Apache Iceberg backups

Clumio stores your Apache Iceberg backup data in the SecureVault Standard tier — Iceberg-aware, air-gapped backups optimized for operational recovery. You can also take on-demand backups of your Apache Iceberg tables to Clumio SecureVault.

SecureVault Standard

Enable air-gapped, Iceberg-aware backups of your Apache Iceberg tables. Backups are incremental — after the first backup, each subsequent backup captures only the changes since the previous backup — and Clumio preserves Iceberg table metadata and snapshot relationships so that restores are automated and transactionally consistent. Because backups are air-gapped, you can rapidly recover even if your production account is compromised, restoring to the current AWS account or to another AWS account.

You can apply a policy to a single Iceberg table or to multiple tables at once from the Inventory page. For Amazon S3 tables, you can also use tag-based AWS Protection Rules to apply policies automatically across accounts and regions. For more information, see AWS Protection Rules.

On-demand backups

On-demand backups are single backups that you generate manually at any point in time. You can take an on-demand SecureVault Standard backup from an individual table's details page, and you select the retention period when you trigger the backup. On-demand backups are taken one table at a time.

Encryption

Clumio encrypts your Apache Iceberg backup data at rest in Clumio SecureVault. By default, Clumio encrypts it with a Customer Master Key (CMK) that Clumio generates and manages, with automatic key rotation enabled.

To use your own key instead, configure Bring Your Own Key (BYOK) encryption. Apache Iceberg is covered by BYOK with no Iceberg-specific setup. Once BYOK is configured for your organization, Clumio encrypts new Apache Iceberg backup data with your CMK in every region where your backups are stored. Iceberg backup data written before you configured BYOK stays encrypted with the previous key and remains restorable, so keep that key enabled and accessible. For more information, see Bring Your Own Key (BYOK) encryption.

×

Loading...