Cleanroom recovery helps you test, investigate, and recover from cyber attacks in an isolated recovery environment.
Many disaster recovery plans handle outages, but they are not enough for targeted cyber attacks. A cleanroom site, also called an isolated recovery environment, gives you a clean place to recover data and restore operations.
Videos
- Customer video: Commvault SaaS Cleanroom Recovery
- Partner video: CSF SaaS Cleanroom Recovery
Key features
Cleanroom recovery supports continuous testing, forensic analysis, and recovery in a secure isolated environment.
-
Active Directory recovery and validation: Restore and validate domain controllers in an isolated environment to ensure authentication and identity services function correctly before bringing dependent applications back online.
-
Continuous testing: Use the cleanroom site to simulate recovery scenarios and validate your cyber recovery plans.
-
Forensic investigation: Analyze attack timelines, identify root causes, and safely test remediation steps before applying them to production.
-
Recovery to an isolated environment: Recover clean data from backups and restore operations in a secure environment when production is compromised.
-
Flexible deployment models: Cleanroom recovery can be deployed as a Commvault-managed isolated environment, where Commvault manages the infrastructure and lifecycle, or as a self-managed environment, giving you full control over architecture, security, and operations. This includes support for fully on-premises isolated recovery environments using HyperScale X (HSX) as an air-gapped vault and VMware ESXi. For more information, see On-premises cleanroom sites.
Support
Cleanroom recovery supports key resources for recovery to cloud and on-prem cleanroom sites.
| Workload | Supported | Not supported |
|---|---|---|
| Amazon EC2 | • Linux VMs • Windows VMs |
Instances with independent disks |
| Azure Virtual Machines | • Linux VMs • Windows VMs |
Instances with independent disks |
| Azure Local | • Linux VMs • Windows VMs |
Instances with independent disks |
| Hyper-V | • Linux VMs • Windows VMs |
Instances with independent disks |
| VMware, on-premises | • Linux VMs • Windows VMs |
Instances with independent disks |
| VMware Cloud on AWS | • Linux VMs • Windows VMs |
Instances with independent disks |
| Google Cloud VMware Engine | • Linux VMs • Windows VMs |
Instances with independent disks |
| Oracle Cloud VMware Solution | • Linux VMs • Windows VMs |
Instances with independent disks |
| Active Directory | • Single domain controller VM recovery (via cleanroom runbooks) • Full forest recovery (via Active Directory forest runbooks from recovered control plane) • Windows-to-Windows recovery • Post-recovery manual registration of recovered servers back to the control plane |
• Full forest recovery via cleanroom runbooks • Linux VMs |
| SQL Server | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery • Windows-to-Windows recovery |
Orchestrated restore of latest databases into recovered VM using runbooks |
| Oracle Database | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery • Windows-to-Windows recovery |
Orchestrated restore of latest databases into recovered VM using runbooks |
| MySQL | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery • Windows-to-Windows recovery |
Orchestrated restore of latest databases into recovered VM using runbooks |
| PostgreSQL | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery • Windows-to-Windows recovery |
Orchestrated restore of latest databases into recovered VM using runbooks |
| SAP HANA | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery |
• Orchestrated restore of latest databases into recovered VM using runbooks • Windows-to-Windows recovery |
| IBM Db2 | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery • Windows-to-Windows recovery |
Orchestrated restore of latest databases into recovered VM using runbooks |
| Epic EHR (InterSystems IRIS Caché) | • IaaS recovery as part of VM recovery • Linux-to-Linux recovery |
Windows-to-Windows recovery |
| Workload | Supported | Not supported |
|---|---|---|
| Amazon EC2 | • Linux VMs • Windows VMs |
Instances with independent disks |
| Azure Virtual Machines | • Linux VMs • Windows VMs |
Instances with independent disks |
| Azure Stack Hub | • Linux VMs • Windows VMs |
Instances with independent disks |
| Azure Local | • Linux VMs • Windows VMs |
Instances with independent disks |
| Google Cloud | • Linux VMs • Windows VMs |
Instances with independent disks |
| Hyper-V | • Linux VMs • Windows VMs |
Instances with independent disks |
| Nutanix AHV | • Linux VMs • Windows VMs |
Instances with independent disks |
| Oracle VM | • Linux VMs • Windows VMs |
Instances with independent disks |
| VMware, on-premises | • Linux VMs • Windows VMs |
Instances with independent disks |
| Azure VMware Solution | • Linux VMs • Windows VMs |
Instances with independent disks |
| Google Cloud VMware Engine | • Linux VMs • Windows VMs |
Instances with independent disks |
| Oracle Cloud VMware Solution | • Linux VMs • Windows VMs |
Instances with independent disks |
| VMware Cloud on AWS | • Linux VMs • Windows VMs |
Instances with independent disks |
| VMware Cloud Director | • Linux VMs • Windows VMs |
Instances with independent disks |
| Active Directory | • Full forest recovery • Single domain controller VM recovery • Windows-to-Windows recovery • Post-recovery registration of recovered servers back to the control plane |
Linux VMs |
| SQL Server | • Iaas recovery as part of VM recovery • Orchestrated restore of latest databases to recovered VMs using runbooks • Linux-to-Windows recovery • Windows-to-Windows recovery |
|
| Oracle Database | • Iaas recovery as part of VM recovery • Manual restore of latest databases to recovered VM • Linux-to-Windows recovery • Windows-to-Windows recovery |
Orchestrated restore of latest databases to recovered VMs using runbooks |
| MySQL | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery • Windows-to-Windows recovery |
Orchestrated restore of latest DBs into recovered VM using runbooks |
| PostgreSQL | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery • Windows-to-Windows recovery |
Orchestrated restore of latest DBs into recovered VM using runbooks |
| SAP HANA | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery |
• Orchestrated restore of latest DBs into recovered VM using runbooks • Windows-to-Windows recovery |
| IBM Db2 | • IaaS recovery as part of VM recovery • Manual restore of latest databases into recovered VM • Linux-to-Linux recovery • Windows-to-Windows recovery |
Orchestrated restore of latest DBs into recovered VM using runbooks |
| Epic EHR (InterSystems IRIS Caché) | • IaaS recovery as part of VM recovery • Linux-to-Linux recovery |
Windows-to-Windows recovery |
| Azure NetApp Files | • Recovery to Azure Files • Windows-to-Windows recovery • CIFS shares |
• Linux-to-Linux recovery • NFS shares |
| Network-attached storage (NAS) servers | • Recovery to Azure Files • Windows-to-Windows recovery • CIFS shares |
• Linux-to-Linux recovery • NFS shares |
| Nutanix Files | • Recovery to Azure Files • Windows-to-Windows recovery • CIFS shares |
• Linux-to-Linux recovery • NFS shares |
| Qumulo file storage | • Recovery to Azure Files • Windows-to-Windows recovery • CIFS shares |
• Linux-to-Linux recovery • NFS shares |
| Windows file system | • Recovery to Azure Files • Windows-to-Windows recovery |
• Linux-to-Linux recovery • NFS shares |
Support for Linux and Windows VMs
Linux and Windows VMs are supported for all workloads:
-
VMware VMs
-
VMware VMs on-premises
-
VMware Cloud on AWS
-
VMware Cloud Director
-
Google Cloud VMware Engine
-
Hyper-V VMs
-
Oracle Cloud VMware Solution
-
Amazon EC2
-
Azure Resource Manager
-
Azure Local
-
Google Cloud
-
Nutanix AHV
Support for IP customization
IP customization is supported for on-prem workloads only:
-
VMware VMs
-
VMware VMs on-premises
-
VMware Cloud on AWS
-
VMware Cloud Director
-
Google Cloud VMware Engine
-
Hyper-V VMs
-
Oracle Cloud VMware Solution
Support for databases and file servers
The following databases and file servers are supported for manual restore of the latest databases or files to the recovered VM:
-
SQL Server
-
Oracle Database
-
MySQL
-
PostgreSQL
-
SAP HANA
-
IBM Db2
-
Windows file system
Not supported
-
Instances with independent disks
-
Encrypted Azure disks
-
VMs that do not have an attached disk
-
Physical RDMs
-
VMs with SCSI adapters configured for bus sharing (physical or virtual)
-
Disks that use the multi-writer option
-
Free ESXi license
-
High Availability (HA) settings
-
Page files and swap files
Additional support boundaries
-
Recovery configuration is standalone—recovery from and to a single server.
-
Backups are:
-
Linux: Crash-consistent
-
Windows: Application-consistent
-
-
File system subclients with the block-level backup setting enabled aren't supported.