Veeam SureBackup: Verify Backups Actually Restore - 夜莺博客

Veeam SureBackup: Verify Backups Actually Restore

An exit code of "Success" on a backup job only proves that data was written, not that the machine will boot. Veeam SureBackup closes that gap by publishing restore points inside an isolated virtual lab, starting the VMs there and running real tests against them, while production keeps running untouched. This guide covers the three objects you configure once, the verification levels worth enabling, and the traps that make SureBackup jobs fail for reasons that have nothing to do with the backup itself.

Three components, configured once and reused

Application group defines which machines boot and in what order -- directory server first, then database, then application. Booting everything simultaneously produces false failures because dependencies are not yet available. Virtual lab provides the isolated network: a proxy appliance masquerades production addressing so verified VMs keep their original IP configuration without colliding with live hosts. SureBackup job ties the two together, selects the backup jobs to verify, runs the tests and produces a report. Because the lab uses instant recovery from the repository, nothing is restored to production storage. Compare this with storage-level verification such as Proxmox Backup Server: Prune, Garbage Collection and Verify, which proves data integrity but not whether a workload boots.

Two verification modes

  • Full recoverability testing - boots VMs in the lab and runs heartbeat, ping and application scripts. Requires a virtual lab plus an application group and an Enterprise-edition licence.
  • Backup verification and content scan only - integrity checks and malware scanning with no virtual lab; useful for Veeam Agent backups and for repositories where you mostly care about corruption and ransomware.

Creating the job

Home > Jobs > SureBackup Job (wizard)
  Name:        SB-CoreServices
  Mode:        Full recoverability testing
  Virtual Lab: Lab-Prod-Mirror
  App Group:   AG-Corp-Services
  Linked Jobs: JOB-VMware-Daily (test VMs, roles, tests)
  Settings:    CRC check + malware scan, SNMP/email report
  Schedule:    daily, after the backup chain completes

For each linked job, define the VM role and startup settings, then select tests. Veeam ships predefined scripts for common services and accepts custom scripts: a SQL query that returns a row, or an HTTP request expected to answer 200, is what actually proves the application recovers.

Traps worth knowing before the first run

  • Application group and verified VMs must be on the same platform; VMware and Hyper-V cannot be mixed in one job.
  • Windows machines with pending updates may reboot mid-test and fail the job.
  • If a verification check fails, Veeam marks that restore point and all later points in the chain as infected -- investigate before the status spreads.
  • Record the actual recovery time from each run and compare it against the RTO you promised; that number is the only empirical evidence your recovery plan is real.

A nightly SureBackup job turns "we think the backups are fine" into a report in your inbox. Where replication rather than backup is the recovery mechanism, the failover considerations in PostgreSQL Streaming Replication and Safe Failover apply instead.

原文链接:https://helpcenter.veeam.com/docs/vbr/userguide/recovery_verification_surebackup_job.html