Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. Cohesity Cloud Scale Technology Manual Deployment Guide for Kubernetes Clusters
  3. Section III. Monitoring and Management
  4. Performing catalog backup and recovery
  5. Backing up a catalog
Cohesity Cloud Scale Technology Manual Deployment Guide for Kubernetes Clusters

Backing up a catalog

You can backup a catalog by using one of the following methods:

  • Automatically

  • Manually

Automatic creation of catalog backup policy

You can backup a catalog by using the automatically created catalog backup policy which is applicable only for fresh/new deployment.

To backup a catalog automatically

  1. A catalog backup policy can be automatically configured during a new installation. This can be done by supplying the DR Secret through the drInfoSecret field of the environment.Spec in helm/values.yaml file.
  2. The drInfoSecret field must be created before deployment using the following command:

    kubectl create secret generic dr-info-secret --namespace <nbu-namespace> --from-literal=passphrase="Y@123abCdEf" --from-literal=emailAddress="abc@xyz.com"

    The passphrase field is compulsory.

  3. Once catalog policy is created, configure Recovery Vault storage in the catalog backup policy. For more information, see NetBackup Deduplication Guide.
  4. In the automatically configured catalog backup policy, the DR package path is set to /mnt/nbdb/usr/openv/drpackage_<storage server name>. If required, this can be changed by editing the policy from the Web UI.
  5. If the email field is included in the DR Secret, then on running a catalog backup job, the created DRPackages would be sent through email. this is applicable only when the e-mail server is configured. Configuring email server
Manual creation of catalog backup policy

To backup a catalog manually

  1. Exec into the primary server pod using the following command:

    kubectl exec -it -n <namespace> <primary-pod-name> -- /bin/bash

  2. Create a directory DRPackages at persisted location using mkdir /mnt/nblogs/DRPackages.
  3. Change ownership of DRPackages folder to service user using chown nbsvcusr:nbsvcusr /mnt/nblogs/DRPackages.
  4. Set the passphrase to be used at time of catalog recovery.
    • Open NetBackup Administrator Console (Java UI).

    • Navigate to Security Management > Global Security Setting > Disaster Recovery.

    • In Encryption for Disaster Recovery section, add the passphrase, confirm passphrase, and save it.

  5. Add respective external media server entry in host properties through NetBackup Management > Host properties > Master Server > Add Additional server.

    Note:

    It is recommended to use an external media server for catalog backup and recovery.

  6. Exec into the primary server pod using the following command:

    kubectl exec -it -n <namespace> <primaryserver pod name> -- bash

    Set the KMS_CONFIG_IN_CATALOG_BKUP configuration option to 1 in /usr/openv/netbackup/bp.conf file of primary server to include the KMS configuration as part of the disaster recovery package during catalog backup.

  7. Restart the NetBackup services in primary and external media server.
    • Exec into the primary server pod using the following command:

      kubectl exec -it -n <namespace> <primary-pod-name> -- /bin/bash

    • Deactivate NetBackup health probes using the /opt/veritas/vxapp-manage/nb-health deactivate command.

    • Run the /usr/openv/netbackup/bin/bp.kill_all command. After stopping all services restart the services using the /usr/openv/netbackup/bin/bp.start_all command.

    • Activate NetBackup health probes using the /opt/veritas/vxapp-manage/nb-health activate command.

    • Run the /usr/openv/netbackup/bin/bp.kill_all command. After stopping all services restart the services using the /usr/openv/netbackup/bin/bp.start_all command on the external media server.

  8. Configure storage unit on earlier added external media server.

    For more information, refer to the NetBackup™ Administrator's Guide,Volume I

    Note:

    It is recommended to use AdvancedDisk or BasicDisk storage unit.

  9. Configure NetBackup catalog backup policy.

    Add package path as /mnt/nblogs/DRPackages while configuring the catalog backup policy.

  10. Run the catalog backup job.

Feedback

Was this page helpful?
Previous

Performing catalog backup and recovery

Next

Restoring a catalog

Feedback

Was this page helpful?