You can perform backups automatically based on the configuration for a hypervisor or VM group, or manually for a VM group or a specific instance.
The first backup of an instance is always a full backup. By default, all subsequent backups are incremental, capturing any changes to instance data since the last backup.
You can recover instance data, even when the most recent backup was incremental.
You can configure a Google Cloud (GC) hypervisor to perform streaming or IntelliSnap backups.
Note
If an instance fails to back up during an IntelliSnap backup of a VM group, the backup job is marked as completed with errors.
What Gets Backed Up
-
Deletion Protection settings
-
Instances (powered on or powered off)
-
Configuration files for each instance
-
Instance disks
-
Regional persistent disks (standard and solid-state drive)
-
Instance disks that are encrypted at the software protection level and Hardware Security Module (HSM) protection level with a customer-managed encryption key
-
Instance disks that are encrypted at the software protection level with a customer-managed encryption key
You can generate customer-managed encryption keys using the Google Cloud Key Management Service.
-
Disks encrypted using customer-managed encryption keys stored externally via Cloud External Key Manager (Cloud EKM) are also protected
-
Shielded VMs, which provide advanced security features like secure boot, integrity monitoring and vTPM, are fully supported for backup, ensuring that even hardened workloads are covered.
Note
Guest file restore is not supported for Shielded VMs if the guest OS drives are encrypted with BitLocker. For more information on Shielded VMs, see Learn more about Shielded VMs on Google Cloud
-
Supported Disk Types:
-
HyperDisks:
-
HyperDisk Balanced
-
Hyperdisk Extreme
-
Hyperdisk Throughput
-
Hyperdisk ML
-
Hyperdisk Balanced HA
-
-
Persistent Disks:
-
SSD Persistent Disk
-
Balanced Persistent Disk
-
Extreme Persistent Disk
-
Standard Persistent Disk
-
-
What Does Not Get Backed Up
-
Images
-
Instance disks that are encrypted with a customer-supplied encryption key and Cloud EKM
-
Local solid-state drive (SSD) scratch disks
When local SSD scratch disks reside on an instance with other supported disks, during the backup operation, the SSD scratch disks are skipped. The other disks are included in the backup.