From 2f5021014d9079f99b6e88935d3167dd9c6b3c00 Mon Sep 17 00:00:00 2001 From: ArnauGabrielAtienza Date: Thu, 3 Sep 2026 12:25:41 +0200 Subject: [PATCH] update Veeam docs Signed-off-by: ArnauGabrielAtienza --- .../backup_system/veeam.md | 69 +++++++++++++++++++ 1 file changed, 69 insertions(+) diff --git a/content/product/cluster_configuration/backup_system/veeam.md b/content/product/cluster_configuration/backup_system/veeam.md index 9c97bbb3d..2f9e98fd4 100644 --- a/content/product/cluster_configuration/backup_system/veeam.md +++ b/content/product/cluster_configuration/backup_system/veeam.md @@ -156,6 +156,7 @@ The configuration file can be found at `/etc/one/ovirtapi-server.yml`. Change th In the same configuration file, configure the OneBEX port and the port range reserved for interactive restores: * `onebex_port`: Port where OneBEX listens on the hypervisors. It must match the port configured in `onebex-server.conf`. +* `onebex_port_ssl`: Alternative port used for SSL. Optional, but recommended for secure Image Transfers. If used, it is mandatory to follow section 4.1 to enable this feature in the hosts. The recommended port is 13015. * `port_min` and `port_max`: Range of available ports reserved for interactive restores. * `ports_path`: File where the oVirtAPI Server tracks ports used for interactive restores. @@ -179,6 +180,74 @@ If the ovirtapi module is going to be configured in High Availability mode, the {{< /alert >}} +#### 4.1 Configuring SSL in the Hosts + +If using SSL, an NGINX proxy needs to be setup on all hosts. If an Image Transfer is attempted by Veeam against a non-configured host while the `onebex_port_ssl` variable is defined, the backup will fail. + +First, you will need to create a certificate for the host. This certificate needs to be signed by the CA authority used by the ovirtAPI server (defined as `cert_path` in the configuration file.). To make this task easier, a script is provided at `/usr/lib/one/ovirtapi-server/scripts/generate_certificate.sh`. You can run it with: + +```shell +./generate_certs.sh -n -c -k -C -K +``` + +After generating the certificate, copy it to the respective host. We recommend storing it in `/etc/one`. + +Then, you will need to install nginx on the host. + +```shell +apt install nginx # Ubuntu/Debian +dnf install nginx # Rhel/Alma +``` + +Depending on the distribution, you will need to create the configuration file on a different location: + +```shell +/etc/nginx/sites-enabled/one-ssl.conf # Ubuntu/Debian +/etc/nginx/conf.d/one-ssl.conf # Rhel/Alma +``` + +The configuration file must look like the following. Change the `ssl_certificate` and `ssl_certificate_key` paths to the ones you generated for this host. If you used a different port than 13015 in the ovirtapi configuration for SSL, make sure to change it in this configuration too. + +```conf +server { + listen 13015 ssl; + listen [::]:13015 ssl; + server_name _; + + # TLS Certificates + ssl_certificate /etc/one/ovirtapi-ssl.crt; + ssl_certificate_key /etc/one/ovirtapi-ssl.key; + + # Secure TLS Defaults + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; + + # Crucial for large disk transfers + client_max_body_size 0; + proxy_request_buffering off; + proxy_buffering off; + + # Extended timeouts for large images + proxy_read_timeout 3600s; + proxy_send_timeout 3600s; + client_body_timeout 3600s; + + location / { + proxy_pass http://127.0.0.1:13014; + + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto https; + + proxy_http_version 1.1; + proxy_set_header Connection ""; + } +} +``` + +Finally, start/restart nginx to load the configuration file. You will need to repeat this workflow for each host. + ### 5. Add OpenNebula to Veeam This section will address the necessary steps to add OpenNebula as a Virtualization Platform into Veeam and deploy the necessary workers.