1782" width="1809" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 2000w, https://us.v-cdn.net/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png" sizes="100vw" /></a>
    </span>
</span>
<p> </p><p><strong>Use cases:</strong> </p><ul><li><strong>Active-active workload distribution</strong> — VMs on either site issue I/O to locally mapped LUNs based on proximity settings </li><li><strong>Metro / stretched cluster</strong> — compute at both sites, storage synchronously mirrored </li></ul><p><strong>How does GDP use SMas to protect you in different failure scenarios:</strong> </p><ul><li><strong>Storage cluster failure </strong>— IO continues without vSphere HA by using remote copy </li><li><strong>Storage network failure on local target side of network </strong>— IO continues without requiring vSphere HA by using the remote copy </li><li><strong>Storage network failure on local initiator side of network </strong>— A vSphere HA event triggers automatic recovery on the remote site with VM reboot </li><li><strong>Compute failure </strong>— vSphere HA reboots VM on an applicable ESXi host based on resource availability. Affinity and anti-affinity rules may dictate which site the VM is rebooted on </li><li><strong>Full site outage</strong> — VM’s on the failed site are rebooted and recovered by vSphere HA on the surviving site, and I/O is resumed; typical switchover latency ~<strong>11 ms</strong> (lab/field reference; actual depends on distance, network, and load) </li></ul><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Metric</strong> </p></th><th><p><strong>Uniform + SM-as</strong> </p></th></tr><tr><td><p>RPO </p></td><td><p>0 </p></td></tr><tr><td><p>RTO </p></td><td><p>Near-zero for I/O continuity (automatic path to surviving copy) </p></td></tr><tr><td><p>I/O pattern </p></td><td><p>Both sites active </p></td></tr></table></div><p><strong>Non-uniform proximity (uniform_host_config = false)</strong> </p><p><strong>Behavior:</strong> Peered datastores are mapped only to hosts <strong>locally within each site</strong>. Site A hosts access Site A SVM LUNs; Site B hosts access Site B SVM LUNs. Replication is still synchronous (SM-as), but with a reduced number of non-disruptive failure scenarios at the VM layer. For this reason, <strong>uniform configurations are considered the best practice</strong> when the environment can support it. </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/3FUIBUSQ7PH7\/vmsc-non-uniform-2026-white-bg.png&quot;,&quot;name&quot;:&quot;vMSC Non Uniform 2026 white bg.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:115496,&quot;width&quot;:1809,&quot;height&quot;:1782,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3FUIBUSQ7PH7%2Fvmsc-non-uniform-2026-white-bg.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5491,&quot;dateInserted&quot;:&quot;2026-08-06T16:16:34+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3FUIBUSQ7PH7%2Fvmsc-non-uniform-2026-white-bg.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png" alt="vMSC Non Uniform 2026 white bg.png" height="1782" width="1809" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 2000w, https://us.v-cdn.net/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png" sizes="100vw" /></a>
    </span>
</span>
<p><strong>Use cases:</strong> </p><ul><li>Campus / dual-room: each room’s hosts only access their local copy </li><li>Optimizing limited WAN bandwidth: eliminating host network traffic between failure domains </li><li>Reduced SAN path management: hosts cannot see remote paths </li><li>Sync DR with site affinity: zero data loss </li></ul><p><strong>How does GDP use SMas to protect you in different failure scenarios:</strong> </p><ul><li>Storage cluster failure — A vSphere HA event triggers automatic recovery on the remote site </li><li>Storage network failure on target side of network — A vSphere HA event triggers automatic recovery on the remote site </li><li>Storage network failure on initiator side of network — A vSphere HA event triggers automatic recovery on the remote site </li><li>Compute failure — vSphere HA reboots VM on applicable ESXi host based on resource availability. Affinity and anti-affinity rules may dictate which site the VM is rebooted on </li><li>Full site outage — VM’s on the failed site are recovered by vSphere HA on the surviving site, and I/O is resumed; typical switchover latency ~11 ms (lab/field reference; actual depends on distance, network, and load) </li></ul><p> </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Metric</strong> </p></th><th><p><strong>Non-uniform + SM-as</strong> </p></th></tr><tr><td><p>RPO </p></td><td><p>0 </p></td></tr><tr><td><p>RTO </p></td><td><p>Non-zero — hosts at DR site must regain access (mount, igroup, rescan orchestration) </p></td></tr><tr><td><p>I/O pattern </p></td><td><p>Site-local active; other site is sync replica </p></td></tr></table></div><p><strong>Side-by-side comparison</strong> </p><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p><strong>Dimension</strong> </p></th><th><p><strong>Uniform</strong> </p></th><th><p><strong>Non-uniform</strong> </p></th></tr><tr><td><p>Host access to peer DS </p></td><td><p>All cluster hosts → both sites </p></td><td><p>Site-local hosts → local SVM only </p></td></tr><tr><td><p>Igroup model </p></td><td><p>Replicated igroups across SVMs </p></td><td><p>Per-site igroups </p></td></tr><tr><td><p>Load balancing across sites </p></td><td><p><strong>Yes</strong> — primary value prop </p></td><td><p>No — site-affine I/O </p></td></tr><tr><td><p>Site failure behavior </p></td><td><p>Surviving hosts continue I/O (~11 ms class) </p></td><td><p>Failover orchestration needed; RTO &gt; 0 </p></td></tr><tr><td><p>Cluster config flag </p></td><td><p>uniform_host_config=true </p></td><td><p>uniform_host_config=false </p></td></tr><tr><td><p>Immutable after create? </p></td><td><p>Yes </p></td><td><p>Yes </p></td></tr></table></div><p><strong>End-to-end user flow: from datastore selection to protected active-active</strong> </p><p> </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/41JEJSRQCCAJ\/image-0d7bcd621556f-7221.png&quot;,&quot;name&quot;:&quot;image-0d7bcd621556f-7221.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:153913,&quot;width&quot;:738,&quot;height&quot;:936,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F41JEJSRQCCAJ%2Fimage-0d7bcd621556f-7221.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5486,&quot;dateInserted&quot;:&quot;2026-08-06T04:53:20+00:00&quot;,&quot;insertUserID&quot;:73861,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;73861&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F41JEJSRQCCAJ%2Fimage-0d7bcd621556f-7221.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png" alt="image-0d7bcd621556f-7221.png" height="936" width="738" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 2000w, https://us.v-cdn.net/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png" sizes="100vw" /></a>
    </span>
</span>
<p><strong>GDP use cases (where customers win)</strong> </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Use case</strong> </p></th><th><p><strong>Why GDP + SM-as fits</strong> </p></th></tr><tr><td><p>Protect critical DS only </p></td><td><p>Dev/test DSs stay unprotected; production DSs get SM-as </p></td></tr><tr><td><p>Incremental adoption </p></td><td><p>Add newly created DSs to an existing protection group via Modify </p></td></tr><tr><td><p>Multi-SVM on one cluster </p></td><td><p>Different SnapMirror targets per SVM — separate protection settings </p></td></tr><tr><td><p>Uniform metro cluster </p></td><td><p>Active-active I/O + sync replication + ~11 ms class failover </p></td></tr><tr><td><p>Non-uniform dual-room </p></td><td><p>Sync data protection with strict site-local compute affinity </p></td></tr><tr><td><p>Decommission one DS </p></td><td><p>Non-last unprotect shrinks CG; others stay protected </p></td></tr></table></div><p><strong>Version and platform guardrails (ONTAP TOOLS 10.6)</strong> </p><p><strong>Supported</strong> </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Requirement</strong> </p></th><th><p><strong>Detail</strong> </p></th></tr><tr><td><p>ONTAP TOOLS </p></td><td><p>10.6 </p></td></tr><tr><td><p>Datastore type </p></td><td><p>VMFS only </p></td></tr><tr><td><p>Protocol </p></td><td><p>iSCSI or FC (FCP) </p></td></tr><tr><td><p>ONTAP for SM-as </p></td><td><p>SVM ONTAP <strong>≥  9.16.1</strong> </p></td></tr><tr><td><p>ONTAP cluster size </p></td><td><p><strong>≤ 4 nodes</strong> </p></td></tr><tr><td><p>SnapMirror policy </p></td><td><p>AFD (Automated Failover Duplex) for active sync </p><p>Standard SnapMirror policies are also supported </p></td></tr><tr><td><p>Disaggregated individual unprotect/delete </p></td><td><p>ONTAP <strong>≥ 9.17.1</strong> </p></td></tr></table></div><p><strong>Not supported in 10.6</strong> </p><ul><li>NFS and NVMe datastore protection </li><li>Sync / strict-sync policies outside AFD SM-as scope </li><li>Local snapshot policies for GDP workflows </li><li>Protecting datastores across <strong>different SVMs</strong> in one protection setting </li><li>Moving a datastore between protection groups (unprotect + re-protect required) </li><li>Custom async SnapMirror policies </li><li>MetroCluster-backed configurations </li><li>ONTAP clusters with <strong>&gt; 4 nodes</strong> </li><li>Mixing uniform and non-uniform protection on the same host cluster </li><li>Protection failover initiated from ONTAP TOOLS UI (use <strong>ONTAP System Manager</strong>) </li><li>ONTAP TOOLS discovering CGs / SnapMirror created outside ONTAP TOOLS (CLI/SM) </li></ul><p><strong>Operational guardrails customers should know</strong> </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Guardrail</strong> </p></th><th><p><strong>Impact</strong> </p></th></tr><tr><td><p>Cluster config is immutable </p></td><td><p>Cannot switch uniform ↔ non-uniform without delete/recreate (blocked if AFD protection exists) </p></td></tr><tr><td><p>One DS unprotect at a time </p></td><td><p>Parallel unprotect of multiple DSs not supported </p></td></tr><tr><td><p>Last DS = full delete </p></td><td><p>Unprotecting the last datastore deletes the entire protection group </p></td></tr><tr><td><p>Protected DS unmount </p></td><td><p>Only from hosts <strong>outside</strong> the protection host cluster </p></td></tr><tr><td><p>Async SM on unified (O9) </p></td><td><p>Individual (non-last) unprotect <strong>blocked</strong> </p></td></tr><tr><td><p>Sequential ops in cluster </p></td><td><p>Create/delete DS blocked while another protected DS op is in-flight </p></td></tr><tr><td><p>Parallel protection ops </p></td><td><p>Second op on same group returns <strong>409</strong> while state=updating </p></td></tr></table></div><p><strong>Host proximity and igroups — what ONTAP TOOLS automates</strong> </p><p>When you protect a datastore, ONTAP TOOLS 10.6: </p><ol><li>Creates or extends an ONTAP <strong>consistency group</strong> spanning the protected LUNs/volumes </li><li>Establishes <strong>SnapMirror Active Sync</strong> to the peered SVM </li><li>Creates <strong>nested igroups</strong> (parent per datastore, child per host) with host <strong>IQNs/WWPNs</strong> from participating sites </li><li>For <strong>uniform AFD:</strong> replicates igroups across sites so all hosts retain access </li><li>For <strong>non-uniform AFD:</strong> creates site-local igroups mapped to local fault-domain hosts </li><li>Mounts peer datastores and rescans HBAs when topology changes (cluster config modify) </li></ol><p>You do not manually patch igroups for GDP lifecycle operations — ONTAP TOOLS owns add/remove host, mount, unmount, and shrink flows. </p><p><strong>Deeper dive, what happens when a complete site or failure domain goes down?</strong> </p><p><strong>Uniform proximity + SM-as</strong> </p><ul><li>Both copies were actively serving I/O </li><li>SM-as maintains synchronous consistency </li><li>ESXi hosts at the surviving site continue I/O on the accessible LUN paths </li><li><strong>Expected:</strong> I/O continuity with failover latency typically in the <strong>~11 ms</strong> range (not a guaranteed SLA — validate in your environment) </li></ul><p><strong>Non-uniform proximity + SM-as</strong> </p><ul><li>Source-site hosts were actively using local LUNs; target site held the sync replica </li><li><strong>RPO remains 0</strong> — no committed write loss </li><li><strong>RTO is non-zero</strong> — DR-site hosts (or orchestrated failover) must establish access via igroup/mount/rescan workflows </li><li>ONTAP TOOLS cluster configuration modify / protection discovery may be needed after topology events </li></ul><p><strong>Quick decision guide</strong> </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/0MM0MZC46VCS\/image-aba7b4a5423df-03c2.png&quot;,&quot;name&quot;:&quot;image-aba7b4a5423df-03c2.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:133496,&quot;width&quot;:886,&quot;height&quot;:936,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F0MM0MZC46VCS%2Fimage-aba7b4a5423df-03c2.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5487,&quot;dateInserted&quot;:&quot;2026-08-06T04:53:20+00:00&quot;,&quot;insertUserID&quot;:73861,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;73861&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F0MM0MZC46VCS%2Fimage-aba7b4a5423df-03c2.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png" alt="image-aba7b4a5423df-03c2.png" height="936" width="886" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 2000w, https://us.v-cdn.net/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png" sizes="100vw" /></a>
    </span>
</span>
<p> </p><p><strong>Summary</strong> </p><p><strong>ONTAP SnapMirror active sync</strong> provides the synchronous, active-active replication engine. <strong>ONTAP TOOLS 10.6 Granular Datastore Protection</strong> provides the VMware-native control plane to: </p><ul><li>Hand-pick which VMFS datastores to protect inside a host cluster </li><li>Model <strong>uniform</strong> or <strong>non-uniform host proximity</strong> via Cluster Configuration </li><li>Lifecycle-manage consistency groups, SnapMirror, igroups, mounts, and rescans </li></ul><p><strong>Key Takeaways </strong> </p><p><strong>Active-active sync SnapMirror:</strong> GDP + SM-as delivers zero-RPO, dual-site VMFS protection at datastore granularity. </p><p><strong>Load balancing:</strong> SnapMirror active sync enables both sites to actively serve I/O, maximizing resource utilization with best of breed business continuity on failure. </p>]]>
        </description>
    </item>
    <item>
        <title>Zero RPO, Zero RTO for NAS: SnapMirror active sync Comes to File Workloads</title>
        <link>https://community.netapp.com/community/discussion/468277/zero-rpo-zero-rto-for-nas-snapmirror-active-sync-comes-to-file-workloads</link>
        <pubDate>Thu, 30 Jul 2026 15:36:58 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>Hashim_Zargar</dc:creator>
        <guid isPermaLink="false">468277@/community/discussions</guid>
        <description><![CDATA[<h2 data-id="zero-rpo-and-zero-rto-for-nas">Zero-RPO and Zero-RTO for NAS</h2><p>For years, zero recovery point objective (RPO) for NAS workloads has been achieved through synchronous replication, but achieving zero recovery time objective (RTO) has been a major bottleneck to achieving business continuity. Although synchronous copies of data were available, accessing those copies when needed required scripting, disruptive cutover procedures, and manual interventions. </p><p>SnapMirror active sync changed the game for SAN by offering zero RPO and zero RTO for block workloads. With ONTAP 9.19.1, that same synchronous replication with automated failover capability extends to NAS workloads, like NFS and SMB. This type of NAS data is often equally mission‑critical as SAN, but transparent failover was out of reach. If you run mission-critical file workloads on AFF or AFX, this release is worth a closer look.</p><p>In this post, you will see the gap SM-as NAS closes, how replication and failover behave under the hood, and where it fits next to other solutions offered by NetApp.</p><h2 data-id="the-problem-business-continuity-for-nas-lagged-behind-san">The problem: Business continuity for NAS lagged behind SAN</h2><p>SnapMirror active sync has delivered zero-RPO, zero-RTO failover for SAN workloads for some time. Critical NAS data, like finance ledgers on SMB, Oracle or virtualization workloads on NFS, custom financial small file workloads, and mixed-protocol departmental shares, was also subject to strict regulatory and operational compliance requirements. The DR options for those workloads included MetroCluster for site-wide protection, using SnapMirror synchronous replication with a manual failover process, or simpler SVM-DR that could deliver a low RPO, but not zero RPO. </p><p>Those options involved trade-offs:</p><ol><li>MetroCluster excels when you need infrastructure-level, site-wide continuity. Still, it comes with architecture and operational constraints that not every file workload can tolerate, and it does not offer the granularity of SnapMirror active sync.</li><li>SVM-DR is approachable for whole-SVM protection, yet asynchronous replication means data loss is possible at failover, and recovery is operator-driven.</li><li>SM-as proved synchronous replication plus automated failover could work at metro distances, but NAS was out of scope until now.</li></ol><p>Before 9.19.1, zero data loss and transparent application failover for these critical NAS workloads was offered with MetroCluster. Without it, customers had to compromise with disruptive procedures, RPO trade-offs, or SAN-only active sync while file services waited. From 9.19.1, critical FlexVol data within SVMs can be protected with zero-RPO, zero-RTO with transparent application failover, leveraging proven SnapMirror and SnapMirror active-sync technologies.</p><h2 data-id="what-s-new-in-ontap-9-19-1">What’s new in ONTAP 9.19.1</h2><p>SnapMirror active sync for NAS ships in ONTAP 9.19.1 and later. Supported platforms are AFF and AFX.</p><p>Table 1: SnapMirror active sync NAS vs SAN</p><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p>Area</p></th><th><p>NAS (9.19.1+)</p></th><th><p>SAN</p></th></tr><tr><td><p>Granularity</p></td><td><p>SVM</p></td><td><p>Consistency group</p></td></tr><tr><td><p>Configuration</p></td><td><p>Active-passive with AutomatedFailover</p></td><td><p>Active-active or active-passive</p></td></tr><tr><td><p>Protocols</p></td><td><p>NFS, SMB3 CA shares (non-disruptive failover)<br />
Other SMB versions (disruptive failover)</p></td><td><p>iSCSI, FC, NVMe</p></td></tr></table></div><p>Note: Although the failover in SMB 2.x / SMB 3.x versions and non-CA shares is disruptive (remount/restart apps), the zero RPO for data is still maintained. This is a protocol limitation and not under the control of SnapMirror active sync.</p><p>Unlike SM-as SAN, NAS does not offer active-active client I/O on both sides of the same protected SVM during normal operation. The secondary SVM remains dormant until failover or planned failover.</p><h2 data-id="how-it-works-architecture-overview">How it works: architecture overview</h2><p><strong>1. Synchronous data replication: </strong>Protected FlexVol volumes in an SVM replicate data synchronously to the partner cluster. Writes are acknowledged to clients only after commit on both sides, which delivers zero RPO for protected volumes.</p><p><strong>2. Configuration Replication Service (CRS): </strong>SVM configuration, i.e., LIF definitions, exports, shares, quota configuration, and related settings, are replicated so the secondary can assume the identity of the primary SVM during failover. Identity discard is not supported. You must plan your network environment carefully for matching network design on both sites.</p><p><strong>3. ONTAP Mediator: </strong>The Mediator (on-premises Linux VM or NetApp Console hosted) is required. It provides quorum for cluster health decisions, enables automated failover, and helps prevent split-brain by ensuring only one site serves a given protected SVM relationship.</p><p>Figure 1: SnapMirror active sync NAS</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/X1QXH7THWL1U\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:285081,&quot;width&quot;:1330,&quot;height&quot;:1196,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FX1QXH7THWL1U%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5403,&quot;dateInserted&quot;:&quot;2026-07-30T15:22:52+00:00&quot;,&quot;insertUserID&quot;:123269,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;123269&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FX1QXH7THWL1U%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/X1QXH7THWL1U/image.png" alt="image.png" height="1196" width="1330" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/X1QXH7THWL1U/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/X1QXH7THWL1U/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/X1QXH7THWL1U/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/X1QXH7THWL1U/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/X1QXH7THWL1U/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/X1QXH7THWL1U/image.png 2000w, https://us.v-cdn.net/6038798/uploads/X1QXH7THWL1U/image.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="secondary-svm-behavior">Secondary SVM behavior</h2><p>Failover does not rely on traditional LIF migration in the sense of moving addresses you never pre-staged. The CRS-replicated LIFs already exist on the secondary and transition to operational up/up on their home nodes.</p><p>Table 2: Secondary SVM behaviour</p><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p>Attribute</p></th><th><p>Normal (secondary)</p></th><th><p>After failover (secondary)</p></th></tr><tr><td><p>Subtype</p></td><td><p>dp-destination</p></td><td><p>default</p></td></tr><tr><td><p>Operational state</p></td><td><p>stopped</p></td><td><p>running</p></td></tr><tr><td><p>LIFs</p></td><td><p>up/down (admin state / operational state)<br />
(no IP collision)</p></td><td><p>up/up (same IPs clients already use)</p></td></tr><tr><td><p>Volumes</p></td><td><p>RW, not mounted</p></td><td><p>RW, mounted, serving I/O</p></td></tr></table></div><h2 data-id="granularity">Granularity</h2><p>Protection is SVM-scoped, but you can include or exclude individual volumes when creating the relationship, or when adding volumes later. You can seamlessly add or remove volumes from the SM-as relationship as and when the SLA changes. It does not delete the volumes or the data inside them; instead, internally, volume membership changes trigger a geometry expand or shrink operation.</p><p>Figure 2: Granularity of protection</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/CUXEFR2RTKYW\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:179772,&quot;width&quot;:1428,&quot;height&quot;:870,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FCUXEFR2RTKYW%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5401,&quot;dateInserted&quot;:&quot;2026-07-30T15:11:34+00:00&quot;,&quot;insertUserID&quot;:123269,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;123269&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FCUXEFR2RTKYW%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/CUXEFR2RTKYW/image.png" alt="image.png" height="870" width="1428" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/CUXEFR2RTKYW/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/CUXEFR2RTKYW/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/CUXEFR2RTKYW/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/CUXEFR2RTKYW/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/CUXEFR2RTKYW/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/CUXEFR2RTKYW/image.png 2000w, https://us.v-cdn.net/6038798/uploads/CUXEFR2RTKYW/image.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="co-existence">Co-existence</h2><p>SnapMirror active sync for SAN and NAS can run on the same cluster. It also allows protected and unprotected SVMs to coexist. To protect a NAS SVM with SnapMirror active sync, the SVM must be dedicated to NAS workloads and must not host SAN or object (S3) protocols.</p><p>Figure 3: Co-existence of SVMs</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/BTX89F6C9189\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:315710,&quot;width&quot;:1382,&quot;height&quot;:1622,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FBTX89F6C9189%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5402,&quot;dateInserted&quot;:&quot;2026-07-30T15:12:34+00:00&quot;,&quot;insertUserID&quot;:123269,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;123269&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FBTX89F6C9189%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/BTX89F6C9189/image.png" alt="image.png" height="1622" width="1382" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/BTX89F6C9189/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/BTX89F6C9189/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/BTX89F6C9189/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/BTX89F6C9189/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/BTX89F6C9189/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/BTX89F6C9189/image.png 2000w, https://us.v-cdn.net/6038798/uploads/BTX89F6C9189/image.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="async-fan-out">Async fan-out</h2><p>SnapMirror active sync for NAS solves metro-distance, zero-RPO continuity between two sites. Many customers also require a 3-way DR solution with a third location, a remote vault, or a recovery region with asynchronous replication and different RPO/RTO expectations. In ONTAP 9.19.1, SM-as NAS supports volume-level async fan-out with one additional SnapMirror async leg per protected volume, layered on top of the synchronous SM-as relationship.</p><p>Figure 4: SnapMirror async fanout</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/DUJDWA48LPZR\/image-f8eee1eca1d6e8-1efb.png&quot;,&quot;name&quot;:&quot;image-f8eee1eca1d6e8-1efb.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:234958,&quot;width&quot;:1378,&quot;height&quot;:1166,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FDUJDWA48LPZR%2Fimage-f8eee1eca1d6e8-1efb.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5399,&quot;dateInserted&quot;:&quot;2026-07-30T15:00:06+00:00&quot;,&quot;insertUserID&quot;:123269,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;123269&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FDUJDWA48LPZR%2Fimage-f8eee1eca1d6e8-1efb.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png" alt="image-f8eee1eca1d6e8-1efb.png" height="1166" width="1378" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 2000w, https://us.v-cdn.net/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="key-benefits">Key benefits</h2><ul><li>Zero-RPO: Synchronous replication for protected NAS FlexVols. No application data loss at failover for in-scope protocols.</li><li>Zero-RTO with automated failover.</li><li>Transparent failover where protocols allow, i.e., NFS and SMB3 CA clients can reconnect with no disruption.</li><li>Granular, workload-level protection. Protect critical SVMs (or subsets of volumes within an SVM) without committing the entire cluster to a single DR model.</li><li>Granular workload failover: Selectively fail over individual tenants, departments, or applications at SVM level without impacting the rest of the cluster. This enables targeted DR testing, non‑disruptive maintenance, phased migrations, and even active load balancing between sites.</li><li>Unified operations story: Manage relationships through ONTAP System Manager alongside SM-as SAN; one ONTAP skillset for block and file metro continuity.</li><li>Secondary copy utility: Cross-SVM FlexClone on the destination supports test/dev, analytics, and DR validation without impacting primary I/O.</li><li>Cost-efficient metro DR: Uses a standard inter-cluster network without dedicated replication switches.</li></ul><h2 data-id="use-cases">Use cases</h2><ul><li>Enterprise file services with strict RPO/RTO requirements:<br />
Departmental or business-specific SVMs that must survive site loss without replaying hours of file changes, especially where audit or compliance treats file data like tier-1 applications.</li><li>Financial services and healthcare:<br />
Workloads that already demanded sync block DR can now align selected NAS tiers (e.g., document repositories, imaging interfaces on NFS, SMB CA–enabled application shares) to the same business continuity requirements provided protocol choices match non-disruptive vs disruptive failover expectations.</li><li>Manufacturing and design collaboration:<br />
Project shares that need metro-distance protection and predictable failover without rebuilding every mount point.</li><li>Service providers and multi-tenant clusters:<br />
SVM-level failover independence allows a protected SVM to fail over without forcing unrelated SVMs on the same cluster into the same event. This helps service providers and multi-tenant environments meet client-specific compliance or regulatory requirements by enabling workloads to run from the secondary cluster when needed. After failover, client access to protected volumes is served from the secondary cluster, providing greater flexibility in where data is accessed and hosted.</li><li>Phased Site Migration &amp; Active Load Balancing<br />
Gradually transition operations from one data center to another on an SVM-by-SVM basis for lower-risk migrations. Distribute active workloads optimally by running some enterprise applications on Site A and others on Site B, while protecting both.</li></ul><h2 data-id="considerations-and-limitations">Considerations and limitations</h2><ul><li>Treat SM-as NAS as workload-granular continuity, not a wholesale MetroCluster replacement. MetroCluster remains the answer when you need site-wide, infrastructure-level protection.</li><li>Scale (per HA pair): up to 50 NAS SVMs (combined with SAN CGs: 50 (SVMs + CGs) total), 400 volumes, 80 volumes per SVM, 16 LIFs per SVM.</li><li>Replication topology: Two-way SM-as (each cluster hosts independent protected SVMs for the other) is supported to optimize infrastructure utilization.</li><li>Auto reconfiguration of asynchronous replication fan-out leg, SVM-granular async fan-out, and cascade replication is not supported with SnapMirror active sync for NAS in the first release.</li></ul>]]>
        </description>
    </item>
    <item>
        <title>How to back up databases in seconds and restore them in minutes with Amazon FSx for NetApp ONTAP</title>
        <link>https://community.netapp.com/community/discussion/468034/how-to-back-up-databases-in-seconds-and-restore-them-in-minutes-with-amazon-fsx-for-netapp-ontap</link>
        <pubDate>Mon, 06 Jul 2026 14:52:51 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>Semion</dc:creator>
        <guid isPermaLink="false">468034@/community/discussions</guid>
        <description><![CDATA[<div><p>Databases are at the heart of many business&#8209;critical applications and services. They underpin essential functions such as order processing, billing, inventory management, customer portals, analytics, and much more. When a database becomes unavailable, the consequences are immediate: users lose access to vital information, business operations are disrupted, and reputational damage can quickly ensue.</p><p>To ensure business continuity, organizations set strict recovery point objectives (RPO) and recovery time objectives (RTO) for their most critical databases. Having a backup alone isn&rsquo;t enough; you must be able to restore swiftly to a recent point in time. Achieving these demanding recovery targets for self-managed databases on <a href="https://aws.amazon.com/" target="_blank" rel="noopener nofollow noreferrer">Amazon Web Services (AWS)</a> becomes increasingly difficult as the environment expands in scale.</p><p>By using <a href="https://www.netapp.com/aws/fsx-ontap/" target="_blank" rel="noopener noreferrer nofollow">Amazon FSx for NetApp ONTAP</a> as the backbone of your data infrastructure, you can <a href="https://www.netapp.com/blog/aws-fsxn-blg-optimize-database-performance-costs-with-amazon-fsx-for-netapp-ontap/" target="_blank" rel="noopener noreferrer nofollow">optimize platforms such as SQL Server, Oracle DB, MongoDB, SAP HANA, and others</a>. For many demanding workloads with strict SLAs, FSx for ONTAP is often the only service that enables these databases to run reliably and at scale on the AWS Cloud. In this post, I am going to explain how this is achieved.</p><p>Here&rsquo;s what we&rsquo;ll cover:</p><ul><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/How-to-back-up-databases-in-seconds-and-restore-them-in-minutes-with-Amazon-FSx/ba-p/468034#toc-hId-1707619003">Navigating database resilience challenges: Meeting strict objectives at scale on AWS</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/How-to-back-up-databases-in-seconds-and-restore-them-in-minutes-with-Amazon-FSx/ba-p/468034#toc-hId--844537958">How FSx for ONTAP optimizes resilience for self-managed databases</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/How-to-back-up-databases-in-seconds-and-restore-them-in-minutes-with-Amazon-FSx/ba-p/468034#toc-hId--720420875">What this means for your team: Benefits in practice</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/How-to-back-up-databases-in-seconds-and-restore-them-in-minutes-with-Amazon-FSx/ba-p/468034#toc-hId-1022389460">Summary and next steps</a></li></ul><h2 id="toc-hId-1707619003">Navigating database resilience challenges: Meeting strict objectives at scale on AWS</h2><p>Protecting a single database is one thing, but the task changes dramatically when you&rsquo;re responsible for a large-scale environment. A typical mission-critical deployment can involve hundreds of databases, several hundred terabytes or more of data, and multiple environments dedicated to development, testing, pre-production, and other purposes.</p><p>Within such a landscape, you must meet a range of requirements simultaneously: High availability to ensure that business-critical workloads withstand both component failures and disruptions to Availability Zones (AZs), strict backup recovery objectives, robust disaster recovery (DR) architecture to maintain business connectivity during major incidents, and diligent cost control given the significant expenses associated with database licences, compute resources, and storage capacity.</p><p>Traditional designs that rely solely on database-level replication and periodic backups to block storage or object storage often struggle to address all these demands at scale. As a result, backup windows can expand, restore processes might take longer, and disaster recovery deployments can become increasingly complex and costly to maintain.</p><h2 id="toc-hId--844537958">How FSx for ONTAP optimizes resilience for self-managed databases</h2><p>Let&rsquo;s take a closer look at the standard architecture of self-managed databases on AWS and then discuss how FSx for ONTAP can optimize it. For this example, we will focus on a SQL Server.</p><h3 id="toc-hId-701758872">Initial architecture: AOAG SQL Server running on Amazon EC2 and Amazon EBS</h3><p>I recently worked with a financial customer managing hundreds of databases and over 500 TB of data across multiple environments, including development, test, pre-production, and others. This deployment required high availability across AZs, RPO of 10 minutes and RTO of 1 hour, and an effective DR site to protect against large-scale events and maintain business continuity. The following diagram illustrates the SQL Server architecture the customer chose, with <a href="https://aws.amazon.com/ebs" target="_blank" rel="noopener nofollow noreferrer">Amazon Elastic Block Store (Amazon EBS)</a>&mdash;a common solution for running a SQL Server on AWS:</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/f2/f2d16143b44125fe4b84cb49f996da76.jpg" role="button" title="SQL SERVER WITH EBS.jpg" alt="SQL SERVER WITH EBS.jpg" width="995" /></span></p><p>In this design:</p><ul><li>Two <strong><a href="https://aws.amazon.com/ec2" target="_blank" rel="noopener nofollow noreferrer">Amazon Elastic Compute Cloud (Amazon EC2)</a> instances running SQL Server</strong> are deployed in different AZs within an AWS Region.</li><li>Each instance uses multiple <strong>Amazon EBS volumes</strong> for database files, log files, and other data.</li><li><strong>SQL Server replication</strong>, such as AOAG, keeps the databases synchronized between the instances.</li><li><strong>Amazon EBS snapshots</strong> are used for volume-level backups, with snapshot data stored in <a href="https://aws.amazon.com/s3/" target="_blank" rel="noopener nofollow noreferrer">Amazon Simple Storage Service (Amazon S3)</a>.</li></ul><p>This architecture delivers high availability by distributing SQL Server instances across two separate AZs, while ensuring data durability and recoverability through SQL-level replication and Amazon EBS snapshots stored in Amazon S3. It provides flexible scaling, clear separation of compute and storage, and protection against outages within the Region.</p><p>However, it has several implications:</p><ul><li><strong>Licensing.</strong> AOAG often requires SQL Server Enterprise licensing, which can significantly increase costs when you have many cores and multiple replicas.</li><li><strong>Backup and restore times.</strong> As data volumes grow, the time required to create and restore from volume-level snapshots and copies increases. Meeting the 1-hour RTO across hundreds of databases becomes difficult.</li><li><strong>Storage and cost.</strong> Multiple Amazon EBS volumes, frequent snapshots, and long retention periods increase storage consumption.</li><li><strong>DR site.</strong> Building a DR site using this design typically involves additional infrastructure, extra replicas, more storage, and complex orchestration to meet the RPO and RTO targets.</li></ul><p>At this stage, companies are seeking an alternative architecture to overcome these challenges and optimize resilience. In many cases, as was the case with this customer, the solution lies in the choice of storage service.</p><h3 id="toc-hId--1850398089">Optimized architecture: SQL Server FCI running on Amazon EC2 and FSx for ONTAP</h3><p>Now let&rsquo;s look at an architecture for a SQL Server failover cluster instance (FCI) using FSx for ONTAP as the underlying storage, which the abovementioned customer eventually moved to:</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/d0/d005de08745b1a99a9e748c30c126a91.jpg" role="button" title="FSXN AS A SHARED BLOCK STORAGE.jpg" alt="FSXN AS A SHARED BLOCK STORAGE.jpg" width="1046" /></span></p><p>With this approach, backup and recovery workflows change. Instead of relying only on host-based backups, you use storage-level snapshots as the primary mechanism for protecting data. Creating a snapshot is a fast operation and restore workflows can be built around reverting or cloning from those snapshots.</p><p>Because FSx for ONTAP provides high availability across AZs, it can be used as a shared block storage for both Amazon EC2 instances. With this capability, the customer can move away from an AOAG architecture to FCI, while achieving the same or even better availability. For this architecture, a Standard SQL licence can be used, substantially reducing licensing costs.</p><p>Additionally, because this architecture requires only a single copy of data, it reduces storage capacity and costs and eliminates cross-AZ charges. And without the need for SQL-level replication, Amazon EC2 instance resources are freed up.</p><p>FSx for ONTAP backup operations are based on NetApp incremental Snapshot&trade; technology. Stored locally on the file system, These Snapshots are created rapidly, require minimal storage due to their space-efficient design, and enable quick recovery from logical failures. Their efficient use of space also keeps backup costs low and ensures performance remains unaffected during creation.</p><p>Thanks to an integrated free tool called NetApp SnapCenter&reg; that synchronizes these Snapshot copies with the SQL Server, they become database-aware and require no log forwarding as part of the restoration process.</p><h3 id="toc-hId--107587754">Adding disaster recovery to the mix</h3><p>Now let&rsquo;s add another layer of protection. To further safeguard against physical failures, the design extends to a secondary FSx for ONTAP file system, which can be air-gapped and deployed in another Region. Using NetApp SnapMirror&reg;, data is replicated asynchronously and efficiently, ensuring the latest backups are always available for DR without the overhead of full data copies.</p><p>The following diagram shows the SQL Server DR architecture with FSx for ONTAP:</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/c5/c53fe6545c8bae5d52888321e68cef10.jpg" role="button" title="SQL SERVER DEPLOYMENT WITH DR USING FSXN.jpg" alt="SQL SERVER DEPLOYMENT WITH DR USING FSXN.jpg" width="1074" /></span></p><p>In this setup, the primary FSx for ONTAP file system replicates data incrementally and asynchronously to a secondary FSx for ONTAP file system in a separate Region, providing protection against site-wide or physical failures.</p><p>A disaster recovery SQL Server instance can swiftly attach to replicated volumes or space-efficient thin clones, enabling rapid failover and recovery. DR tests and failovers rely on these storage-level copies, eliminating the need for time-consuming full data restores.</p><p>This approach aligns easily with demanding recovery objectives, such as a 10-minute RPO and 1-hour RTO, because both replication and restoration are handled efficiently at the storage layer.</p><h3 id="toc-hId-1635222581">Outcomes of the revised architecture</h3><p>Compared to the initial architecture, FSx for ONTAP streamlines resilience with high availability across AZs. Backup happens in seconds and restore in minutes, and an effective disaster recovery site is provided.</p><p>For the customer, this meant:</p><ul><li>Meeting its <strong>RPO and RTO requirements</strong>.</li><li>Achieving <strong>high availability across AZs</strong> using a storage&#8209;centric design.</li><li>Reducing <strong>backup operations to seconds</strong> and <strong>restore operations to minutes</strong> by using application-aware, lightweight snapshots.</li><li>Building an <strong>efficient DR site</strong> backed by storage replication.</li><li>Transitioning to a SQL Server Failover Cluster Instance (FCI) design that provided an approximately <strong>40% reduction in licensing and maintenance costs</strong>, along with additional savings on compute and storage.</li></ul><h2 id="toc-hId--720420875"><a target="_blank" name="_Toc257683081" id="_Toc257683081"></a>What this means for your team: Benefits in practice</h2><p>This strategy delivers significant benefits for teams managing their own databases on AWS.</p><p><strong>Database administrators</strong> enjoy quicker and more reliable backup and restore processes, even when working with hundreds of databases. Regular testing of recovery and disaster recovery procedures becomes more straightforward, because snapshot-based clones allow for the rapid creation of temporary environments.</p><p><strong>Storage administrators</strong> benefit from a solution built for efficient snapshots, thin clones, and replication&mdash;naturally supporting database protection. They can set storage policies once and apply them consistently across multiple databases and environments.</p><p><strong>Cloud architects</strong> can implement an architecture that meets stringent RPO and RTO objectives, while optimizing licensing, compute, and storage expenses. Additionally, this approach makes it easier to scale as more databases, environments, and Regions are introduced.</p><p>In short, FSx for ONTAP empowers each team to focus on strategic improvements rather than routine maintenance, enhancing both productivity and resilience.</p><h2 id="toc-hId-1022389460">Summary and next steps</h2><p>Protecting self&#8209;managed databases on AWS at scale is challenging. You need high availability, fast recovery capabilities, and a robust DR strategy, while keeping an eye on cost and operational complexity.</p><p>By adopting FSx for ONTAP as the storage layer and optimizing the architecture, companies can meet strict SLA requirements, achieve high availability across AZs, build efficient DR sites, while gaining substantial savings on licensing costs and additional cost savings on compute and storage.</p><p>If you&rsquo;re running self-managed databases on the AWS Cloud today, this architecture is worth evaluating. Start by assessing your current RPO and RTO targets, backup times, and disaster recovery design, and consider how FSx for ONTAP can help you protect your databases more efficiently.</p><p>To deepen your understanding and explore practical guidance:</p><ul><li><a href="https://www.youtube.com/watch?v=ohU4lDRuB6M&amp;t=447s" target="_blank" rel="noopener nofollow noreferrer">Watch the explainer demo video</a>, showing 3.1 TB of SQL data backed up in just 9 seconds and restored in 8 minutes.</li><li>Read about <a href="https://www.netapp.com/blog/aws-fsxn-blg-optimize-database-performance-costs-with-amazon-fsx-for-netapp-ontap/" target="_blank" rel="noopener noreferrer nofollow">how FSx for ONTAP optimizes database performance and reduces costs by up to 50%</a> and <a href="https://aws.amazon.com/blogs/storage/using-netapp-snapcenter-with-amazon-fsx-for-netapp-ontap-to-protect-your-sql-server-workloads/" target="_blank" rel="noopener nofollow noreferrer">how to protect your SQL Server workloads using NetApp SnapCenter</a> in our blogs.</li><li>Check out the <a href="https://www.netapp.com/aws/fsx-ontap/fsx-mssql-workloads-overview/" target="_blank" rel="noopener noreferrer nofollow">how-to guides and documentation</a> to help you get started.</li></ul></div>]]>
        </description>
    </item>
    <item>
        <title>Run advanced analytics with Amazon Athena directly on data in Amazon FSx for NetApp ONTAP</title>
        <link>https://community.netapp.com/community/discussion/466956/run-advanced-analytics-with-amazon-athena-directly-on-data-in-amazon-fsx-for-netapp-ontap</link>
        <pubDate>Wed, 29 Apr 2026 12:46:47 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>Hanan</dc:creator>
        <guid isPermaLink="false">466956@/community/discussions</guid>
        <description><![CDATA[<div><p><span>Organizations are continuously seeking ways to extract more value from their data while minimizing operational friction. Advanced analytics is one way that can happen.</span></p><p><a href="https://www.amazonaws.cn/en/athena/" target="_blank" rel="noopener nofollow noreferrer"><span>Amazon Athena</span></a><span>, a serverless interactive query service, has long enabled teams to analyze data stored in </span><a href="https://aws.amazon.com/s3" target="_blank" rel="noopener nofollow noreferrer"><span>Amazon Simple Storage Service (Amazon S3)</span></a><span> using standard SQL. But it&rsquo;s not always easy to make file data stored in on-premises systems or outside of AWS accessible to Athena without carefully planned relocations to Amazon S3.</span></p><p><span>Now it&rsquo;s possible to run Athena SQL queries directly on data stored in </span><a href="https://aws.amazon.com/fsx/netapp-ontap/" target="_blank" rel="noopener nofollow noreferrer"><span>Amazon FSx for NetApp ONTAP (FSx for ONTAP) file systems</span></a><span>, and a new world of possibilities is opening up for solution architects, data engineers, and IT leaders. This direct data access streamlines analytics, enhances data governance, and solves the long-standing challenges of data migration.</span></p><p><span>Read on as we cover:</span></p><ul><li aria-level="1"><span>The challenges of migrating data to Amazon S3</span></li><li aria-level="1"><span>Direct SQL analytics with Athena on FSx for ONTAP</span></li><li aria-level="1"><span>The benefits of the FSx for ONTAP Athena integration</span></li><li aria-level="1"><span>Get your data to Athena without a migration</span></li></ul><h2 id="toc-hId-1707568134"><span>The challenges of migrating data to Amazon S3</span></h2><p><span>In typical analytics workflows, preparing data for analysis with Athena would often mean moving datasets from enterprise storage systems into data lakes stored on Amazon S3. However, this data movement process could be time-consuming and require extra attention:</span></p><ul><li aria-level="1"><strong>Extract-transform-load (ETL) jobs:</strong><span> Data engineers must build, maintain, and monitor ETL pipelines, which require specialized skills and tools.</span></li></ul><ul><li aria-level="1"><strong>Operational overhead:</strong><span> Data migration introduces latency, a risk of data inconsistency, and potential compliance issues due to storing data outside of on-premises data centers or specific regions.</span></li></ul><ul><li aria-level="1"><strong>Resource costs:</strong><span> Duplicating large datasets consumes additional compute, network, and storage resources, driving up costs and slowing down project timelines.</span></li></ul><p><span>These challenges can stall business insights and create friction between data producers and consumers.</span></p><h2 id="toc-hId--844588827"><span>Direct SQL analytics with Athena on FSx for ONTAP</span></h2><p><span>With the new </span><a href="https://www.netapp.com/blog/data-access-s3-access-points-fsx-ontap/" target="_blank" rel="noopener noreferrer nofollow"><span>Amazon S3 Access Points for FSx for ONTAP capability</span></a><span>, Amazon S3-based services can directly access file data stored in FSx for ONTAP using the Amazon S3 API. That means Athena can query data in your FSx for ONTAP volumes without migrating or duplicating data to Amazon S3. Data remains within the FSx for ONTAP file system, and users access it using familiar SQL syntax, just as they would with Amazon S3-based datasets.</span></p><p><span>This direct approach means analytics teams can easily run queries, generate reports, and build dashboards using the latest data, all while maintaining a single source of truth (SSoT).</span></p><p><span>Choosing FSx for ONTAP as the storage target for Athena delivers several advantages:</span></p><ul><li aria-level="1"><strong>Multiprotocol access:</strong><span> FSx for ONTAP supports Network File System (NFS), Server Message Block (SMB), and now Amazon S3 protocols. This means the same data can be accessed by analytics tools, legacy applications, and AWS-native services without duplicating files or managing multiple silos. </span><a href="https://www.netapp.com/learn/aws-fsxn-blg-multiprotocol-access-with-amazon-fsx-for-netapp-ontap/" target="_blank" rel="noopener noreferrer nofollow"><span>Learn more about the FSx for ONTAP multiprotocol capability</span></a><span>.</span></li></ul><ul><li aria-level="1"><strong>Non-disruptive operation: </strong><span>FSx for ONTAP lets users query source data directly, eliminating the need to transfer or manipulate data for use on Amazon S3, reducing duplication and time delays. Athena can run live data, providing up-to-date insights without impacting your production applications.</span></li></ul><ul><li aria-level="1"><strong>Extending on-premises deployments: </strong><span>With the help of NetApp&reg; SnapMirror&reg; data replication, on-premises ONTAP&reg; users can easily replicate data to FSx for ONTAP for use with Athena. There&rsquo;s no need for the ETL pipeline to get the data to Amazon S3, and the dataset is kept in sync seamlessly.&nbsp;</span></li></ul><ul><li aria-level="1"><strong>Advanced data management: </strong><span>Features such as point-in-time NetApp Snapshot&trade; copies and rapid cloning allow teams to create safe, instant backups and DevTest environments, accelerating data-driven development and recovery processes. </span><a href="https://www.netapp.com/learn/aws-fsxn-blg-reduce-costs-and-increase-efficiency-with-fsx-for-ontap-cloning/" target="_blank" rel="noopener noreferrer nofollow"><span>Learn more about the FSx for ONTAP cloning capability</span></a><span>.</span></li></ul><ul><li aria-level="1"><strong>Data protection:</strong><span> FSx for ONTAP provides robust data protection through point-in-time Snapshot copies, and Autonomous Ransomware Protection (ARP), which automatically detects and mitigates ransomware threats. Business continuity is further enhanced by built-in data replication, enabling seamless backup and recovery across sites and AWS Regions, along with </span><a href="https://docs.netapp.com/us-en/workload-fsx-ontap/create-cyber-vault.html" target="_blank" rel="noopener noreferrer nofollow"><span>FSx for ONTAP cyber vault</span></a><span> capabilities that secure critical backups in isolated environments for added resilience.</span></li></ul><ul><li aria-level="1"><strong>Storage efficiency features:</strong><span> FSx for ONTAP offers built-in thin provisioning, data deduplication, compression, and compaction, as well as data tiering, all of which significantly reduce your storage footprint and its associated costs. </span><a href="https://www.netapp.com/learn/aws-fsxn-blg-reduce-costs-and-increase-efficiency-with-fsx-for-ontap/" target="_blank" rel="noopener noreferrer nofollow"><span>Learn more about the FSx for ONTAP cost efficiency</span></a><span>.</span></li></ul><p><span>Deduplication also benefits performance when running analytics workloads on large volumes that contain similar or repetitive data.</span></p><h2 id="toc-hId-898221508"><span>The benefits of the FSx for ONTAP Athena integration</span></h2><p><span>For cloud architects, data engineers, and IT leaders, the integration of Athena with FSx for ONTAP translates into real-world value:</span></p><ul><li aria-level="1"><strong>Flexibility: </strong><span>Multiprotocol access enables seamless collaboration between diverse teams and applications.</span></li></ul><ul><li aria-level="1"><strong>Seamless access to on-premises data:</strong><span> With SnapMirror replicating data from ONTAP systems to FSx for ONTAP, Athena has seamless access to your datasets. No migrations required.</span></li></ul><ul><li aria-level="1"><strong>Cost savings:</strong><span> Eliminating the need for data migration, the FSx for ONTAP storage efficiency features mean lower infrastructure bills and less time spent on operational tasks.</span></li></ul><ul><li aria-level="1"><strong>Simplified workflows:</strong><span> With data available for both operational and analytical workloads in place, teams can move faster from raw data to actionable insights.</span></li></ul><ul><li aria-level="1"><strong>Improved data governance: </strong><span>Maintaining a single, consistent copy of data simplifies access control, auditing, and meeting compliance goals. These are critical requirements for organizations in highly regulated sectors, such as the healthcare and financial industries.<br /></span></li></ul><h2 id="toc-hId--1653935453"><span>Get your data to Athena without a migration</span></h2><p><span>Running Athena queries directly on data stored in FSx for ONTAP is a gamechanger for organizations striving to modernize their analytics capabilities without the pain of migrating data to Amazon S3.&nbsp;</span></p><p><span>This new accessibility brings together the best of both worlds: Instant, serverless SQL analysis and enterprise-grade storage with multiprotocol access, advanced data management, and storage efficiency.&nbsp;</span></p><p><span>By adopting Athena with FSx for ONTAP, cloud architects, data engineers, and IT leaders can accelerate insights, reduce costs, and strengthen data governance empowering their teams to realize the full potential of their data, faster and more securely than ever before.</span></p><p><span>Learn more in:</span></p><ul><li aria-level="1"><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/Accelerate-innovation-with-Amazon-S3-Access-Points-for-Amazon-FSx-for-NetApp/ba-p/464634" target="_blank"><span>How Amazon S3 Access Points for FSx for ONTAP works</span></a></li><li aria-level="1"><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/Unlock-GenAI-and-analytics-use-cases-with-Amazon-S3-Access-Points-for-FSx-for/ba-p/465378" target="_blank"><span>Amazon S3 Access Points for FSx for ONTAP analytics use cases</span></a></li><li aria-level="1"><a href="https://docs.aws.amazon.com/fsx/latest/ONTAPGuide/accessing-data-via-s3-access-points.html" target="_blank" rel="noopener nofollow noreferrer"><span>Amazon S3 Access Points for FSx for ONTAP documentation</span></a></li></ul></div>]]>
        </description>
    </item>
    <item>
        <title>NetApp Backup &amp; Recovery preview support for Kubernetes workloads</title>
        <link>https://community.netapp.com/community/discussion/462563/netapp-backup-recovery-preview-support-for-kubernetes-workloads</link>
        <pubDate>Fri, 08 Aug 2025 14:21:02 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>PatricU</dc:creator>
        <guid isPermaLink="false">462563@/community/discussions</guid>
        <description><![CDATA[<div><p>Last week, NetApp <a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/NetApp-Backup-and-Recovery-adds-preview-support-for-Kubernetes-workloads/ba-p/462304" target="_blank">previewed</a> its new Backup and Recovery solution for Kubernetes-based containers, offering seamless, unified protection for applications on NetApp storage. This integration is a game-changer for those managing modern applications in their organizations.</p><p>Key Highlights:</p><ul><li>Unified Protection: Manage and protect Kubernetes applications and resources from a single console.</li><li>Enhanced Data Protection: Leverages NetApp SnapMirror&reg; for faster backups and restores, building on the robust Trident&trade; software.</li><li>Streamlined Operations: Efficiently moves backup data to object storage using SnapMirror technology.</li></ul><p>Preview features are:</p><ul><li>Centralized management for Kubernetes applications and resources.</li><li>Structured incremental backups with protection policies.</li><li>Restore applications to the same or different clusters and namespaces.</li><li>Change block tracking for optimized performance.</li></ul><p>Stay tuned for more features being added throughout the preview period!</p><p>In this blog post, we&rsquo;ll guide you through setting up protection policies and protecting and restoring your K8s applications with NetApp backup &amp; recovery.</p><p>Ready to elevate your data protection game? Let&rsquo;s dive in!</p><h1 id="toc-hId-1903958659">Test environment</h1><p>For our further demonstrations, we use an <a href="https://docs.rke2.io/" target="_blank" rel="nofollow noopener noreferrer">RKE2</a> cluster <span style="font-family: andale mono,times;">sks3725</span> with the latest version of the NetApp <a href="https://docs.netapp.com/us-en/trident/index.html" target="_blank" rel="noopener noreferrer nofollow">Trident</a> CSI provisioner installed, and the NetApp <a href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Where_can_the_NetApp_ONTAP_9_Simulator_be_downloaded" target="_blank" rel="noopener noreferrer nofollow">ONTAP 9 simulator</a> to provide backend storage.</p><p>After installing the RKE2 snapshot controller and configuring the Trident backend including the corresponding storage and volume snapshot class, we have this storage configuration on our cluster:</p><pre><code>$ tridentctl -n trident get backends
+-----------------+----------------+--------------------------------------+--------+------------+---------+
|      NAME       | STORAGE DRIVER |                 UUID                 | STATE  | USER-STATE | VOLUMES |
+-----------------+----------------+--------------------------------------+--------+------------+---------+
| ontap-nas-vsim1 | ontap-nas      | 1654b6a5-b588-4d53-859d-20303c6d2f60 | online | normal     |       0 |
+-----------------+----------------+--------------------------------------+--------+------------+---------+

$ kubectl get sc
NAME                        PROVISIONER             RECLAIMPOLICY   VOLUMEBINDINGMODE   ALLOWVOLUMEEXPANSION   AGE
ontap-vsim1-nas (default)   csi.trident.netapp.io   Delete          Immediate           false                  18s


$ kubectl get volumesnapshotclass
NAME                    DRIVER                  DELETIONPOLICY   AGE
trident-snapshotclass   csi.trident.netapp.io   Delete           57s</code></pre><p>For the backup and restore tests, we installed a simple Minio&reg; application:</p><pre><code>$ kubectl get all,pvc -n minio
NAME                               READY   STATUS    RESTARTS   AGE
pod/minio-b6b84f46c-sr2qm          1/1     Running   0          114s
pod/minio-console-cb99559c-zgq76   1/1     Running   0          114s
 
NAME                    TYPE        CLUSTER-IP     EXTERNAL-IP   PORT(S)    AGE
service/minio           ClusterIP   10.98.237.51   &lt;none&gt;        9000/TCP   115s
service/minio-console   ClusterIP   10.104.0.87    &lt;none&gt;        9090/TCP   115s
 
NAME                            READY   UP-TO-DATE   AVAILABLE   AGE
deployment.apps/minio           1/1     1            1           115s
deployment.apps/minio-console   1/1     1            1           115s
 
NAME                                     DESIRED   CURRENT   READY   AGE
replicaset.apps/minio-b6b84f46c          1         1         1       115s
replicaset.apps/minio-console-cb99559c   1         1         1       115s
 
NAME                          STATUS   VOLUME                                     CAPACITY   ACCESS MODES   STORAGECLASS      VOLUMEATTRIBUTESCLASS   AGE
persistentvolumeclaim/minio   Bound    pvc-b0fed8f1-c5ed-4000-b938-ba29393864f0   8Gi        RWO            ontap-vsim1-nas   &lt;unset&gt;                 116s</code></pre><p>Our NetApp Backup and Recovery account and environment are prepared already as per the NetApp Backup and Recovery <a href="https://docs.netapp.com/us-en/bluexp-setup-admin/task-quick-start-standard-mode.html" target="_blank" rel="noopener noreferrer nofollow">requirements</a>: My user has the required permissions and a NetApp Backup and Recovery <a href="https://docs.netapp.com/us-en/bluexp-setup-admin/task-install-connector-on-prem.html" target="_blank" rel="noopener noreferrer nofollow">connector</a> is already installed and configured in our on-premises test environment, and the working environment was created and associated with an Azure Storage account.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/5b/5b3fd77fed0b76219e2d62ed777b4792.png" role="button" title="PatricU_0-1754660414728.png" alt="PatricU_0-1754660414728.png" width="669" /></span></p><h1 id="toc-hId--648198302">Discover the Kubernetes cluster</h1><p>The typical workflow to protect your K8s applications obviously starts by adding your K8s cluster to NetApp Backup and Recovery, enabling you to then add applications to the cluster and protect the resources hosted by the cluster.</p><p>If you are discovering Kubernetes workloads for the first time, in NetApp Backup and Recovery, select&nbsp;<strong>Discover and Manage</strong>&nbsp;under the Kubernetes workload type. If you have already discovered Kubernetes workloads, in NetApp Backup and Recovery, select&nbsp;<strong>Inventory</strong>&nbsp;&gt;&nbsp;<strong>Workloads</strong>&nbsp;and then select&nbsp;<strong>Discover resources</strong>.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/47/47f85c053abe3c731ca0bf9216e7ac19.png" role="button" title="PatricU_1-1754660548666.png" alt="PatricU_1-1754660548666.png" width="604" /></span><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/95/959ed9ece0d4753399b357fcc2f2a0b2.png" role="button" title="PatricU_2-1754660568771.png" alt="PatricU_2-1754660568771.png" width="669" /></span></p><p>In the next screen, select the <strong>Kubernetes</strong> workload type.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/26/2694192215b14f82baa4d9d9537860a9.png" role="button" title="PatricU_3-1754660611178.png" alt="PatricU_3-1754660611178.png" width="669" /></span></p><p>Enter the cluster name to add to NetApp Backup and Recovery and choose a NetApp Backup and Recovery connector to use with the K8s cluster:</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/b9/b946c3cb3d75466395c14e54c33c7e1d.png" role="button" title="PatricU_4-1754660654479.png" alt="PatricU_4-1754660654479.png" width="669" /></span></p><p>Now NetApp Backup and Recovery creates command line instructions to add the K8s cluster to NetApp Backup and Recovery.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/eb/eb6857fe5ddf38d036a5b5a6eecd4c93.png" role="button" title="PatricU_5-1754660678090.png" alt="PatricU_5-1754660678090.png" width="669" /></span></p><p>Follow the command line instructions on your K8s cluster:</p><pre><code>$ kubectl create namespace trident-protect
namespace/trident-protect created

$ kubectl -n trident-protect create secret generic tp-proxy-api-token --from-literal apiToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhY2NvdW50X2lkIjoiN2YyOTU1YWItZDEwOS00NTk3LThkMzItMzM2M2NmOTVjYTllIiwiYWdlbnRfaWQiOiJjSFBTTFRWRzdXM1FKVnN0czJFSTRXazBUZmx5U2ZiVyIsImlhdCI6MTc1MjY4MTQ1M30.7PcaZ4VwnWCAhA137wV5lgH9cLHDTI8Ngzq9fut3vGY
secret/tp-proxy-api-token created

$ helm repo add --force-update netapp-trident-protect https://netapp.github.io/trident-protect-helm-chart
"netapp-trident-protect" has been added to your repositories

$ helm install trident-protect netapp-trident-protect/trident-protect-connector --version 100.2507.0 --namespace trident-protect --set clusterName=sks3725 --set trident-protect.cbs.accountID=7f2955ab-d109-4597-8d32-3363cf95ca9e --set trident-protect.cbs.connectorID=cHPSLTVG7W3QJVsts2EI4Wk0TflySfbWclients --set trident-protect.cbs.proxySecretName=tp-proxy-api-token --set trident-protect.cbs.proxyHost=http://10.192.65.83/tpproxy
NAME: trident-protect
LAST DEPLOYED: Wed Jul 16 18:10:16 2025
NAMESPACE: trident-protect
STATUS: deployed
REVISION: 1
TEST SUITE: None</code></pre><p>These steps install Trident protect and the Trident protect connector on the K8s cluster in the <span style="font-family: andale mono,times;">trident-protect</span> namespace, ensuring that NetApp Backup and Recovery can interact with the K8s cluster.</p><pre><code>$ kubectl get all -n trident-protect
NAME                                                      READY   STATUS    RESTARTS      AGE
pod/trident-protect-connector-566f7c87cb-twc4b            1/1     Running   0             43s
pod/trident-protect-controller-manager-5cbf8b5f57-wpc4p   2/2     Running   1 (38s ago)   43s
 
NAME                                                         TYPE        CLUSTER-IP       EXTERNAL-IP   PORT(S)    AGE
service/tp-webhook-service                                   ClusterIP   10.100.92.100    &lt;none&gt;        443/TCP    44s
service/trident-protect-controller-manager-metrics-service   ClusterIP   10.109.117.217   &lt;none&gt;        8443/TCP   44s
 
NAME                                                 READY   UP-TO-DATE   AVAILABLE   AGE
deployment.apps/trident-protect-connector            1/1     1            1           44s
deployment.apps/trident-protect-controller-manager   1/1     1            1           44s
 
NAME                                                            DESIRED   CURRENT   READY   AGE
replicaset.apps/trident-protect-connector-566f7c87cb            1         1         1       44s
replicaset.apps/trident-protect-controller-manager-5cbf8b5f57   1         1         1       44s</code></pre><p>After you complete the steps, select <strong>Discover</strong>. The cluster is added to the inventory.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/1e/1e79e4ad80daaf05c3a8555ff22135a7.png" role="button" title="PatricU_6-1754660955731.png" alt="PatricU_6-1754660955731.png" width="669" /></span></p><p>Select <strong>View</strong> in the associated Kubernetes workload to see the list of applications, clusters, and namespaces for that workload. We see our newly added cluster <span style="font-family: andale mono,times;">sks3725</span> in the list of managed clusters:</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/29/2914a8bbe9da349886199ccd9bf88fa6.png" role="button" title="PatricU_7-1754661006665.png" alt="PatricU_7-1754661006665.png" width="669" /></span></p><h1 id="toc-hId-1094612033">Create application</h1><p>With our test cluster <span style="font-family: andale mono,times;">sks3725</span> added to NetApp Backup and Recovery, we can now add our sample Minio application to NetApp Backup and Recovery, making NetApp Backup and Recovery aware of the running application on the Kubernetes cluster. In NetApp Backup and Recovery, select <strong>Inventory</strong>, then select the <strong>Applications</strong> tab and click on <strong>Create application</strong>.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/3c/3cc043c328a9844f03543f17ef5d2ec1.png" role="button" title="PatricU_8-1754661055388.png" alt="PatricU_8-1754661055388.png" width="669" /></span></p><p>Now add your name for the application, select the K8s cluster it&rsquo;s running on, and the namespaces that contain the app&rsquo;s resources. Optionally you can also include resources based on label and GroupVersionKind (GVK) filters and add cluster scoped resources to the NetApp Backup and Recovery application definition. In our case, we simply add the <span style="font-family: andale mono,times;">minio</span> namespace to the application definition.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/74/7453fcbea5ef79f4b8e8fc3b7a0d4626.png" role="button" title="PatricU_9-1754661123773.png" alt="PatricU_9-1754661123773.png" width="669" /></span></p><p>We now hit <strong>Search</strong> to get the list of application resources NetApp Backup and Recovery discovers and check the list for completeness.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/12/129b07f13560e30e70f85dbf92f88dc2.png" role="button" title="PatricU_10-1754661157061.png" alt="PatricU_10-1754661157061.png" width="669" /></span><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/27/27690d6855bd374247faefb45eef20a8.png" role="button" title="PatricU_11-1754661170764.png" alt="PatricU_11-1754661170764.png" width="669" /></span></p><p>In the next window, we could add pre- and postscripts (execution hooks the run before and after snapshots/backups) and assign a protection policy to the application. As we don&rsquo;t need pre- and postscripts and want to create a protection policy separately, we skip both steps and create the application.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/1d/1d1a5fe16b6b51c18ef31458e642e6a5.png" role="button" title="PatricU_12-1754661212781.png" alt="PatricU_12-1754661212781.png" width="669" /></span></p><p>The minio application is created and appears in the list of applications in the <strong>Applications</strong> tab of the Kubernetes inventory with the protection status &ldquo;Unprotected&rdquo; and application status &ldquo;Ready&rdquo;.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/57/5723ba78a741da60d9cf2f260fb820ed.png" role="button" title="PatricU_13-1754661254590.png" alt="PatricU_13-1754661254590.png" width="669" /></span></p><h1 id="toc-hId--1457544928">Create protection policy</h1><p>Next, let&rsquo;s create a new protection policy. We start from the list of applications in the Backup &amp; recovery Inventory, find our still unprotected minio application in the list of applications and select</p><h1 id="toc-hId-285265407">Create protection policy</h1><p>Next, let&rsquo;s create a new protection policy. We start from the list of applications in the Backup &amp; recovery Inventory, find our still unprotected <span style="font-family: andale mono,times;">minio</span> application in the list of applications and select Protect from the associated <strong>Actions</strong> menu.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/3b/3b20d9dbe3b0757cea0111ffaf2ecca0.png" role="button" title="PatricU_14-1754661337686.png" alt="PatricU_14-1754661337686.png" width="793" /></span></p><p>From there, we can create a new protection policy (or could add an existing one).</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/8d/8d0c1b9d720b3bb29682725d62e9fedf.png" role="button" title="PatricU_15-1754661393748.png" alt="PatricU_15-1754661393748.png" width="793" /></span></p><p>In the first step, we select Kubernetes as the workload type and set the policy name as <span style="font-family: andale mono,times;">pu-minio-11</span>.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/1e/1ed49a997018bafd76043788af83a7be.png" role="button" title="PatricU_16-1754661427006.png" alt="PatricU_16-1754661427006.png" width="578" /></span></p><p>Then we select the backup architecture. As we want to protect our application also against for example the failure of the K8s cluster, the underlying ONTAP storage, or the whole data center, we select &ldquo;Disk to object storage&rdquo; as data flow model, which protects the application data by local snapshots and copies of the data in an offsite object storage.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/e5/e5a4f800f2d19340d6804acf56d0a3fa.png" role="button" title="PatricU_17-1754661461344.png" alt="PatricU_17-1754661461344.png" width="598" /></span></p><p>Now we define the protection schedules, sticking with the default schedules of hourly snapshots and one daily snapshot, keeping the last three snapshots of each cycle.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/55/5577a4297d6fa10780d961c1c7716f14.png" role="button" title="PatricU_18-1754661487924.png" alt="PatricU_18-1754661487924.png" width="530" /></span></p><p>Next, we select the object storage location to store the Kubernetes application resources during each snapshot cycle, selecting an already configured Azure backup target.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/33/3395a5ff97e499fedbaa95ac97ad4594.png" role="button" title="PatricU_19-1754661512136.png" alt="PatricU_19-1754661512136.png" width="422" /></span></p><p>Then we select the object storage location to store the actual application backup data, in our case we use the same target as for the application resources.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/b5/b55082972f3f0a0cc8b0a726c0eaeb7a.png" role="button" title="PatricU_20-1754661536570.png" alt="PatricU_20-1754661536570.png" width="431" /></span></p><p>In the last step, we can adjust the schedule for the backup schedules if needed and click <strong>Create</strong> to create the protection schedule.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/70/7083bcbc63c1c781ad88fd32398d6912.png" role="button" title="PatricU_21-1754661587076.png" alt="PatricU_21-1754661587076.png" width="636" /></span></p><h1 id="toc-hId-2028075742">Protect application</h1><p>To protect our sample application, we go back to the list of applications in the Backup &amp; recovery <strong>Inventory</strong>, select our minio application and select <strong>Protect</strong> from the associated <strong>Actions</strong> menu.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/c9/c9419629cc58f3a3b21f4c8469fe9d44.png" role="button" title="PatricU_22-1754661637548.png" alt="PatricU_22-1754661637548.png" width="793" /></span></p><p>Now we search for the newly created protection policy <span style="font-family: andale mono,times;">pu-minio-11</span> in the list of existing policies and select it.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/39/394559c39c5b662b57bc8cfcd8c28e1f.png" role="button" title="PatricU_23-1754661663045.png" alt="PatricU_23-1754661663045.png" width="793" /></span></p><p>As we don&rsquo;t want to add any pre- or postscript, we select <strong>Done</strong> and the policy is attached to the application.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/dd/ddbe580a94fb1eaa82051c8833ca8218.png" role="button" title="PatricU_24-1754661690016.png" alt="PatricU_24-1754661690016.png" width="793" /></span></p><p>NetApp Backup and Recovery now immediately starts a baseline backup, a full backup of the application. Any future incremental backups are created based on the schedule that you define in the protection policy associated with the application. We can track the progress of the backup by selecting <strong>Track progress</strong>.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/90/901dcdaadbd8431ba3289562a8ef3735.png" role="button" title="PatricU_25-1754661746054.png" alt="PatricU_25-1754661746054.png" width="793" /></span></p><p>This leads to the <strong>Monitoring</strong> tab, where we see the details of the protection job, which succeeds after a short while.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/6e/6e4c4d2639ebd6bfc9458df5f8fb9d8d.png" role="button" title="PatricU_26-1754661792505.png" alt="PatricU_26-1754661792505.png" width="793" /></span></p><p>Checking on the K8s cluster with the Trident protect CLI, we see the baseline backup and snapshot.</p><pre><code>$ tridentctl-protect get backup -n minio
+-------------------------------------+------------------+----------------+-----------+-------+--------+
|                NAME                 |       APP        | RECLAIM POLICY |   STATE   | ERROR |  AGE   |
+-------------------------------------+------------------+----------------+-----------+-------+--------+
| baseline-transfer-backup-9hviqxzflt | minio-bjo9nkv54p | Retain         | Completed |       | 16m26s |
+-------------------------------------+------------------+----------------+-----------+-------+--------+
$ tridentctl-protect get snapshot -n minio
+---------------------------------------------+------------------+----------------+-----------+-------+--------+
|                    NAME                     |       APP        | RECLAIM POLICY |   STATE   | ERROR |  AGE   |
+---------------------------------------------+------------------+----------------+-----------+-------+--------+
| backup-e97a09a2-7b1f-4296-b718-b8c3f648a29f | minio-bjo9nkv54p | Delete         | Completed |       | 16m35s |
+---------------------------------------------+------------------+----------------+-----------+-------+--------+</code></pre><h2 id="toc-hId--720594724">On-demand backup</h2><p>We can also manually create a backup of the sample application if needed, for example to make sure the most recent data is protected. Again, from the list of application in the <strong>Inventory</strong>, select the <span style="font-family: andale mono,times;">minio</span> application and select <strong>Backup now </strong>from the <strong>Actions</strong> menu.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/c7/c77e0f3da13ac0aaff7e2c385bcd43d4.png" role="button" title="PatricU_27-1754661993501.png" alt="PatricU_27-1754661993501.png" width="793" /></span></p><p>Start the on-demand backup by selecting <strong>Back up</strong>.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/b3/b364e842b104a48ab984b4ff62fe38c9.png" role="button" title="PatricU_28-1754662027270.png" alt="PatricU_28-1754662027270.png" width="793" /></span></p><p>The on-demand backup starts, and we could again track its progress.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/89/8931d4337c1f2b7d2527fced141ba51f.png" role="button" title="PatricU_29-1754662063339.png" alt="PatricU_29-1754662063339.png" width="793" /></span></p><p>Once the backup finishes, we can see it on the cluster listed as an ad-hoc backup.</p><pre><code>$ tridentctl-protect get backup -n minio
+-------------------------------------+------------------+----------------+-----------+-------+-------+
|                NAME                 |       APP        | RECLAIM POLICY |   STATE   | ERROR |  AGE  |
+-------------------------------------+------------------+----------------+-----------+-------+-------+
| ad-hoc-backup-drpz2so916            | minio-bjo9nkv54p | Retain         | Completed |       | 2m8s  |
| baseline-transfer-backup-9hviqxzflt | minio-bjo9nkv54p | Retain         | Completed |       | 39m8s |
+-------------------------------------+------------------+----------------+-----------+-------+-------+</code></pre><p>From <strong>View and restore</strong> in the <strong>Actions</strong> menu of our application, we can check the details of the application protection, and the list of available restore points.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/5e/5e4dc9e08a9e4a503df169eb1b3195ae.png" role="button" title="PatricU_30-1754662128311.png" alt="PatricU_30-1754662128311.png" width="793" /></span></p><p>We see three restore points, as meanwhile the schedule kicked in an created the first scheduled backup.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/64/642fd2e89e387b07f3a7000ffe04dd54.png" role="button" title="PatricU_31-1754662150427.png" alt="PatricU_31-1754662150427.png" width="502" /></span></p><p>This can also be seen with the CLI, showing the three available backups and snapshots.</p><pre><code>$ tridentctl-protect get backup -n minio
+-------------------------------------+------------------+----------------+-----------+-------+--------+
|                NAME                 |       APP        | RECLAIM POLICY |   STATE   | ERROR |  AGE   |
+-------------------------------------+------------------+----------------+-----------+-------+--------+
| ad-hoc-backup-drpz2so916            | minio-bjo9nkv54p | Retain         | Completed |       | 27m27s |
| baseline-transfer-backup-9hviqxzflt | minio-bjo9nkv54p | Retain         | Completed |       | 1h4m   |
| custom-eb7d6-20250724090012         | minio-bjo9nkv54p | Retain         | Completed |       | 12m28s |
+-------------------------------------+------------------+----------------+-----------+-------+--------+
$ tridentctl-protect get snapshot -n minio
+---------------------------------------------+------------------+----------------+-----------+-------+--------+
|                    NAME                     |       APP        | RECLAIM POLICY |   STATE   | ERROR |  AGE   |
+---------------------------------------------+------------------+----------------+-----------+-------+--------+
| backup-e2f70988-8b2e-4d6f-9ee0-332f186a8c72 | minio-bjo9nkv54p | Delete         | Completed |       | 27m30s |
| backup-e97a09a2-7b1f-4296-b718-b8c3f648a29f | minio-bjo9nkv54p | Delete         | Completed |       | 1h4m   |
| custom-eb7d6-20250724090012                 | minio-bjo9nkv54p | Delete         | Completed |       | 12m31s |
+---------------------------------------------+------------------+----------------+-----------+-------+--------+</code></pre><h1 id="toc-hId-1218729116">Restore application</h1><p>Now we&rsquo;re all set to test a restore of the <span style="font-family: andale mono,times;">minio</span> sample application. Out of the many possible restore (and failure) scenarios, let&rsquo;s see in more detail how we can recover our application to another cluster in case of a failure of the original cluster hosting the application.</p><p>For a realistic test scenario, let&rsquo;s first simulate a cluster failure by stopping the Trident protect connector on the cluster. We scale down the <span style="font-family: andale mono,times;">trident-protect-connector</span> deployment to zero and wait for the associated pod to stop.</p><pre><code>$ kubectl -n trident-protect scale deployment.apps/trident-protect-connector --replicas=0
deployment.apps/trident-protect-connector scaled
 
$ kubectl get all -n trident-protect
NAME                                                               READY   STATUS    RESTARTS   AGE
pod/autosupportbundle-5cdc2a2f-4317-4eed-9c59-6f98d3bf0727-k58xh   1/1     Running   0          9h
pod/trident-protect-controller-manager-78f47d8788-fnlqs            2/2     Running   0          25h
 
NAME                                                         TYPE        CLUSTER-IP      EXTERNAL-IP   PORT(S)    AGE
service/tp-webhook-service                                   ClusterIP   10.102.57.222   &lt;none&gt;        443/TCP    25h
service/trident-protect-controller-manager-metrics-service   ClusterIP   10.103.73.197   &lt;none&gt;        8443/TCP   25h
 
NAME                                                 READY   UP-TO-DATE   AVAILABLE   AGE
deployment.apps/trident-protect-connector            0/0     0            0           25h
deployment.apps/trident-protect-controller-manager   1/1     1            1           25h
 
NAME                                                            DESIRED   CURRENT   READY   AGE
replicaset.apps/trident-protect-connector-677554db48            0         0         0       25h
replicaset.apps/trident-protect-controller-manager-78f47d8788   1         1         1       25h
 
NAME                                                               STATUS    COMPLETIONS   DURATION   AGE
job.batch/autosupportbundle-5cdc2a2f-4317-4eed-9c59-6f98d3bf0727   Running   0/1           9h         9h</code></pre><p>This leads to NetApp Backup and Recovery losing the communication to the K8s cluster. After some minutes, our cluster goes into the "Removed" state in NetApp Backup and Recovery.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/a6/a6dd8e386b22e6f4f15123abc27349ad.png" role="button" title="PatricU_32-1754662288883.png" alt="PatricU_32-1754662288883.png" width="673" /></span></p><p>Luckily our application is protected already, and we can easily initiate a restore to another cluster. We select again <strong>View and restore</strong> from the <strong>Actions</strong> menu of the <span style="font-family: andale mono,times;">minio</span> application in the list of applications.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/d6/d66e515fe1f09792245f46828b3ca4ff.png" role="button" title="PatricU_33-1754662320050.png" alt="PatricU_33-1754662320050.png" width="793" /></span></p><p>From the list of available restore points, we select the restore point from which we want to restore form and select <strong>Restore</strong> from its associated <strong>Actions</strong> menu.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/0c/0c72b565bfe0baeb95494dbcfb0bbe1e.png" role="button" title="PatricU_34-1754662341571.png" alt="PatricU_34-1754662341571.png" width="793" /></span></p><p>As the local snapshots are not available anymore due to the cluster failure, we select to restore from object store and choose the destination cluster from the list of managed clusters.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/ae/ae00c669958d29e8b4e0b27a30fe43e0.png" role="button" title="PatricU_35-1754662394169.png" alt="PatricU_35-1754662394169.png" width="793" /></span></p><p>We choose <span style="font-family: andale mono,times;">minio-dr</span> as destination namespace on the destination cluster and select <strong>Next</strong>.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/63/63abb0d18bf7741926ed6493ee39bf41.png" role="button" title="PatricU_36-1754662418721.png" alt="PatricU_36-1754662418721.png" width="793" /></span></p><p>As we want to restore the complete application, we select <strong>Restore all resources </strong>and then <strong>Next</strong>.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/8c/8cc079bb96e2ad52554a3092ed683097.png" role="button" title="PatricU_37-1754662436894.png" alt="PatricU_37-1754662436894.png" width="793" /></span></p><p>Finally, we select to restore to the default storage class on the destination cluster and start the restore by selecting <strong>Restore</strong>.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/0a/0a0e38b803c2fb7f4bc73593d5808654.png" role="button" title="PatricU_38-1754662457885.png" alt="PatricU_38-1754662457885.png" width="793" /></span></p><p>We can also track the progress of the restore job, which finishes after some minutes.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/6f/6f965386f299c59be6e25db9ab7e5779.png" role="button" title="PatricU_39-1754662508955.png" alt="PatricU_39-1754662508955.png" width="793" /></span></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/54/5468b9e915917447f03fa78b89ff6e47.png" role="button" title="PatricU_40-1754662522966.png" alt="PatricU_40-1754662522966.png" width="793" /></span></p><p>Finally, we confirm that the <span style="font-family: andale mono,times;">minio</span> application is up and running on the destination cluster in the <span style="font-family: andale mono,times;">minio-dr</span> namespace.</p><pre><code>$ kubectl get all,pvc -n minio-dr --context sks3794-admin@sks3794
NAME                               READY   STATUS             RESTARTS       AGE
pod/minio-b6b84f46c-v7cxw          1/1     Running            0              4h42m
pod/minio-console-cb99559c-td8f4   1/1     Running            0              4h42m
 
NAME                    TYPE        CLUSTER-IP       EXTERNAL-IP   PORT(S)    AGE
service/minio           ClusterIP   10.103.102.117   &lt;none&gt;        9000/TCP   4h42m
service/minio-console   ClusterIP   10.108.79.13     &lt;none&gt;        9090/TCP   4h42m
 
NAME                            READY   UP-TO-DATE   AVAILABLE   AGE
deployment.apps/minio           1/1     1            1           4h42m
deployment.apps/minio-console   1/1     1            1           4h42m
 
NAME                                     DESIRED   CURRENT   READY   AGE
replicaset.apps/minio-b6b84f46c          1         1         0       4h42m
replicaset.apps/minio-console-cb99559c   1         1         1       4h42m
 
NAME                          STATUS   VOLUME                                     CAPACITY   ACCESS MODES   STORAGECLASS      VOLUMEATTRIBUTESCLASS   AGE
persistentvolumeclaim/minio   Bound    pvc-d2bbdd4f-9fe1-4fa3-a89d-8c65264b400e   8Gi        RWO            ontap-vsim4-nas   &lt;unset&gt;                 4h42m</code></pre><h1 id="toc-hId--1333427845">Conclusion and call to action</h1><p>NetApp has introduced a preview of its NetApp Backup and Recovery solution for Kubernetes workloads, enhancing the protection of Kubernetes-based containers. This new solution offers a unified management console, leveraging NetApp SnapMirror for efficient backups and restores, and integrates seamlessly with NetApp Trident software for streamlined operations. Key features include centralized management, structured incremental backups, and the ability to restore applications across different clusters and namespaces.</p><p>This blog post provides a detailed guide on setting up protection policies, protecting, and restoring Kubernetes applications using NetApp Backup and Recovery. It includes step-by-step instructions for configuring the test environment, discovering Kubernetes clusters, creating applications, and implementing protection policies. Additionally, it covers manual and on-demand backups, as well as restoring applications to different clusters in case of failures.</p><p>Ready to elevate your data protection strategy? Dive into the comprehensive guide and start leveraging NetApp Backup and Recovery for your Kubernetes workloads today! Ensure your applications are protected against any failures with seamless, efficient, and unified backup solutions. Get started now and experience the future of data protection with NetApp Backup and Recovery!</p><p>Complete <a href="https://forms.office.com/Pages/ResponsePage.aspx?id=oBEJS5uSFUeUS8A3RRZbOojtBW63mDRDv3ZK50MaTlJUNjdENllaVTRTVFJGSDQ2MFJIREcxN0EwQi4u" target="_blank" rel="nofollow noopener noreferrer">this form</a> to gain access to the preview program. Upon completing the form, you'll gain access to the service and can start exploring its features and providing feedback within 48-72 hours.&nbsp;</p></div>]]>
        </description>
    </item>
    <item>
        <title>Monitoring SnapMirror for AWS FSx for ONTAP with NetApp Data Infrastructure Insights</title>
        <link>https://community.netapp.com/community/discussion/461628/monitoring-snapmirror-for-aws-fsx-for-ontap-with-netapp-data-infrastructure-insights</link>
        <pubDate>Mon, 23 Jun 2025 13:00:00 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>mark_stugard</dc:creator>
        <guid isPermaLink="false">461628@/community/discussions</guid>
        <description><![CDATA[<div><p>In today&rsquo;s cloud-centric landscape, organizations rely heavily on data replication technologies to ensure business continuity, disaster recovery, and high availability. SnapMirror, a powerful data replication feature from NetApp, plays a vital role in replicating data across ONTAP environments &mdash; including AWS FSx for NetApp ONTAP (FSxN). But even the most robust replication strategy needs deep visibility and proactive monitoring to deliver true reliability. That&rsquo;s where <strong>NetApp Data Infrastructure Insights&nbsp;</strong>comes into play.</p><h1 id="toc-hId-1903929710">&nbsp;</h1><h1 id="toc-hId--648227251"><strong>The Challenge with Data Replication in the Cloud</strong></h1><p>SnapMirror is designed to efficiently replicate data between ONTAP systems, whether on-premises or in the cloud. With FSxN, you get all the benefits of ONTAP in a fully managed AWS service. However, as your cloud footprint grows and data volumes scale, it becomes increasingly difficult to track:</p><ul><li>The health of each replication relationship</li><li>Lag times between source and destination</li><li>Transfer efficiency and throughput</li><li>Failover readiness</li></ul><p>Traditional monitoring tools often lack granular insight into SnapMirror operations, especially across hybrid or cloud-native environments. This blind spot can lead to missed SLAs, data inconsistency, or recovery delays.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/3c/3ce7737058eea860bc8518409306394e.png" role="button" title="NetApp SnapMirror topologies.jpg.png" alt="NetApp SnapMirror topologies.jpg.png" width="1600" /></span></p><h2 id="toc-hId-898069579">&nbsp;</h2><h2 id="toc-hId--1654087382"><strong>Enter NetApp Data Infrastructure Insights</strong></h2><p><strong>NetApp Data Infrastructure Insights&nbsp;</strong>is a modern observability solution that delivers real-time visibility across hybrid cloud multi-vendor environments. By monitoring FSxN with Data Infrastructure Insights, you gain full-stack awareness of your SnapMirror relationships with powerful dashboards, proactive alerts, and historical analytics.</p><h2 id="toc-hId-88722953"><strong>Key Benefits of Monitoring SnapMirror</strong></h2><h3 id="toc-hId-1635019783"><strong>1. Proactive Alerting for Replication Issues</strong></h3><p>Data Infrastructure Insights continuously monitors SnapMirror states &mdash; idle, transferring, broken-off, or failed &mdash; and triggers alerts when anomalies arise. This helps teams respond faster to issues before they impact recovery objectives.</p><h3 id="toc-hId--917137178"><strong>2. Visualize Lag and Transfer Metrics</strong></h3><p>Track replication lag time in real-time, across all volumes and relationships. Dashboards make it easy to spot underperforming links or bottlenecks, helping you take corrective actions quickly.</p><h3 id="toc-hId-825673157"><strong>3. Correlation with Infrastructure Metrics</strong></h3><p>Data Infrastructure Insights doesn't just stop at SnapMirror &mdash; it correlates replication performance with underlying FSxN storage health, network latency, and IOPS trends. This holistic view enables smarter troubleshooting and root cause analysis.</p><h3 id="toc-hId--1726483804"><strong>4. Simplified Compliance and Reporting</strong></h3><p>With built-in historical analysis and exportable reports, Data Infrastructure Insights helps document replication SLAs and demonstrate recovery readiness &mdash; a must for audits, compliance, and disaster recovery planning.</p><h3 id="toc-hId-16326531"><strong>5. Scalable Insights for Hybrid and Multi-Cloud</strong></h3><p>Whether you're replicating from on-prem ONTAP to FSxN, or FSxN to FSxN across regions, Data Infrastructure Insights provides a single pane of glass to monitor it all. This unified visibility is essential for modern, distributed data architectures.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/6f/6f3710a9403afc15e0af875b5ba3be08.png" role="button" title="Screenshot 2025-05-23 at 3.50.08&#8239;PM.png" alt="Screenshot 2025-05-23 at 3.50.08&#8239;PM.png" width="2516" /></span></p><h1 id="toc-hId-342910999"><strong><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/d6/d62c1fda05276737c437c4a4150b3b8c.png" role="button" title="Screenshot 2025-05-23 at 3.55.09&#8239;PM.png" alt="Screenshot 2025-05-23 at 3.55.09&#8239;PM.png" width="1882" /></span></strong></h1><h1 id="toc-hId-2085721334">&nbsp;</h1><h1 id="toc-hId--466435627"><strong>Final Thoughts</strong></h1><p>As cloud adoption accelerates, ensuring the reliability and performance of data replication is more critical than ever. Monitoring SnapMirror with&nbsp;<strong>Data Infrastructure Insights</strong> empowers teams to move from reactive to proactive operations &mdash; improving data resilience, reducing downtime, and enhancing operational confidence.</p><h4 id="toc-hId-180487927"><strong>Ready to get started?</strong></h4><p>Reach out to your NetApp representative or <a href="https://www.netapp.com/forms/cloud-insights-demo-request/" target="_blank" rel="noopener noreferrer nofollow">request a demo</a> to learn how you can integrate FSxN visibility into your observability strategy.</p></div>]]>
        </description>
    </item>
    <item>
        <title>best practice for disk firmware on ONTAP 8.0.2 P3 7-mode</title>
        <link>https://community.netapp.com/community/discussion/35518/best-practice-for-disk-firmware-on-ontap-8-0-2-p3-7-mode</link>
        <pubDate>Tue, 11 Sep 2012 02:26:11 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>mdvillanueva</dc:creator>
        <guid isPermaLink="false">35518@/community/discussions</guid>
        <description><![CDATA[<div><p>Hello Experts,</p><p>We are preparing to upgrade to 8.1.1 7-mode. All of our SAS disks need disk firmware upgrade, so I downloaded X412_S15K7560A15.zip.</p><p>inside /etc/disk_fw I see X412_S15K7560A15.lod.</p><p>I know have to to turn this on "options raid.background_disk_fw_update.enable"</p><p>I can access \etc\disk_fw via CIFS.</p><p>Should I move the&nbsp; X412_S15K7560A15.zip inside \etc/disk_fw and then unzip inside OR</p><p>unzip X412_S15K7560A15.zip in a Windows machine and then copy-paste inside \etc\disk_fw? </p><p>Both steps would overwrite the existing LOD file, correct?</p><p>Or am I approaching this all wrong?</p><p>Thanks,</p><p>Maico</p></div>]]>
        </description>
    </item>
    <item>
        <title>Optimizing Game Development in AWS with Amazon FSx for NetApp ONTAP</title>
        <link>https://community.netapp.com/community/discussion/461254/optimizing-game-development-in-aws-with-amazon-fsx-for-netapp-ontap</link>
        <pubDate>Tue, 03 Jun 2025 08:22:53 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>h0lmstr0m</dc:creator>
        <guid isPermaLink="false">461254@/community/discussions</guid>
        <description><![CDATA[<div><p><span style="font-size: medium;">The landscape of modern game development </span>is evolving rapidly and becoming more complex than ever before. Studios are pushing creative and technical boundaries to deliver increasingly rich and immersive player experiences. However, this evolution brings significant infrastructure challenges. Managing sprawling codebases, massive libraries of high-fidelity assets, lengthy compile and build times, and coordinating distributed teams worldwide place enormous strain on the development pipeline.</p><p>Compounding these technical challenges are security concerns, especially when working with external partners, and the high financial costs of maintaining robust, high-performance infrastructure. Traditional on-premises environments struggle to keep pace. They lack the elasticity, automation, and scalability that today&rsquo;s demanding workflows require. Moreover, shortages in IT resources, scarcity of skilled personnel, and global supply chain disruptions make on-premises infrastructure maintenance increasingly impractical.</p><p><em><span style="font-size: large;"><strong>This reality has driven a significant shift: game studios are moving to the cloud</strong></span></em></p><p>Cloud platforms&mdash;particularly AWS&mdash;offer a vast array of innovation-enabling services, built-in resiliency, and the ability to dynamically scale compute and storage resources based on fluctuating developer and player demand. This shift unlocks opportunities to optimize game development end-to-end: improving performance, enabling seamless collaboration, and drastically reducing time to market.</p><p>But to truly harness the cloud&rsquo;s potential, game studios need more than just scalable compute&mdash;they require a cloud-native file system that delivers enterprise-grade performance, security, and data management capabilities that they experienced with on-prem infrastructure.</p><p><span style="font-size: xx-large;"><span data-teams="true">Game Studios are Building with Amazon FSx for NetApp ONTAP</span></span></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/62/6285c44f82a475bbf4f6db38c9c426ec.png" width="222" height="222" role="button" title="FSxN Logo.png" alt="FSxN Logo.png" /></span></p><p>Amazon FSx for NetApp ONTAP is a fully managed AWS service that integrates AWS&rsquo;s scalable infrastructure with NetApp&rsquo;s industry-leading ONTAP file system <strong>delivered as a native AWS service</strong> just like AWS&rsquo;s other native data storage services. It is purpose-built to empower developers to streamline and accelerate their entire development pipeline&mdash;from asset ingestion and code management to build automation and playtesting. Additionally, it can directly tackle core infrastructure challenges in game development, enabling studios to innovate faster, scale smarter, and reduce costs, which is a perfect fit for game development.</p><p><span style="font-size: large;"><strong>In this blog, we'll explore:</strong></span></p><ul><li>The unique challenges of game development in the cloud.</li><li>How Amazon FSx for NetApp ONTAP addresses these through real-world use cases:</li><li><strong>Game code repositories:</strong> How AAA studios use FSxN with Perforce Helix Core (P4).</li><li><strong>Game build pipeline hydration:</strong> How FSxN accelerates build hydration and reduces costs.</li><li><strong>Developer Virtual Desktop Infrastructure (VDI):</strong> How FSxN enhances workspace provisioning efficiency.</li></ul>How to start optimizing game development with FSx for ONTAP:<ul><li>Manual deployment via AWS Console</li><li>Automation using the AWS Cloud Game Development Toolkit</li><li>Advanced workload management with NetApp BlueXP Workload Factory</li></ul><h3 id="toc-hId-1510898945"><span style="font-size: xx-large;"><strong>Bridging the DevOps Gap in Game Development with FSx for NetApp ONTAP</strong></span></h3><p>Traditional software development benefits from mature DevOps workflows supported by toolchains like Jenkins, GitHub Actions, Gradle, and Webpack. These tools thrive on standardized, repeatable cycles with large active communities.</p><p>Game development, however, operates on a different scale and complexity. Massive codebases and vast asset libraries are typically managed via Perforce P4, a version control system designed for scalability and performance. Once developers submit changes, continuous integration and delivery (CI/CD) systems trigger automated build and test processes that rely on ephemeral build agents. These agents spin up with the necessary tools, execute jobs, and terminate upon completion.</p><p>The build artifacts in game development&mdash;compiled code, 3D models, audio files, textures&mdash;are enormous and complex. Testing often extends beyond automation to include human playtesting, adding further resource demands. Unlike standard software, games target multiple platforms simultaneously&mdash;PC, consoles, mobile&mdash;requiring resilient, high-throughput infrastructure capable of handling massive workloads without bottlenecks or failure.</p><p>This complexity creates a <strong>DevOps gap</strong>&mdash;both on-prem and traditional cloud data infrastructure often cannot efficiently support the performance, cost, and flexibility demands of game development pipelines.</p><p><span style="font-size: large;"><strong>Amazon FSx for NetApp ONTAP is purpose-built to addresses this gap in the cloud for game development by providing:</strong></span></p><ul><li><span style="font-size: large;"><strong>High throughput and low latency:</strong></span> Accelerate build pipelines by delivering shared storage that supports fast, concurrent access to instant thin clones of code depots across distributed build agents.</li><li><span style="font-size: large;"><strong>Cost savings:</strong> </span>The combination of advanced deduplication and thin cloning reduce data duplication and storage footprint for build pipeline hydration, yielding up to 70% savings on infrastructure spend.</li><li><span style="font-size: large;"><strong>Data protection:</strong> </span>Native snapshotting and cross-region replication improve backup and disaster recovery capabilities while greatly improving data resilience and availability for game data with native high-available architectures.</li><li><span style="font-size: large;"><strong>Simplified management:</strong></span> Centralized control and consistency across applications and platforms reduce operational complexity.</li><li><span style="font-size: large;"><strong>Global collaboration:</strong></span> FSx for ONTAP supports distributed teams by delivering high-performance, consistent, and centralized data access across multiple locations ensuring the data developers crave is where they need it when they need it.</li><li><span style="font-size: large;"><strong>Scalability and automation:</strong></span>&nbsp;Flexible and elastic infrastructure that grows with your project demands, reducing operational overhead and can be automated via extensive and easily accessible APIs.</li></ul><p>For game studios specifically, FSx for ONTAP becomes a strategic enabler&mdash;helping close the tooling gap while aligning infrastructure with the creative and technical realities of modern game production. To do this, FSx for ONTAP leverages:</p><ul><li><span style="font-size: large;"><strong>Unique Instantaneous Thin Cloning:</strong></span> Create writable, point-in-time copies of datasets instantly without full data duplication, ideal for test environments or rapid iteration. For game builds, this means creating near-instantaneous, space-efficient copies of large game builds and asset libraries, drastically reducing storage costs and eliminating unnecessary data duplication.</li><li><span style="font-size: large;"><strong>Deduplication &amp; Compression:</strong></span> Reduce redundant data storage and optimize disk usage.</li><li><span style="font-size: large;"><strong>Enterprise Grade Data Protection</strong></span></li><li><span style="font-size: medium; color: #333333;"><strong>Snapshots &amp; Backup:</strong></span> Instant, space-efficient point-in-time copies support rapid recovery.</li><li><strong>Resiliency and security:</strong> Built-in snapshotting, replication, and cross-region capabilities protect your most valuable assets and minimize downtime.</li></ul><span style="font-size: large;"><strong>Efficient Cross-region Replication:</strong> </span>Sync data between AWS regions or availability zones for disaster recovery while maintaining storage efficiency.<span style="font-size: large;"><strong>Data Auto-tiering:</strong></span><span> Data is automatically moved between SSD and capacity tiers based on access patterns, balancing cost and performance.</span><p>Together, these capabilities significantly streamline game development pipelines by enabling faster iteration, lowering costs, and enhancing code protection. By reducing end-to-end build and test cycles from hours to minutes, teams can accelerate time-to-market and improve Mean Time To Resolution (MTTR), allowing for quicker, more frequent, and higher-quality releases. Advanced cloning and data efficiency technologies help cut storage costs by up to 70%, boosting return on investment (ROI) and lowering total cost of ownership (TCO). Meanwhile, robust security and resiliency features protect critical intellectual property, ensuring rapid recovery and minimal downtime in the event of a failure.</p><p>This can all be realized in three strategically targeted aspects of the complete game development pipeline:</p><ol><li><span style="font-size: large;"><strong>Game Code and Data Version Control Repositories</strong></span></li><li><span style="font-size: large;"><strong>Game Build Pipeline Hydration</strong></span></li><li><span style="font-size: large;"><strong>Game Developer VDI Workspace Provisioning</strong></span></li></ol><p>It's clear, game development is evolving - here's how some of the world's leading game studios are rethinking and optimizing core aspects of their game development pipelines with FSx for ONTAP at the center:</p><h3 id="toc-hId--1041258016"><span style="font-size: xx-large;"><span><strong>Use Case 1: Optimizing Game Code Repositories with FSx for NetApp ONTAP</strong></span></span></h3><p>When considering the game development process as a whole, creating and building a game starts with an idea made into code. Eventually, some of these games become core to critical success at their game studios necessitating the use of optimized solutions to manage the life of their award winning titles. Perforce P4 (formerly known as Helix Core) is the industry-standard version control system for game development, favored for its ability to handle massive critical codebases and complex branching workflows.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/9e/9ebd69ba161b08dcd0411e6cb02b6df0.jpg" width="221" height="118" role="button" title="logo-p4-reg-600x319-e307f76.jpg" alt="logo-p4-reg-600x319-e307f76.jpg" /></span></p><p>According to a 2023 TechValidate survey:</p><ul><li>80% agree P4 is the most scalable, high-performance version control system</li><li>82% rate Helix Core&rsquo;s scalability as "Best in Class" or "Significantly Better" than alternatives</li><li>100% reported ROI within 1-2 years of deployment</li></ul><p>One of the major benefits of using Perforce P4 is its performance. P4 only preserves changes of updates in text files. For binary files, it compresses each version and saves them as chunks, known as versioned files. Even when a large development project increases the number of files or commits, the size of the repository (hxdepot) is not prone to explode. It also has a mechanism that works faster even if clients are physically away from the master server. Therefore, Perforce is used for version controlling not only text files, but also large binary files, such as images.</p><p>Modernizing P4 infrastructure by migrating these repositories and workspaces to the cloud is a natural step&mdash;but it brings challenges around cost, resiliency, and data flexibility due to the sheer size of game development data.</p><p>FSx for ONTAP extends the realized benefits of on-prem enterprise storage to Perforce P4 in AWS, enabling:</p><p><span style="font-size: large;"><strong>Flexibility, Scalability, and Elasticity </strong></span>as a well-architected AWS native service, FSx for ONTAP filesystems can be easily deployed in multiple flexible architectures for multiple P4 server types, scaled-out up to 72GBps of throughput, 2,400,000 IOPS, and ~1PB for a single namespace.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/10/10745f28d9dcd09720869de565febde9.png" width="398" height="477" role="button" title="P4_SAZ_Architecture.png" alt="P4 on FSx for ONTAP HA Single-AZ" /><span>P4 on FSx for ONTAP HA Single-AZ</span></span></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/fd/fde38d33c030ed08140159a25868f961.png" width="610" height="406" role="button" title="P4_MAZ_Architecture.png" alt="P4 deployed on FSx for ONTAP HA Multi-AZ" /><span>P4 deployed on FSx for ONTAP HA Multi-AZ</span></span></p><p>Furthermore, FSx for ONTAP can be easily and quickly adjusted to expand storage, throughput, and IOPS from within the AWS console, AWS and ONTAP CLI&rsquo;s, various available APIs, or other available tools we&rsquo;ll visit later in this article.</p><p><span style="font-size: large;"><strong>Up to 70% reduction in recurring storage costs</strong></span> via data deduplication, compression, compaction, and strategically leveraging FSx for ONTAP&rsquo;s instant thin cloning in build processes. These efficiencies are maintained when leveraging FSx for ONTAP backups and replication for data protection. Data tiering can also be enabled for disaster recovery replicas that are infrequently used, even further reducing total data footprint.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/ac/ac52c336aada0585852751d21fa9c315.png" width="649" height="712" role="button" title="P4 Cross AZ Efficiencies.png" alt="Cross-AZ Data Footprint Reduction" /><span>Cross-AZ Data Footprint Reduction</span></span></p><p><span style="font-size: large;"><strong>Enhanced data protection and resiliency with improved RPO (Recovery Point Objective) and RTO (Recovery Time Objective) </strong></span>ensuring rapid recovery from failures or data corruption through:</p><ul><li><strong>Flexible High Availability:</strong> Both Single-AZ and Multi-AZ deployments feature an HA pair of nodes that make a single filesystem. Single-AZ is a 2-node cluster in a single AZ and protects against a node failure in a single AZ. Multi-AZ is a 2-node cluster spread across 2 AZs and further protects from a single AZ failure.</li><li><strong>Advanced Snapshot Technology:</strong> Fast, space-efficient point-in-time backups which are also integrated into AWS and FSx Backups.</li><li><strong>Optimized Disaster Recovery:</strong> Cross-region replication (commonly known as SnapMirror on FSx for ONTAP), backups through integration with AWS and FSx Backup, and data tiering capability to balance cost and speed by tiering cold data to a cheaper and lower class storage medium.</li></ul><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/89/89226f5edea171e4e7940bfbbc2c0ce1.png" role="button" title="P4_DR_Architecture.png" alt="P4 on FSx for ONTAP HA Multi-AZ replicating to P4 Edge/Replica on FSx for ONTAP HA Single-AZ leveraging data tiering for further cost reduction." width="1783" /><span>P4 on FSx for ONTAP HA Multi-AZ replicating to P4 Edge/Replica on FSx for ONTAP HA Single-AZ leveraging data tiering for further cost reduction.</span></span></p><p><strong><span style="font-size: large;">Global availability and consistency</span></strong>&nbsp;supporting distributed teams with centralized control. Since FSx for ONTAP is a native AWS service, it is consistently available in multiple AWS regions capable of supporting multiple Perforce P4 server types&nbsp;and replication across all regions where FSx for ONTAP is available.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/09/09e824475ef75203e12db3444e62e530.png" role="button" title="P4 Global Availability.png" alt="P4 Global Availability on FSx for ONTAP" width="1902" /><span>P4 Global Availability on FSx for ONTAP</span></span></p><p><span style="font-size: large;"><strong>Critical high performance, low latency, and high throughput </strong></span>that game development hungers for. AAA studios have demonstrated significant performance gains by running Perforce on FSx for ONTAP in AWS by reducing latency and accelerating developer productivity while cutting infrastructure costs.</p><p>To achieve the highest performance possible, iSCSI (block storage protocol) on FSx for ONTAP for all P4 server volumes (/hxmetadata, /hxlogs, and /hxdepots) is considered the best practice. However, NFS can also be considered for the /hxdepots volume as a balanced performance vs. manageability option.</p><p>For a brief perspective on iSCSI vs. NFS performance differences, please consider the following analysis that leveraged Perforce&rsquo;s general P4 multi-sync benchmark while testing multi-P4 client simultaneous multi-syncs:</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/ef/ef201f6251c68b96de7295c00bda6d4b.png" role="button" title="P4 Performance - Total Client Throughput.png" alt="P4 Multi-Sync Benchmark Total Client Throughput" width="1998" /><span>P4 Multi-Sync Benchmark Total Client Throughput</span></span></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/a0/a06dd79b8aaa2edc90eb4dd5eeac3328.png" role="button" title="P4 Performance - Total Client IOPS.png" alt="P4 Multi-Sync Benchmark Total Client IOPS" width="2194" /><span>P4 Multi-Sync Benchmark Total Client IOPS</span></span></p><p>For simultaneous multi-syncs up to 20 clients, the completion time was significantly better with iSCSI (block) storage. As we increased the number of clients to 150, the completion time was determined by network throughput, that is, the actual time it takes to pull the files into local client workspaces. In this case, iSCSI continued to outperform NFS with consistency.</p><p>However, regardless of which protocol is chosen for the /hxdepots volume, it is recommended to run multiple iSCSI or NFS nconnect sessions to achieve higher levels of throughput. This allows data to be transferred in parallel over multiple connections, thereby increasing the aggregate bandwidth and reducing the time it takes to complete I/O-intensive operations such as P4 syncs and submits. For example, the following configuration was used for the NFS testing shown above:</p><pre><code>-o nfsvers=3,nconnect=8,local_lock=all
-n node.session.nr_sessions -v 8</code></pre><h3 id="toc-hId-701552319"><span style="font-size: xx-large;"><strong>Use Case 2: Accelerating Game Build Pipeline Hydration and Full Optimization</strong></span></h3><p>Hydrating build pipelines means populating the build environment with the latest game code and assets after changes are committed&mdash;critical for generating up-to-date builds for development, testing, and release.</p><p>Because game assets and build artifacts can reach terabytes in size, hydration can become a major bottleneck for game development studios. Copying large datasets consumes time and storage, slowing iteration and inflating costs.</p><p>FSx for ONTAP&rsquo;s shared, high-throughput storage solves these problems by:</p><ul><li>Providing <strong>thin, instantaneous, and fully writable environments based on instant snapshots</strong> for rapid and cost effective provisioning.</li><li>Creating new build environments in <strong>seconds</strong> with near-zero capacity overhead.</li><li>Reducing build pipeline costs by up to 70% through thin cloning and data efficiency.</li></ul><p>This results in:</p><ul><li>Faster build times and shorter MTTR.</li><li>Enhanced collaboration with immediate access to the latest builds.</li><li>Drastically lower infrastructure costs.</li></ul><p>An award-winning AAA game development studio conducted its own analysis on cost savings between their current game build hydration configuration that leverages EBS vs. FSx for ONTAP leveraging their own game data for three distinct projects and achieved the following savings for Game Build Hydration with FSx for ONTAP:</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/0a/0a088be7408a1f8a3ee2a66b15be94cf.png" role="button" title="Game Build - AAA Studio Cost Savings Analysis.png" alt="Across three of their major game development projects, 80% storage savings was realized which translated to 68.3% in cost savings with FSx for ONTAP thin clones for build hydration." width="3355" /><span>Across three of their major game development projects, 80% storage savings was realized which translated to 68.3% in cost savings with FSx for ONTAP thin clones for build hydration.</span></span></p><p>While these cost savings are already drastic, FSx for ONTAP could be leveraged across the whole pipeline to reap further cost savings outside of just the build hydration portion of the pipeline as shown in the following sample architecture:</p><p><strong><span style="font-size: large;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/30/30d03584482b11b79d1e9519174fa658.png" role="button" title="Game Build Hydration Architecture.png" alt="Ephemeral Game Build Hydration with FSx for NetApp ONTAP" width="2046" /><span>Ephemeral Game Build Hydration with FSx for NetApp ONTAP</span></span></span></strong></p><p>Here's how the sample architecture for optimizing the game build pipeline works:</p><ol start="1"><li><span style="font-size: large;"><strong> Build Trigger &amp; Environment Provisioning</strong></span><br />A build is triggered either manually via a Self-Service Portal or automatically via Perforce or code flag. Orchestration (e.g., Jenkins, TeamCity, Ansible, Terraform, Horde) provisions build nodes using a custom AMI (built with Packer) that includes all necessary tooling (e.g., .NET SDK, msbuild, compilers, gcc, etc.).&nbsp;</li></ol><ol start="2"><li><span style="font-size: large;"><strong>"Syncer" Client Selection &amp; Preparation</strong></span><br />Orchestration monitors persistent lightweight instances called <strong>&ldquo;Syncer&rdquo; clients</strong>, which maintain replicated Perforce (P4) data from the Build-Edge. Each "Syncer" represents a unique workspace/changelist and mounts its primary volume from FSx for ONTAP, allowing persistent high-performance access and instant thin-clone capability. Once an available "Syncer" is found, it is synced to the <strong>latest requested changelist</strong>, enabling near-instant readiness due to the already-updated replica from Build-Edge.</li></ol><ol start="3"><li><span style="font-size: large;"><strong> Volume Cloning for Build Execution</strong></span><br />After the "Syncer" is updated, which only requires delta change updates, orchestration clones its volume using <strong>FSx for ONTAP thin clones</strong>, tied to the specific changelist. This clone is mounted to the already instantiated build node, providing access to the exact source code snapshot. Builds may read/write to this volume with minimal overhead due to snapshot-based delta management.</li></ol><ol start="4"><li><span style="font-size: large;"><strong> Post-Build Output &amp; Distribution</strong></span><br />Build artifacts are written to <strong>S3 + CloudFront</strong> or back to <strong>FSx for ONTAP</strong>, depending on whether the use case involves developer collaboration (caching and testing), intermediate asset reuse, or external distribution to consumer platforms.</li></ol><ol start="5"><li><span style="font-size: large;"><strong> Teardown &amp; Reset for Next Build</strong></span><br />Once the build is complete the builders are destroyed, their FSx for ONTAP clones are deleted, and the persistent&nbsp;"Syncer" clients remain, but are updated with the latest P4 data and reset for the next changelist request.</li></ol><p><strong><span style="font-size: large;">&rarr; This cycle repeats efficiently for every new build request.</span></strong></p><p>As shown, leveraging instant thin clones on FSx for ONTAP vs. other data services results in a drastic cost savings by reducing data requirements in the game build pipeline. Furthermore, because there is less data to copy, build hydration is significantly faster drastically reducing game builds.</p><p><span style="font-size: xx-large;"><strong>Use Case 3: Optimizing Developer VDI Environments</strong></span></p><p>Developers often require isolated Virtual Desktop Infrastructure (VDI) workspaces provisioned with the latest code and assets. Even further, these VDI workspaces need to travel with the developer, meaning the data needs to be globally mobile and consistent across regions. Traditional approaches use full snapshots, resulting in enormous data duplication and slow workspace creation.</p><p>Much like Build Hydration, because VDI orchestration would leverage similar code and instant thin cloning, FSx for ONTAP enables:</p><ul><li><strong><span style="font-size: large;">Accelerated iteration:</span></strong> Workspace cloning from base volumes with FlexClone technology.</li><li><span style="font-size: large;"><strong>Massive cost savings:</strong></span> Reduce copies from thousands of FULL snapshots to a handful of thin cloned volumes.</li><li><span style="font-size: large;"><strong>Faster time to productivity:</strong></span> Reduces provisioning times from hours to minutes since FSx for ONTAPs cloning is a unique thin-provisioned cloning technology.</li><li><span style="font-size: large;"><strong>Performance advantages:</strong></span> Provisioned file system-level performance outperforms individually provisioned native volumes.</li></ul><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/73/73977264f2bd870244dd73c26acbf452.png" role="button" title="VDI Workspace Hydration Architecture.png" alt="Similar to Game Build Hydration, FSx for ONTAP's cloning capabilities can be used to reduce the storage footprint of workspace clones, game install volumes, user shares, or any other volume mount that needs to be ephemeral, mobile, and mounted to a dev VDI." width="2020" /><span>Similar to Game Build Hydration, FSx for ONTAP's cloning capabilities can be used to reduce the storage footprint of workspace clones, game install volumes, user shares, or any other volume mount that needs to be ephemeral, mobile, and mounted to a dev VDI.</span></span></p><p>A major AAA game studio analyzed that they would benefit from $4.4M of savings annually for their developer VDI farm and would expect to multiply these savings as their developer base grows by leveraging FSx for ONTAP cloning concepts. They reported:</p><ul><li>Drastic reduction in storage footprint.</li><li>Near-instantaneous code updates via cloning and FlexCache, a native ONTAP feature for efficient caching at distance.</li><li>Significant cost savings and operational efficiency.</li></ul><p><span style="font-size: xx-large;"><strong>How to Get Started</strong></span></p><p><span style="font-size: x-large;"><strong>AWS Console Manual Deployment</strong></span></p><p>Amazon FSx for NetApp ONTAP is a native AWS service, available directly through the AWS Management Console alongside other native storage options like S3 and EBS. This provides a simple way to deploy, configure, and monitor your FSx file systems.</p><p><span style="font-size: x-large;"><strong>AWS Cloud Game Development Toolkit (CGD Toolkit)</strong></span></p><p>The CGD Toolkit is a modular collection of templates, automation scripts, and reference architectures designed to streamline game infrastructure deployments on AWS. The toolkit provides</p><ul><li><strong>Guidance: </strong>Recommendations and best practices for common architectures and tooling, from Packer to Horde and even managing iSCSI on FSx for NetApp ONTAP.</li><li><strong>Assets:</strong> Individual playbooks, pipelines, and automation scripts for targeted tasks.</li><li><strong>Modules:</strong> Reusable Terraform configurations for deploying workloads.</li><li><strong>Samples:</strong> Complete reference architectures combining modules and AWS services.</li></ul><p>For example, studios can utilize provided customizable Terraform and Ansible templates, purpose built with best practices, to deploy Perforce P4 on FSx for ONTAP using the CGD Toolkit automation, drastically simplifying deployment and setup of not only P4 and it's associated infrastructure, but also required FSx for ONTAP iSCSI storage as recommended previously in this blog.</p><p>Basically, turn this:</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/da/da767216f41df8ce6c9763e1e24cff2a.png" role="button" title="Game Build Hydration Architecture.png" alt="Game Build Hydration Architecture.png" width="2046" /></span></p><p>Into this:</p><pre><code>module "unreal_horde" {
  source                                = "modules/unreal/horde"
  unreal_horde_service_subnets          = aws_subnet.private_subnets[*].id
  unreal_horde_external_alb_subnets     = aws_subnet.public_subnets[*].id   # External ALB used by developers
  unreal_horde_internal_alb_subnets     = aws_subnet.private_subnets[*].id  # Internal ALB used by agents
  vpc_id                                = aws_vpc.unreal_horde_vpc.id
  certificate_arn                       = aws_acm_certificate.unreal_horde.arn
  github_credentials_secret_arn         = var.github_credentials_secret_arn
  tags                                  = local.tags

  fully_qualified_domain_name = "https://horde.${var.root_domain_name}"
}</code></pre><pre><code>resource "netapp-ontap_lun" "depots_volume_lun" {
  count           = var.storage_type == "FSxN" &amp;&amp; var.protocol == "ISCSI" ? 1 : 0
  cx_profile_name = "aws"
  os_type         = "linux"
  size            = var.depot_volume_size * 0.75 * 1073741824
  svm_name        = var.fsxn_svm_name
  volume_name     = aws_fsx_ontap_volume.depot[0].name
  name            = "/vol/${aws_fsx_ontap_volume.depot[0].name}/${aws_fsx_ontap_volume.depot[0].name}"
  depends_on = [
    aws_lambda_function.lambda_function,
    aws_vpc_security_group_egress_rule.link_outbound_fsxn,
    aws_vpc_security_group_ingress_rule.fsxn_inbound_link
  ]
}

resource "netapp-ontap_san_lun-map" "depots_lun_map" {
  count           = var.storage_type == "FSxN" &amp;&amp; var.protocol == "ISCSI" ? 1 : 0
  cx_profile_name = "aws"
  svm = {
    name = var.fsxn_svm_name
  }
  lun = {
    name = netapp-ontap_lun.depots_volume_lun[count.index].name
  }
  igroup = {
    name = netapp-ontap_san_igroup.perforce_igroup[count.index].name
  }
  depends_on = [
    aws_lambda_function.lambda_function,
    aws_vpc_security_group_egress_rule.link_outbound_fsxn,
    aws_vpc_security_group_ingress_rule.fsxn_inbound_link
  ]
}</code></pre><p><span style="font-size: small;"><em><strong>**Disclaimer**</strong> The above snippets are only examples taken from:&nbsp; <a title="AWS CGD Toolkit Horde Module" href="https://github.com/aws-games/cloud-game-development-toolkit/tree/main/modules/unreal/horde" target="_blank" rel="noopener nofollow noreferrer">https://github.com/aws-games/cloud-game-development-toolkit/tree/main/modules/unreal/horde</a>&nbsp;&amp; <a title="AWS CGD Toolkit Perforce Module" href="https://github.com/aws-games/cloud-game-development-toolkit/tree/main/modules/perforce/" target="_blank" rel="noopener nofollow noreferrer">https://github.com/aws-games/cloud-game-development-toolkit/tree/main/modules/perforce/</a></em></span></p><p>For more complete and comprehensive code with guidance, please visit the AWS CGD Toolkit here:</p><p><a title="AWS Cloud Game Development Toolkit (CGD Toolkit)" href="https://aws-games.github.io/cloud-game-development-toolkit/latest/" target="_blank" rel="noopener nofollow noreferrer">https://aws-games.github.io/cloud-game-development-toolkit/latest/</a></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/c5/c5f6f507072b277f7b8f98d221319958.png" width="239" height="237" role="button" title="CGD Toolkit QR.png" alt="CGD Toolkit QR.png" /></span></p><p><span style="font-size: x-large;"><strong>NetApp BlueXP Workload Factory</strong></span></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/fe/fec1c11feb862d9c69942dabafefcde2.png" role="button" title="WF Logo.png" alt="WF Logo.png" width="3982" /></span></p><p>BlueXP Workload Factory automates workload lifecycle management on FSx for ONTAP&mdash;handling everything from initial design to ongoing operations with workload-centric, best-practice workflows. For Perforce workloads, you can create and mount clones of desired game versions for QA or release from directly within the Perforce P4 client itself. Code snippets are automatically generated of the automation used to create and mount the clones which can be leveraged later in automated build pipelines.</p><p>Workload Factory accelerates the creation and management of software version data infrastructure, by leveraging FSx for ONTAP's thin cloning as mentioned previously. It eliminates the need for custom tools or scripts and seamlessly integrates with your CI/CD workflows including a built-in integration with Perforce P4 (Helix Core).</p><p>This allows you to more easily speed up development lifecycles, lower cloud spend, and increase developer productivity, making it easier to :</p><ul><li><span style="font-size: large;"><strong>Automate data cloning for software versions: </strong></span>Workload Factory facilitates the cloning of FSx for ONTAP-based data environments without the need for third-party tools or scripts. Developers can instantly create and access required software versions environments.</li><li><strong><span style="font-size: large;">Integrate cloning into CI/CD</span>: </strong>Workload Factory seamlessly fits into existing CI/CD workflows by offering a well-documented API, as well as an out-of-the -box integration with Perforce P4 (Helix Core).</li><li><span style="font-size: large;"><strong>Leverage Built-in administrations: </strong></span>Workload Factory simplifies administrational tasks of each software environment including automatic environment space reclamation, capacity limitations, and access duration.</li><li><span style="font-size: large;"><strong>Establish workspace data control and audit: </strong></span>With Workload Factory, you gain the ability to effectively manage access policies for project&rsquo;s data, monitor data usage, and audit user activity.</li></ul><p>Get started with Workload Factory here:&nbsp;<strong><a title="NetApp BlueXP workload factory" href="https://console.workloads.netapp.com" target="_blank" rel="noopener noreferrer nofollow">https://console.workloads.netapp.com</a>&nbsp;</strong></p><h3 id="toc-hId--1850604642"><span style="font-size: xx-large;"><strong>In Conclusion</strong></span></h3><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/6b/6b5e8f77a81d065c90f30d0a6e5a195a.png" width="226" height="226" role="button" title="FSxN Logo.png" alt="FSxN Logo.png" /></span></p><p>Amazon FSx for NetApp ONTAP and AWS together provide a comprehensive, scalable, and cost-efficient platform tailored for the unique needs of modern game development. From managing massive game code repositories and accelerating build pipelines to enabling agile developer environments, FSx for ONTAP empowers studios to innovate faster and deliver richer player experiences.</p><p>By bridging the DevOps gap between traditional software and game development, FSx for ONTAP helps studios reduce costs, improve resilience, and accelerate time-to-market&mdash;ultimately fueling creativity and success in an increasingly competitive industry.</p></div>]]>
        </description>
    </item>
    <item>
        <title>OpenShift Virtualization Disaster Recovery with NetApp Trident Protect</title>
        <link>https://community.netapp.com/community/discussion/460716/openshift-virtualization-disaster-recovery-with-netapp-trident-protect</link>
        <pubDate>Fri, 16 May 2025 18:27:08 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>Rahul-Rana</dc:creator>
        <guid isPermaLink="false">460716@/community/discussions</guid>
        <description><![CDATA[<div><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Written by&nbsp;<a rel="nofollow" href="/profile/96132">@LuisRico</a>&nbsp; and&nbsp;<a rel="nofollow" href="/profile/122379">@Rahul-Rana</a></span></strong></span></p><p><span style="font-size: x-large; font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">OpenShift Virtualization Disaster Recovery with NetApp Trident protect</span></span></p><ul><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId-1510873837">Introduction</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId-505013706">Red Hat OpenShift Virtualization</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId--2047143255">Kubernetes lacks Disaster Recovery</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId--304332920">VMware SRM gap</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId-1438477415">RTO and RPO requirements</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId--917166041">Requirements</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId-629130789">Source Cluster Setup:</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId--1923026172">Destination Cluster Setup:</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId-1043946714">Testing Disaster Recovery - Failover without affecting the source region</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId-234600088">Swapping the Regions - Migration of Virtual Machines</a></li><li><a rel="nofollow" href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/OpenShift-Virtualization-Disaster-Recovery-with-NetApp-Trident-Protect/ba-p/460716#toc-hId-1977410423">Complete Disaster Recovery - Failover and Failback</a></li></ul><h3 id="toc-hId-1510873837"><strong><span style="font-family: arial,helvetica,sans-serif;"><br />Introduction</span></strong></h3><h4 id="toc-hId--1237796629">&nbsp;</h4><h4 id="toc-hId-505013706"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Red Hat OpenShift Virtualization</span></strong><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></h4><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Red Hat OpenShift Virtualization provides a virtualization platform on top of OpenShift to run and manage Windows and Linux Virtual Machines (VMs) alongside containers, by using Kubernetes custom resources to enable virtualization common tasks.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">It&rsquo;s based on the open-source project KubeVirt that has become one of the most popular and active projects of the CNCF (Cloud Native Computing Foundation).</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Although the KubeVirt project started in 2017, it has only gained real popularity as an alternative virtualization platform in recent years.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">For running VMs in OpenShift Virtualization in production, the worker nodes of the OpenShift cluster must be bare metal servers, to avoid nested virtualization. Despite that fact you can run it on premises and on the main hyperscalers.&nbsp;</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><h4 id="toc-hId--2047143255"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Kubernetes lacks Disaster Recovery</span></strong><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></h4><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">As OpenShift Virtualization runs on Kubernetes platform it intrinsically inherits the limitations of Kubernetes and OpenShift to usual practices performed by virtualization administrators. Kubernetes lacks Disaster Recovery (DR) tools, and so does OpenShift Virtualization.&nbsp;</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><h4 id="toc-hId--304332920"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">VMware SRM gap</span></strong><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></h4><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">For VMware vSphere users</span><span>,</span><span data-contrast="auto"> used to different DR applications included VMware Site Recovery Manager (SRM), it's a must to have a data protection tool with Disaster Recovery capabilities. For protecting hundreds or thousands of Virtual Machines with their VM disks, the only feasible option is to use some kind of storage replication to optimize the data transfer between sites.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><h4 id="toc-hId-1438477415"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">RTO and RPO requirements</span></strong><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></h4><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">In the virtualization world, it's also usual to comply with strict Service Level Agreements (SLAs) on availability for the VMs, reflected on low RPO (Recovery Point Objective) and RTO (Recovery Time Objective). That forces the use of fast and efficient storage replication to transfer data as fast and frequent as possible for low RPO, and to automate the failover to reduce the time the VMs get started in the secondary/destination site for low RTO.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">NetApp with Trident Protect, that is available for NetApp customers at no additional cost with NetApp Trident, helps to solve this gap.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:120,&quot;335559739&quot;:120}">&nbsp;</span></span></p><h3 id="toc-hId--917166041"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Requirements</span></strong><span data-ccp-props="{}">&nbsp;<br /><br /></span></span></h3><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Virtual Machine running on source OCP Cluster:</span></strong><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/88/88bfeea1a821246fa121e4610e0b8c4a.png" role="button" title="RahulRana_0-1747376598098.png" alt="RahulRana_0-1747376598098.png" width="1379" /></span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">ONTAP</span></strong><span data-contrast="auto"> - Storage backends must be peered as mentioned in our&#8239;</span><a href="https://docs.netapp.com/us-en/ontap/peering/peering-basics-concept.html" target="_blank" rel="noopener noreferrer nofollow"><span data-contrast="auto">documentation</span></a><span data-contrast="auto">.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">AppVault </span></strong><span data-contrast="auto">&ndash; AppVault</span> <span data-contrast="auto">(Object Storage Bucket) is used to store metadata (k8s resources) for the Virtual Machine and associated namespace used during failover operations.&#8239;Recommendation is to create two separate AppVault configurations for your source and destination sites.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p aria-level="3"><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></span></p><h4 aria-level="3" id="toc-hId-629130789"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Source Cluster Setup:</span></strong><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></span></h4><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Cluster AppVault -&#8239;</span></strong><span data-contrast="none"> Verify that the AppVault CR shared between the source and destination has been created, following the example provided below.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p><pre><code>oc create secret generic &lt;secret-name&gt; \ 
--from-literal=accessKeyID=&lt;objectstorage-accesskey&gt; \ 
--from-literal=secretAccessKey=&lt;ontap-s3-trident-protect-src-bucket-secret&gt; \ 
-n trident-protect </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><pre><code>apiVersion: protect.trident.netapp.io/v1 
kind: AppVault 
metadata: 
  name: ontap-s3-trident-protect-src-bucket 
  namespace: trident-protect 
spec: 
  dataMoverPasswordSecretRef: my-optional-data-mover-secret 
  providerType: OntapS3 
  providerConfig: 
    s3: 
      bucketName: trident-protect-src-bucket 
      endpoint: s3.example.com 
      proxyURL: http://10.1.1.1:3128 
  providerCredentials: 
    accessKeyID: 
      valueFromSecret: 
        key: accessKeyID 
        name: s3-secret 
    secretAccessKey: 
      valueFromSecret: 
        key: secretAccessKey 
        name: s3-secret </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Create AppVault CR using command below:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:300,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>oc apply &ndash;f example-file.yaml </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Application CR -</span></strong><span data-contrast="auto"> The Application CR&nbsp;is a Kubernetes object that allows Trident Protect to discover&nbsp;and manage user provided&nbsp;namespace or multiple namespaces&nbsp;for data protection operations, such as snapshots, backups, restores, or replication.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">&#8239;Define</span> <span data-contrast="auto">CR for your source application using example below:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><pre><code>apiVersion: protect.trident.netapp.io/v1 
kind: Application 
metadata: 
  annotations: 
    protect.trident.netapp.io/skip-vm-freeze: "false" 
  name: demo-vm 
  namespace: source-vm-ns 
spec: 
  includedNamespaces: 
    - namespace: source-vm-ns 
      labelSelector: 
        matchLabels: 
          app: demo-vm 
  includedClusterScopedResources: 
    - groupVersionKind: 
        group: rbac.authorization.k8s.io 
        kind: ClusterRole 
        version: v1 
      labelSelector: 
        matchLabels: 
          mylabel: test</code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Create App CR using command below:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:300,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>oc apply &ndash;f example-file.yaml</code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Snapshot Schedule</span></strong> <strong><span data-contrast="none">CR -</span></strong><span data-contrast="none"> Snapshot CR is used to specify the frequency (e.g., hourly) and retention (e.g., keep 24 snapshots) for data protection. These snapshots are then used for App Replication from source to destination OCP cluster.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Snapshot Schedule -&#8239;</span></strong><span data-contrast="auto">Schedule for snapshots (CR) using example below:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><pre><code>apiVersion: protect.trident.netapp.io/v1 
kind: Schedule 
metadata: 
&#8239;&#8239;name: snapshot-schedule 
&#8239;&#8239;namespace: source-vm-ns  
spec: 
&#8239;&#8239;appVaultRef: source-bucket 
&#8239;&#8239;applicationRef: source-vm-ns 
&#8239;&#8239;backupRetention:&#8239;"0" 
&#8239;&#8239;enabled:&#8239;true 
&#8239;&#8239;granularity: custom 
&#8239;&#8239;recurrenceRule: |- 
&#8239;&#8239;&#8239;&#8239;DTSTART:20220101T000200Z 
&#8239;&#8239;&#8239;&#8239;RRULE:FREQ=MINUTELY;INTERVAL=5 
&#8239;&#8239;snapshotRetention:&#8239;"5" </code></pre><p aria-level="3"><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Create SnapshotSchedule CR using command below:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:300,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>oc apply &ndash;f example-file.yaml </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><h4 aria-level="3" id="toc-hId--1923026172"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Destination Cluster Setup:</span></strong><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></span></h4><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Destination Cluster AppVault CR</span></strong><span data-contrast="auto">: Create a common &#8239;</span><a href="https://docs.netapp.com/us-en/trident/trident-protect/trident-protect-appvault-custom-resources.html" target="_blank" rel="noopener noreferrer nofollow"><span>AppVault</span></a><span data-contrast="auto"> between source and destination so that destination cluster can access the application metadata created on the source cluster. Also create a destination AppVault similar to what was done on the source cluster. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Configuring AMR</span></strong><span>&nbsp;<br /></span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">AppMirrorRelationship CR</span></strong><span data-contrast="auto">: The AppMirror CR in NetApp Trident Protect is used to manage the replication frequency of applications across OCP clusters for disaster recovery and application mobility, leveraging NetApp&rsquo;s SnapMirror technology. It defines the replication relationship between a source application and a destination, enabling failover, failback, or workload migration between OCP&nbsp;clusters.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Define the&#8239;</span><a href="https://docs.netapp.com/us-en/trident/trident-protect/trident-protect-use-snapmirror-replication.html" target="_blank" rel="noopener noreferrer nofollow"><span data-contrast="auto">application mirror relationship</span></a><span data-contrast="auto">&#8239;with&#8239;a replication schedule.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Example of AMR CR:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559738&quot;:150}">&nbsp;</span></span></p><pre><code>apiVersion:&#8239;protect.trident.netapp.io/v1 
kind:&#8239;AppMirrorRelationship 
metadata: 
&#8239;&#8239;name:&#8239;amr-demo 
&#8239;&#8239;namespace:&#8239;destination-vm-ns 
spec: 
&#8239;&#8239;desiredState:&#8239;Established 
&#8239;&#8239;destinationAppVaultRef: destination-bucket 
&#8239;&#8239;namespaceMapping: 
&#8239;&#8239;&#8239;&#8239;-&#8239;destination:&#8239; destination-vm-ns 
&#8239;&#8239;&#8239;&#8239;&#8239;&#8239;source:&#8239; source-vm-ns 
&#8239;&#8239;recurrenceRule:&#8239;|- 
&#8239;&#8239;&#8239;&#8239;DTSTART:20220101T000200Z 
&#8239;&#8239;&#8239;&#8239;RRULE:FREQ=MINUTELY;INTERVAL=5 
&#8239;&#8239;sourceAppVaultRef:&#8239;source-bucket-appvault 
&#8239;&#8239;sourceApplicationName:&#8239; source-vm-ns 
&#8239;&#8239;sourceApplicationUID:&#8239;7498d32c-328e-4ddd-9029-122540866aeb 
&#8239;&#8239;storageClassName:&#8239;ontap-sc </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Create AMR CR using command below:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>oc apply &ndash;f example-file.yaml </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:150,&quot;335559739&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">As we can see below our AMR has been established and Region B namespace only contains the PVC</span><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/8d/8d8c082afd00d1d770f9a81ca4687bcf.png" role="button" title="RahulRana_1-1747376598098.png" alt="RahulRana_1-1747376598098.png" width="1600" /></span></span></p><p><strong><span style="font-family: arial,helvetica,sans-serif;">Production Site Region A and Standby Site Region B&nbsp;</span></strong></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/2f/2fa7ab4e6814f75964b22846e52575fb.png" role="button" title="RahulRana_2-1747376598098.png" alt="RahulRana_2-1747376598098.png" width="938" /></span></span></p><h3 id="toc-hId-16297668">&nbsp;</h3><h3 id="toc-hId-1043946714"><span style="font-family: arial,helvetica,sans-serif;"><strong>Testing Disaster Recovery - Failover without affecting the source region</strong></span></h3><p>In this section we perform disaster recovery without impacting the our production site Region A. Towards the end we will bring down the VMs running in Region B without affecting our original site which is Region A.&nbsp;<span> In a failover scenario, the standby system or environment takes over the responsibilities of the primary system or environment, ensuring business continuity. </span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: large;"><strong>Failover without affecting the source region.</strong></span><span data-ccp-props="{}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/8b/8b947e387898ae6f4b17c4d4561fd410.png" role="button" title="RahulRana_0-1747417966255.png" alt="RahulRana_0-1747417966255.png" width="938" /></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p aria-level="3"><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Execute Failover on Region B:</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}">&nbsp;</span></span></p><pre><code>oc patch amr -n destination-vm-ns amr-demo --type='json' -p '[{"op": "replace", "path": "/spec/desiredState", "value":"Promoted"}]' </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p aria-level="3"><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">You can observe AMR status change from promoting to promoted</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}">&nbsp;</span></span></p><pre><code>oc get amr amr-demo -n destination-vm-ns -w </code></pre><p aria-level="3"><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">VM is up and running on Region B after failover</span><span data-contrast="auto">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/7b/7b4b6e41a83d7f00769f8e929ff47979.png" role="button" title="RahulRana_4-1747376598098.png" alt="RahulRana_4-1747376598098.png" width="1600" /></span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/91/914b99bc42393d66191c0c44e864f891.png" role="button" title="RahulRana_5-1747376598098.png" alt="RahulRana_5-1747376598098.png" width="1339" /></span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p aria-level="3"><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Execute command below to discard changes on Region B cluster and re-establish mirror relationship from Region A to Region B:</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}">&nbsp;</span></span></p><pre><code>oc patch amr -n destination-vm-ns amr-demo --type='json' -p '[{"op": "replace", "path": "/spec/desiredState", "value":"Established"}]' </code></pre><p aria-level="3"><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Ensure AMR state change has changed from establishing to established</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}">&nbsp;</span></span></p><pre><code>oc get amr amr-demo &ndash;n destination-vm-ns -w </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">We can see below AMR is back in Established state and VM has been Terminated</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/d3/d3da0ecca3d7bbfa06ae9ce2add329b9.png" role="button" title="RahulRana_6-1747376598098.png" alt="RahulRana_6-1747376598098.png" width="1600" /></span></span></p><h3 id="toc-hId--1508210247"><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></h3><h3 aria-level="2" id="toc-hId-234600088"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Swapping the Regions - Migration of Virtual Machines</span></strong></span></h3><p aria-level="2"><span><br />In this section Region B becomes the source region, and the Region A becomes the destination.&nbsp;</span>Modifications to Region B Virtual Machines during failover are preserved.</p><p aria-level="2"><span style="font-size: large;"><strong>Swapping Production and Standby Site</strong></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/19/19012a465b709da892852ef03ef91e78.png" role="button" title="RahulRana_7-1747376598099.png" alt="RahulRana_7-1747376598099.png" width="938" /></span></span></p><p aria-level="4"><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Prerequisite to this section of Reverse resync would be a failed over replication relationship as outlined above.</span></span></p><p aria-level="4"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="none">Delete AMR CR on Region B<br /></span></strong></span></span></p><pre><code>oc delete amr amr-demo -n destination-vm-ns </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="none">Capture changes since failover</span></strong><span data-contrast="none">: Create a new base snapshot on Region B using example snapshot CR below:</span><span data-ccp-props="{}">&nbsp;</span></span></p><pre><code>apiVersion: protect.trident.netapp.io/v1 
kind: Snapshot 
metadata: 
  namespace: destination-vm-ns 
  name: snapshot-cr 
spec: 
  applicationRef: destination-vm-ns 
  appVaultRef: Destination-bucket 
  reclaimPolicy: Delete </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span>&nbsp;<br /></span><span data-contrast="auto">Create Snapshot CR using command below:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:300,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>oc apply &ndash;f example-file.yaml </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559685&quot;:720}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="none">Create snapshot schedule</span></strong><span data-contrast="none">: Create a new snapshot schedule CR on Region B.</span><span data-ccp-props="{}">&nbsp;</span></span></p><pre><code>apiVersion: protect.trident.netapp.io/v1 
kind: Schedule 
metadata: 
&#8239;&#8239;name: snapshot-schedule 
&#8239;&#8239;namespace: destination-vm-ns 
spec: 
&#8239;&#8239;appVaultRef: destination-bucket 
&#8239;&#8239;applicationRef: destination-vm-ns 
&#8239;&#8239;backupRetention:&#8239;"0" 
&#8239;&#8239;enabled:&#8239;true 
&#8239;&#8239;granularity: custom 
&#8239;&#8239;recurrenceRule: |- 
&#8239;&#8239;&#8239;&#8239;DTSTART:20220101T000200Z 
&#8239;&#8239;&#8239;&#8239;RRULE:FREQ=MINUTELY;INTERVAL=5 
&#8239;&#8239;snapshotRetention:&#8239;"5" </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Create SnapshotSchedule CR using command below:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:300,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>oc apply &ndash;f example-file.yaml </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559685&quot;:720}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="none">Delete snapshot schedule on Region A</span><span>&nbsp;<br /></span></span></p><pre><code>oc delete schedule vm-snap-schedule -n source-vm-ns </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559685&quot;:720}">&nbsp;</span></span><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="none">Create new AMR CR</span></strong><span data-contrast="none">: Establish a new AppMirrorRelationship CR on Region A.</span><span data-ccp-props="{}">&nbsp;</span></span></p><ul><li><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="none">Ensure namespace mapping is accurate</span><span data-ccp-props="{}">&nbsp;</span></span></li><li><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="none">Ensure AppVaults have been swapped if using a source and destination app vault (destination will become source and source will become destination)</span><span data-ccp-props="{}">&nbsp;</span></span></li><li><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="none">Ensure srcApplicationName matches the name of the Application CR created on secondary instance</span><span data-ccp-props="{}">&nbsp;</span></span></li><li><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="none">Ensure srcApplicationUID matches the .metadata.uid from the Application CR created on the secondary instance</span></span></li></ul><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="none">Example of AMR CR to be created on Region B&nbsp;OCP Cluster which can be created using:</span><span data-ccp-props="{&quot;335559685&quot;:720}">&nbsp;</span></span></p><pre><code>apiVersion:&#8239;protect.trident.netapp.io/v1 
kind:&#8239;AppMirrorRelationship 
metadata: 
&#8239;&#8239;name:&#8239;amr-demo 
&#8239;&#8239;namespace:&#8239;destination-vm-ns 
spec: 
&#8239;&#8239;desiredState:&#8239;Established 
&#8239;&#8239;destinationAppVaultRef:&#8239; destination-bucket 
&#8239;&#8239;namespaceMapping: 
&#8239;&#8239;&#8239;&#8239;-&#8239;destination:&#8239; destination-vm-ns 
&#8239;&#8239;&#8239;&#8239;&#8239;&#8239;source:&#8239; source-vm-ns 
&#8239;&#8239;recurrenceRule:&#8239;|- 
&#8239;&#8239;&#8239;&#8239;DTSTART:20220101T000200Z 
&#8239;&#8239;&#8239;&#8239;RRULE:FREQ=MINUTELY;INTERVAL=5 
&#8239;&#8239;sourceAppVaultRef:&#8239;source-bucket-appvault 
&#8239;&#8239;sourceApplicationName:&#8239; source-vm-ns 
&#8239;&#8239;sourceApplicationUID:&#8239;7498d32c-328e-4ddd-9029-122540866aeb 
&#8239;&#8239;storageClassName:&#8239;ontap-sc </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559685&quot;:720}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Create AMR CR using command below:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:300,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>oc apply &ndash;f example-file.yaml </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559685&quot;:0}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="none">Wait for AMR establishment</span></strong><span data-contrast="none">: Wait for the AppMirrorRelationship to reach the "Established" state in Region A.</span><span data-ccp-props="{}">&nbsp;</span></span></p><pre><code>oc get amr amr-demo -n source-vm-ns -w  </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">We can see below AMR is in the Established state in Region A</span><span data-ccp-props="{}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/9c/9c5ec51f58e3a7df7f9ca9e0525360e6.png" role="button" title="RahulRana_8-1747376598099.png" alt="RahulRana_8-1747376598099.png" width="1600" /></span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Note: If VM was in running state it would be torn down as part of Establishing the AMR</span><span data-ccp-props="{}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="none">Region B is now the primary site with the VM operational replicating to Region A.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/2e/2ece9f3362768d62e5e844cf96fb720a.png" role="button" title="RahulRana_9-1747376598099.png" alt="RahulRana_9-1747376598099.png" width="1600" /></span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/58/583d18120d4e3aebc5dbfc6e34f16fcc.png" role="button" title="RahulRana_10-1747376598099.png" alt="RahulRana_10-1747376598099.png" width="1328" /></span></span></p><h3 aria-level="2" id="toc-hId-1977410423"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Complete Disaster Recovery - Failover and Failback</span></strong></span></h3><p aria-level="2"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto"><br /></span></strong>In this scenario we revert to the original replication direction and state, we first replicate (resynchronize) any application changes to the Region A Virtual Machines prior to reversing the replication direction.<span><br /></span></span></p><p aria-level="2"><span style="font-family: arial,helvetica,sans-serif;"><span><br /></span><strong><span data-contrast="auto">Syncing changes back to original Region A and bringing the App down on Region B</span></strong><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}">&nbsp;</span></span></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/73/73229135446cc689953a2d0a7316aacd.png" role="button" title="RahulRana_0-1747418803014.png" alt="RahulRana_0-1747418803014.png" width="938" /></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Reversing the replication direction from Region B to Region A</span></strong><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/45/45828af60ddc6e829ec0c96572f9a811.png" role="button" title="RahulRana_0-1747418481756.png" alt="RahulRana_0-1747418481756.png" width="938" /></span></p><p aria-level="4"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Prerequisite to this section would be Reverse resync a failed over replication relationship as outlined above.</span></strong></span></p><p aria-level="4"><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Disable Schedules on Region B</span></strong><span data-contrast="auto">&#8239;-&#8239;Delete any snapshot schedules in Region B.</span></span></p><p><li-wrapper><i></i></li-wrapper></p><pre><code>oc delete schedule snapshot-schedule -n destination-vm-ns </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">ShutdownSnapshot CR:&#8239;</span></strong><span data-contrast="auto">Create a ShutdownSnapshot CR on Region B to take a final snapshot and gracefully shutdown your application. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Configure the following attributes for ShutDown snapshot CR:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;335559685&quot;:720}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Region B&nbsp;AppVaultRef</span></strong><span data-contrast="auto">: (</span><i><span data-contrast="auto">Required</span></i><span data-contrast="auto">) This value must match the metadata.name field of the AppVault for the source application</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;335559685&quot;:720}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="none">Region B </span></strong><strong><span data-contrast="auto">ApplicationRef</span></strong><span data-contrast="auto">: (</span><i><span data-contrast="auto">Required</span></i><span data-contrast="auto">) This value must match the metadata.name field of the source application CR file.</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;335559685&quot;:720}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Example of ShutdownSnapshot CR:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:300,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>apiVersion: protect.trident.netapp.io/v1 
kind: ShutdownSnapshot 
metadata: 
  name: replication-shutdown-snapshot 
  namespace: destination-vm-ns 
spec: 
  appVaultRef: destination-bucket 
  applicationRef: destination-vm-ns </code></pre><p><span style="font-family: arial,helvetica,sans-serif;">&nbsp;</span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Create ShutdownSnapshot CR using command below:</span><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559685&quot;:300,&quot;335559738&quot;:240,&quot;335559739&quot;:150}">&nbsp;</span></span></p><pre><code>oc apply &ndash;f example-file.yaml </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335557856&quot;:16777215,&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">On the source cluster, after the shutdown snapshot completes, get the status of the shutdown snapshot:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p><pre><code>oc get shutdownsnapshot -n source-vm-ns &lt;shutdown_snapshot_name&gt; -o yaml </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Shutdown snapshot created and VM resources have cleaned up in Region B</span><span><br /></span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/06/06ba0e6a69a52674d2e71574dd1f177e.png" role="button" title="RahulRana_13-1747376598099.png" alt="RahulRana_13-1747376598099.png" width="1600" /></span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">After the ShutdownSnapshot has completed, get the name of the snapshot from the CR status&#8239;as mentioned in our&#8239;</span><a href="https://docs.netapp.com/us-en/trident/trident-protect/trident-protect-use-snapmirror-replication.html%22%20/l%20%22reverse-application-replication-direction" target="_blank" rel="noopener noreferrer nofollow"><span>documention.</span></a><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;335559685&quot;:720}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">On the source cluster, find the value of </span><strong><span data-contrast="auto">shutdownsnapshot.status.appArchivePath</span></strong><span data-contrast="auto"> using the command below, and record the last part of the file path (also called the basename; this will be everything after the last slash):</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p><pre><code>oc get shutdownsnapshot -n source-vm-ns &lt;shutdown_snapshot_name&gt; -o jsonpath='{.status.appArchivePath}' </code></pre><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Perform a Failover using the snapshot basename in apparchive path retrieved using previous step from Region B to Region A.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Follow Reverse Resync steps from Region A to Region B.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;335559685&quot;:720}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="auto">Enable snapshot schedules on your original site Region A as described in prerequisites section of the blog.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-contrast="none">At this point you have completed the full cycle of failover and failback. VMs are again running in Region A replicating to Region B.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/c2/c2a9892355347fe3b23fa54814f4a205.png" role="button" title="RahulRana_14-1747376598098.png" alt="RahulRana_14-1747376598098.png" width="1600" /></span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><strong><span data-contrast="auto">Conclusion</span></strong><span>&nbsp;<br /></span><span data-contrast="auto">In conclusion, the integration of OpenShift Virtualization, NetApp Trident, and AppMirror provides a powerful solution for protecting and mirroring critical applications. By leveraging this integrated solution, organizations can unlock enterprise-grade virtualization, simplify management, and improve data protection. Whether you're a seasoned IT professional or just starting to explore the world of virtualization, this integrated solution is definitely worth considering.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p><p><span style="font-family: arial,helvetica,sans-serif;"><span data-ccp-props="{}">&nbsp;</span></span></p></div>]]>
        </description>
    </item>
    <item>
        <title>Does deleting a source snapshot that is mirrored and used at destination for flexclone impact snapm?</title>
        <link>https://community.netapp.com/community/discussion/458539/does-deleting-a-source-snapshot-that-is-mirrored-and-used-at-destination-for-flexclone-impact-snapm</link>
        <pubDate>Thu, 13 Feb 2025 05:38:46 +0000</pubDate>
        <category>Data Protection</category>
        <dc:creator>limitless</dc:creator>
        <guid isPermaLink="false">458539@/community/discussions</guid>
        <description><![CDATA[<div><p><span>&gt; version NetApp Release 9.15.1P5</span><br /><br />1. I have a snapmirror relationship and I manually mirrored a snapshot "test5" from source to destination using the below command.<br /><br />Dest &gt; snapmirror -update -destination-path &lt;&gt; -snapshot test5<br /><br />2. I created a flexclone at the destination using the snapshot test5<br /><br /><span>&gt; vol clone show<br />Parent Parent Parent Vserver FlexClone Vserver Volume Snapshot State Type<br />------- ------------- ------- ------------- -------------------- --------- ----<br />dest&nbsp;&nbsp;&nbsp;&nbsp; vol_dest_clone&nbsp;&nbsp;&nbsp;&nbsp; dest&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; vol_dest&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; test5 &nbsp; &nbsp; &nbsp; &nbsp; online&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; RW</span><br /><br />3. Now, I deleted(accidentally) the test5 snapshot at the source forcefully<br /><span>*&gt; snap delete -vserver source -volume vola -snapshot test5 -ignore-owners true</span><br /><br />4. The snapmirror relationship is not affected by this even after an update:<br /><span>&gt;snapmirror update -destination-path dest:vol_dest</span><br /><span>&gt; snapmirror show<br />Progress Source Destination Mirror Relationship Total Last Path Type Path State Status Progress Healthy Updated -<br />---------- ---- ------------ ------- -------------- --------- ------- --------<br />SourceLocal:vola XDP dest:vol_dest Snapmirrored Idle - true -<br /></span><br />Question:<br />- From the past experience I have noted that this type of action affects the snapmirror relationship. As mentioned in a 3rd party article:<br /><br />~~~<br />If a FlexClone volume is created from a <span>Snapshot copy</span> that is not the most recent <span>Snapshot copy</span>, and that <span>Snapshot copy</span> no longer exists on the source volume, then every update will need to delete the <span>Snapshot copy</span> on the destination. In this case, all <span>SnapMirror</span> updates to the destination volume fail until the clone is destroyed or split.<br />~~<br />What has changed on a newer version of Netapp that deleting the source snapshot does not affect snapmirror?<br />Or it only affects if snapshot deleted is a baseline snapshot?<br /><br /><br /><br /></p></div>]]>
        </description>
    </item>
    <item>
        <title>Temporary stop of snapmirror in CDOT</title>
        <link>https://community.netapp.com/community/discussion/107620/temporary-stop-of-snapmirror-in-cdot</link>
        <pubDate>Thu, 23 Jul 2015 13:16:52 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>dpeverley</dc:creator>
        <guid isPermaLink="false">107620@/community/discussions</guid>
        <description><![CDATA[<div><p>In 7-Mode I could stop snapmirror with</p><p>snapmirror off</p><p>How is this acheived in CDOT?</p><p>Going down into the node level there is the option</p><p>snapmirror.enable</p><p>But it doesn't seem to make a difference if it is on or off at this point.</p><p>Can anyone advise?</p></div>]]>
        </description>
    </item>
    <item>
        <title>SVM DR</title>
        <link>https://community.netapp.com/community/discussion/139655/svm-dr</link>
        <pubDate>Tue, 17 Apr 2018 19:57:29 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>kdean1979</dc:creator>
        <guid isPermaLink="false">139655@/community/discussions</guid>
        <description><![CDATA[<div><p>Good day,</p><p>With SVM Disaster Recovery I have 2 questions:</p><p>1) Is synchronous snapmirror supported?</p><p>2)&nbsp;Can you&nbsp; failover a single volume from the SVM or it is only meant in SVM level recovery?</p><p>Thanks</p><p>Kathy</p></div>]]>
        </description>
    </item>
    <item>
        <title>Snapshot volume is full</title>
        <link>https://community.netapp.com/community/discussion/129372/snapshot-volume-is-full</link>
        <pubDate>Fri, 24 Mar 2017 07:02:39 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>Narry</dc:creator>
        <guid isPermaLink="false">129372@/community/discussions</guid>
        <description><![CDATA[<div><p>Hi All,</p><p>I am new to this platform, One of my snapshot size is kept on increasing and now it has consumed all the snap reserve space by taking spill. I wonder if this can cause any damage to snapshot or should I need to allocate more space to snapshot reserve. If is it so how to do that? Will it effect my volume?</p></div>]]>
        </description>
    </item>
    <item>
        <title>Disk Sanitization</title>
        <link>https://community.netapp.com/community/discussion/110077/disk-sanitization</link>
        <pubDate>Wed, 23 Sep 2015 09:04:57 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>storageadmin</dc:creator>
        <guid isPermaLink="false">110077@/community/discussions</guid>
        <description><![CDATA[<div><p>For failed disks that still can be unfailed we use disk sanitization for wiping out any data before we return the disk to NetApp. To use disk sanitization we had to activate the option <strong>"licensed_feature.disk_sanitization.enable"</strong>. After activation, this option can't be deactivated anymore. This is clearly documented in the command reference of the option.</p><p>In contrast to this the documentation of the sanitazation is very vague in regard to the consequences: "Attention: After disk sanitization is enabled on a storage system, it is permanent, and it prevents certain Data ONTAP commands from being run." (Storage Management Guide) We had to painfully learn that one of the commands that is prevented from being run is the vol move command. Before activating the option we used vol move without problems. Afterwards it threw an error message saying that vol move requires a Snapmirror license now.</p><p>In a case opened for this it was pointed out that this was for security reasons. Since we do not use Snapmirror we didn't have a licence and had to procure it. After adding the license vol move worked fine again. This occured with 7-Mode ONTAP 8.1.3 and I requested a documentation update on this. But it hasn't been incorporated in 8.3.1 yet.<br /><br />Question:<br />Are there any experiences on what doesn't work in conesquence of activating the disk sanitization option?</p></div>]]>
        </description>
    </item>
    <item>
        <title>Snap Mirror Procedure</title>
        <link>https://community.netapp.com/community/discussion/139243/snap-mirror-procedure</link>
        <pubDate>Thu, 29 Mar 2018 17:53:53 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>Storage_Professional</dc:creator>
        <guid isPermaLink="false">139243@/community/discussions</guid>
        <description><![CDATA[<div><p>Dear Experts,</p><p>I am new to this Community and I am looking for some steps on how to create a SnapMirror ( Site to Site Replication) both our Sites Identical Replica of AFF700 with 9.3 P1 running on it and we are using it as a Unified Array ( Block &amp; File )&nbsp;</p><p>Appreciate any help or any technical kb article that shows the procedure.&nbsp;</p><p>Thank You&nbsp;</p><p>Storage Professional&nbsp;</p></div>]]>
        </description>
    </item>
    <item>
        <title>Stop Snapmirror for limited time</title>
        <link>https://community.netapp.com/community/discussion/129702/stop-snapmirror-for-limited-time</link>
        <pubDate>Fri, 31 Mar 2017 18:57:10 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>tibak</dc:creator>
        <guid isPermaLink="false">129702@/community/discussions</guid>
        <description><![CDATA[<div><p>Hi Everyone,</p><p>I want to upgrade DataOntap in &nbsp;7-mode . I want to stop snapmirror before upgrade and after upgrade again start it .</p><p>What is the best way to stop the snapmirror just for limited time&nbsp;&nbsp;. i dont want to loose any snapshot or something happen for snapmirror relationships .</p><p>Thanks</p></div>]]>
        </description>
    </item>
    <item>
        <title>What is snap vault?what is the difference between Snap mirror and snap vault?</title>
        <link>https://community.netapp.com/community/discussion/52938/what-is-snap-vault-what-is-the-difference-between-snap-mirror-and-snap-vault</link>
        <pubDate>Wed, 28 Oct 2009 01:07:18 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>prabuvediappa</dc:creator>
        <guid isPermaLink="false">52938@/community/discussions</guid>
        <description><![CDATA[<div><p>What is snap vault?what is the difference between Snap mirror and snap vault?</p></div>]]>
        </description>
    </item>
    <item>
        <title>Unable to increase size!!</title>
        <link>https://community.netapp.com/community/discussion/11758/unable-to-increase-size</link>
        <pubDate>Thu, 07 Mar 2013 20:53:06 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>PPATTNAIK</dc:creator>
        <guid isPermaLink="false">11758@/community/discussions</guid>
        <description><![CDATA[<div><p>I am unable to increase size of a filer. It's throwing an alert </p><p dir="ltr" id="imcontent"><span dir="ltr">'Volume has the fixed filesystem size option set '..</span></p></div>]]>
        </description>
    </item>
    <item>
        <title>Unable to delete volume - snapmirror in progress</title>
        <link>https://community.netapp.com/community/discussion/132847/unable-to-delete-volume-snapmirror-in-progress</link>
        <pubDate>Mon, 17 Jul 2017 11:08:08 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>TuvaluAsks</dc:creator>
        <guid isPermaLink="false">132847@/community/discussions</guid>
        <description><![CDATA[<div><p>Hi,</p><p>I've lately come across this volume that I want to delete on my ClusterMode controller (8.3.1).</p><p>Volume is offline. I've tried "volume delete -vserver &lt;SVM&gt; -volume &lt;VOL&gt;" and received the following error:</p><p><em><span style="font-family: arial,helvetica,sans-serif;">Command Failed: Volume VOL in vserver SVM is in one or more SnapMirror relationships. You must delete the SnapMirror relationships before you can delete this volume.</span></em></p><p><span style="font-family: arial,helvetica,sans-serif;">However, there are no snapmirror relationships connected to this volume. I've checked it with "snapmirror list-destination -source-path SVM:VOL" and "snapmirror show -source-path SVM:VOL" and the output for both is&nbsp;<em>There are no entries matching your query</em>.</span></p><p><span style="font-family: arial,helvetica,sans-serif;">How can I delete my volume with nonexistent snapmirror relationships?</span></p></div>]]>
        </description>
    </item>
    <item>
        <title>Unable to Break SVM Peer Relationship</title>
        <link>https://community.netapp.com/community/discussion/159877/unable-to-break-svm-peer-relationship</link>
        <pubDate>Fri, 02 Oct 2020 10:04:42 +0000</pubDate>
        <category>Data Protection</category>
        <dc:creator>CSTOCKDA</dc:creator>
        <guid isPermaLink="false">159877@/community/discussions</guid>
        <description><![CDATA[<div><p>Hello,</p><p>There is an issue where we are unable to remove an SVM peer relationship so we can destroy the SVM.</p><p>The SVM is peered:</p><p>praesdc1&nbsp;&nbsp;&nbsp; praesdc2&nbsp;&nbsp;&nbsp; peered&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; dc2-tier1-cluster1</p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; snapmirror&nbsp; &nbsp;&nbsp;&nbsp;praesdc2</p><div id="tinyMceEditorCSTOCKDA_0">&nbsp;</div><p>When trying to delete the peer relationship we get the following error "Error: command failed: Relationship is in use by SnapMirror iocal cluster. Use the "Snapmirror list-destinations" command to view the relationship"</p><p>Checking we do not see a Snapmirror relationship. I have been advised that the volumes were deleted before the relationship was broken.</p><p>Is there any way be can break the peer relationship when we dont see a Snapmirror relationship</p><p>Thanks</p></div>]]>
        </description>
    </item>
    <item>
        <title>Delete Volumes in SVM DR</title>
        <link>https://community.netapp.com/community/discussion/137602/delete-volumes-in-svm-dr</link>
        <pubDate>Thu, 25 Jan 2018 18:21:53 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>eyeboxone</dc:creator>
        <guid isPermaLink="false">137602@/community/discussions</guid>
        <description><![CDATA[<div><p>Two FAS 8020, NetApp Release 9.1P6 with SVM DR configured. When a volume gets created on Site A SVM it then gets automatically replicated to Site B SVM. Site B SVM is not running until failover. A few other things happend in a WFA workflow but that is basically what is going on.</p><p>I need to delete a few volumes but cannot because they are in a SVM DR relationship. When I attempt quiese, break or release a volume I get the message,&nbsp; "Error: command failed: Cannot complete the operation because the destination volume "VOLUMES" belongs to Vserver "SVM" which is configured as the destination endpoint of Vserver DR relationship."</p><p>I can exclude a volume from SVM DR with this command,&nbsp;</p><p>source_cluster::&gt; volume modify -vserver vs1 -volume test_vol1 -vserver-dr-protection unprotected.</p><p>This will remove the relationship from System Manager but if you run list destination from the command line it still appears that relics of relationship are still present. Interesting enough, I can delete the destination volume but not the source volume. It it gives a similar message to the one above. Here is the message.</p><p>Data ONTAP API Failed: Volume "VolumeName" in Vserver "SVM" is the source endpoint of one or more SnapMirror relationships. Before you delete the volume, you must release the source information of the SnapMirror relationships using "snapmirror release". To display the destinations to be used in the "snapmirror release" commands, use the "snapmirror list-destinations -source-vserver SVM -source-volume Volume" command.</p><p>I have attempted the suggested commands and that is where I find the relics of the relationship even though I have excluded it from protection. I also can not doing anything on volume and will received the message above.</p><p>Support suggest I break the entire SVM DR relationship, then I will be able to interact with the volumes and eventually delete them. This seems excessive. Plus, while I am deleting the volumes, my other volumes are syncing on their scheduled interval.</p><p>Any suggestions?&nbsp;&nbsp;</p></div>]]>
        </description>
    </item>
    <item>
        <title>Snapmirror logs</title>
        <link>https://community.netapp.com/community/discussion/139239/snapmirror-logs</link>
        <pubDate>Thu, 29 Mar 2018 15:31:54 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>apw</dc:creator>
        <guid isPermaLink="false">139239@/community/discussions</guid>
        <description><![CDATA[<div><p>Hi -&nbsp; i&nbsp; am running OnTap cDOT 9.1P7.</p><p>I need to gather information for every snapmirror transfer which has completed and is still in the logs. I want to generate a single text file with the following fields</p><p>RelaionshipID:Start timestamp:FinishTimeStamp:TransferSize:TransferStatus</p><p>There are many logs and i can't seem to find any clear 'Start' and 'End' in the logs</p><p>Can anyone help me identify these fields so I can write some code to extract the data?</p><p>Thanks!</p></div>]]>
        </description>
    </item>
    <item>
        <title>SnapMirror peer limits</title>
        <link>https://community.netapp.com/community/discussion/117956/snapmirror-peer-limits</link>
        <pubDate>Tue, 05 Apr 2016 12:19:31 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>alexey_tkachev</dc:creator>
        <guid isPermaLink="false">117956@/community/discussions</guid>
        <description><![CDATA[<div><p>Hi all,</p><p>Does anybody knows how many cluster peer relationships I can have for one cluster (CDOT 8.3.1)? Which limit is if I will use SVM peering? I could not find a clear answer.<br /><br />Thanks in advance.<br /><br />P.S.<br />Yes, I've read the TR-4015</p></div>]]>
        </description>
    </item>
    <item>
        <title>CDOT Snapmirror</title>
        <link>https://community.netapp.com/community/discussion/154633/cdot-snapmirror</link>
        <pubDate>Fri, 28 Feb 2020 15:45:20 +0000</pubDate>
        <category>AFF, AFX, ASA, &amp; FAS</category>
        <dc:creator>lucifer6</dc:creator>
        <guid isPermaLink="false">154633@/community/discussions</guid>
        <description><![CDATA[<div><p>Hi All,</p><p>Need to replicate data between 2 data centers . we have AF series and FAS series and both are Ontap 9.X version.</p><p>below are the plan , Appreciate for help</p><p>1) Network route to be opened?</p><p>2)Open port 10566 for snap mirror replication. Any other ports to be opened?</p><p>3) Do we need perform cluster and SVM&nbsp; peering ? before or after initiating snapmirror? Any firewall ports to be opened?</p><p>thanks</p></div>]]>
        </description>
    </item>
    <item>
        <title>Throttle Active SnapMirror Jobs in Cdot</title>
        <link>https://community.netapp.com/community/discussion/136349/throttle-active-snapmirror-jobs-in-cdot</link>
        <pubDate>Wed, 29 Nov 2017 16:06:35 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>TMADOCTHOMAS</dc:creator>
        <guid isPermaLink="false">136349@/community/discussions</guid>
        <description><![CDATA[<div><p>A few years ago, a colleague&nbsp;created a PowerShell script to throttle active SnapMirror jobs during business hours, and a separate script to unthrottle them at night. The scripts only apply to jobs that run into daytime hours and in some cases continue into a second day. We have to throttle during business hours or it brings these offices to a crawl.</p><p>We are about to convert the filers at our remote offices from 7-mode to cdot. Unfortunately, the "snapmirror throttle" command we use in 7-mode doesn't have an equivalent in cdot. i'm looking online and in help to determine the best way to accomplish the same task in cdot. Everything I've found so far&nbsp;adjusts throttling for the&nbsp;<strong>next</strong> transfer but not the current one. Any ideas?</p><p>Here is an example of the script we use for 7-mode:</p><p>Invoke-NaSsh -Name &lt;filer_name&gt; -Command "snapmirror throttle&nbsp;&lt;amount&gt;&nbsp;&lt;destination_path&gt;"</p></div>]]>
        </description>
    </item>
    <item>
        <title>VM restoration from vault backup using snapcenter plug-in</title>
        <link>https://community.netapp.com/community/discussion/452945/vm-restoration-from-vault-backup-using-snapcenter-plug-in</link>
        <pubDate>Tue, 28 May 2024 18:30:03 +0000</pubDate>
        <category>Virtualization</category>
        <dc:creator>Kalki</dc:creator>
        <guid isPermaLink="false">452945@/community/discussions</guid>
        <description><![CDATA[<div><p>I have snapcenter plug-in for VMware and the underlying protocol is FC for the storage connectivity.&nbsp;</p><p>I want to retain more snapcenter snapshots at the secondary storage and hence planning to use &ldquo;mirror-vault&rdquo; policy for SM relation and update snapvault after back up option in plugin.&nbsp;<br /><br /></p><p>To restore a VM from vault backup what is the connectivity requirement from secondary storage to snapcenter plugin/vcenter/host. Do I need any fc connectivity as primary is based on FC protocol ?</p></div>]]>
        </description>
    </item>
    <item>
        <title>SVM Snapmirror Configuration - Can I modify root volume name post migration?</title>
        <link>https://community.netapp.com/community/discussion/450682/svm-snapmirror-configuration-can-i-modify-root-volume-name-post-migration</link>
        <pubDate>Thu, 08 Feb 2024 04:49:51 +0000</pubDate>
        <category>Data Protection</category>
        <dc:creator>MohitS</dc:creator>
        <guid isPermaLink="false">450682@/community/discussions</guid>
        <description><![CDATA[<div><p>we are migrating from one cluster to another and using SVM snapmirror config to perform the same, in this process the root volume migrated is having the naming convention of source netapp cluster, can I modify this in destination cluster. Will it have any impact?</p></div>]]>
        </description>
    </item>
    <item>
        <title>Powershell New-NcSnapMirrorPolicy</title>
        <link>https://community.netapp.com/community/discussion/445902/powershell-new-ncsnapmirrorpolicy</link>
        <pubDate>Thu, 13 Jul 2023 11:44:12 +0000</pubDate>
        <category>ONTAP APIs &amp; SDKs</category>
        <dc:creator>DWoodberry</dc:creator>
        <guid isPermaLink="false">445902@/community/discussions</guid>
        <description><![CDATA[<div><p>I am trying to recreate a snapmirror policy with schedule that I built out manually on a test cluster.&nbsp; Cluster is running ONTAP 9.12 and my toolkit is 9.12.1.2302.</p><p>My issue is when I try to apply the schedule (Cron Job) to the policy. When using the gui to build everything, I have no issues.&nbsp; Below is my syntax:<br />"New-NcSnapmirrorPolicy -Name 45DailyBackup -Type async -SnapmirrorLabel backup -VserverContext $cluster -CreateSnapshotOnSource $false -Keep 45 -TransferSchedule MAAG-Vault"</p><p>&nbsp;The error I get is (Cannot bind parameter 'TransferSchedule'. Cannot convert the "MAAG-Vault" value of type "System.String" to type "DataONTAP.C.Types.SnapmirrorPolicy.TransferSchedule".)<br />I have tried to assign the "Trasnfer Schedule" as a variable to see if it would convert, but no luck. However, I can use the gui and assign this transfer schedule. I also made an attempt to also use Set-NcSnapmirrorPolicyRule and Add-NcSnapmirrorPolicyRule using my Policy name, but I get "no matching records". Any help would be great as I feel I am missing something simple.&nbsp;<br /><br /></p></div>]]>
        </description>
    </item>
   </channel>
</rss>
