Network AdministrationUnit 710 min read
Backup & Software Repository Services: Types, Tools & Strategies
Unit 7 of Network Administration covers backup strategies (full, incremental, differential), repository services (YUM, APT, Docker Hub), disaster recovery plans, and Linux/Windows commands for verification—with real-world examples from eSewa’s transaction logs and Ncell’s SIM card databases.
TAKEAWAYS:
- Backup types differ by scope (full, incremental, differential) and must align with RPO/RTO goals—e.g., Ncell’s daily incremental backups of SIM card data ensure 1-hour recovery.
- Software repositories (YUM, APT, Docker Hub) automate package management, reducing manual updates (e.g., Daraz’s Linux servers use APT for real-time order-processing dependencies).
- Disaster recovery requires tiered backups (local + cloud) and tested restoration—like NTC’s fiber-optic route backups to prevent outages during landslides.
- Linux/Windows commands (
tar,robocopy,apt-cache) verify backups and repositories; master these for exam scenarios (e.g., "Check if a backup file is corrupted"). - Repository security uses GPG keys (e.g., WhatsApp’s code-signing repos) and access controls to prevent tampering.
- Cloud vs. on-premise backups trade cost for latency—e.g., eSewa uses AWS S3 for offsite backups but keeps critical transaction logs on-premise for compliance.
1. Backup Services: Types, Strategies, and Tools
1.1 What is Backup?
Backup is the process of copying and archiving data to a secondary storage medium to prevent loss from hardware failure, cyberattacks, or human error. Key terms:
- RPO (Recovery Point Objective): Maximum acceptable data loss (e.g., 1 hour for Ncell’s billing system).
- RTO (Recovery Time Objective): Maximum downtime tolerated (e.g., 4 hours for Daraz’s order processing).
1.2 Types of Backups
| Type | Definition | Example Use Case | Pros | Cons |
|---|---|---|---|---|
| Full Backup | Copies all data every time. | Monthly backup of NEPSE’s stock transaction logs. | Complete recovery, simple. | Time-consuming, high storage. |
| Incremental | Copies only changes since last backup (any type). | Daily backups of Pathao’s rider location data (only new trips). | Fast, low storage. | Complex recovery (chain-dependent). |
| Differential | Copies changes since last full backup. | Weekly differential backups of Khalti’s wallet data after monthly full backups. | Faster than incremental for recovery. | Storage grows over time. |
| Snapshot | Point-in-time copy (virtual, no data moved). | VMware snapshots of a test server before updates. | Instant, low overhead. | Not a true backup (risk of corruption). |
Worked Example: Ncell’s SIM Card Database
- RPO: 15 minutes (critical for subscriber data).
- Strategy:
- Full backup: Weekly (stored offline).
- Incremental: Every 15 minutes (stored on NAS + encrypted cloud).
- Recovery:
- If corruption occurs at 3:45 PM, restore the full backup (Sunday) + incremental from 3:30 PM.
1.3 Backup Tools and Commands
Linux:
# Create a full backup (tar + compression)
tar -czvf backup_2024.tar.gz /var/www/html
# Verify checksum (MD5)
md5sum backup_2024.tar.gz
# Schedule daily incremental backups (cron)
0 2 * * * tar -czvf /backups/incremental_$(date +\%Y\%m\%d).tar.gz /var/log/
Windows:
# Create a full backup (robocopy)
robocopy C:\Data E:\Backup\Full\ /MIR /Z /R:3 /W:5
# Verify backup integrity
Get-FileHash -Algorithm SHA256 E:\Backup\Full\*.zip
Cloud Tools:
- AWS Backup: Automates cross-region replication (e.g., eSewa’s transaction logs).
- Veeam: Agentless backups for VMs (used by NTC’s core routers).
2. Software Repository Services
2.1 What is a Repository?
A software repository is a centralized storage for software packages, updates, and dependencies. It enables:
- Version control (e.g., rolling back a misconfigured update).
- Dependency resolution (e.g., installing
nginxpulls inlibssl). - Security patching (e.g., WhatsApp’s auto-updates from Docker Hub).
2.2 Types of Repositories
| Type | Example | Use Case | Command to Use |
|---|---|---|---|
| Package Manager | YUM (RHEL), APT (Debian) | Daraz’s Linux servers use APT to update order-processing scripts. | apt update && apt upgrade -y |
| Container Registry | Docker Hub, ECR | Pathao’s microservices pull images from Docker Hub (e.g., nginx:latest). |
docker pull nginx |
| Private Repo | Nexus, Artifactory | NTC’s custom routing software stored in a private Nexus repo. | mvn deploy (for Maven packages) |
Worked Example: Daraz’s Order Processing System
- Repository: APT (Ubuntu 22.04).
- Dependency Chain:
apt install python3-pip # Installs Python + pip pip install flask==2.0.1 # Locks version for reproducibility - Why? Ensures all servers run the same
flaskversion to avoid crashes during Black Friday sales.
2.3 Repository Security
- GPG Keys: Sign packages to prevent tampering (e.g., WhatsApp’s
.debfiles).gpg --import whatsapp_repo.gpg - Access Control: Restrict repositories to specific IPs (e.g., Ncell’s internal Docker Hub).
- Vulnerability Scanning: Tools like
apt list --upgradableordocker scan.
3. Disaster Recovery Planning (DRP)
3.1 DRP vs. Backup
| Aspect | Backup | Disaster Recovery Plan (DRP) |
|---|---|---|
| Goal | Restore data. | Restore entire system (hardware + data). |
| Scope | Data only. | Hardware, network, applications. |
| Example | Restoring NEPSE’s stock data. | Rebuilding a crashed NTC router cluster. |
3.2 DRP Components
- Tiered Backups:
- Local: NAS (fast, but vulnerable to fire).
- Offsite: Cloud (AWS S3, encrypted).
- Air-Gapped: Tape drives (for ransomware).
- Failover Testing:
- Simulate a power outage (e.g., NTC’s UPS + generator test every quarter).
- Documentation:
- Runbook: Step-by-step recovery (e.g., "Replace failed router with spare from rack B").
Worked Example: Kathmandu Traffic Outage
- Scenario: Major fiber cut during Dashain.
- DRP Steps:
- Activate backup route via NTC’s redundant fiber ring.
- Restore traffic data from last incremental backup (RPO: 30 mins).
- Notify users via SMS (using Khalti’s bulk SMS API).
4. Exam Tip
What Examiners Want to See:
- Backup Strategies:
- Always compare full vs. incremental vs. differential with RPO/RTO examples.
- Trace a recovery scenario (e.g., "If a backup fails at 3:00 PM, how do you restore?").
- Repository Commands:
- Linux:
apt,yum,docker pull. - Windows:
robocopy,Get-FileHash. - Security: Mention GPG keys or access controls.
- Linux:
- DRP:
- Tiered backups (local + cloud + air-gapped).
- Real-world tie-in: NTC, eSewa, or Daraz examples.
Common Pitfalls:
- Forgetting to verify backups (always include
md5sumorTest-Restorein answers). - Confusing incremental vs. differential (draw a timeline in exams).
- Ignoring security (e.g., encrypted backups, GPG-signed repos).
In the Real World
eSewa’s Transaction Logs:
- Backup Strategy: Full backup weekly + incremental every 15 minutes (RPO: 15 mins).
- Repository: Private Docker Hub for microservices (e.g.,
esewa-payment-service:v2.1). - DRP: If the primary database fails, restore from AWS S3 + failover to a hot standby server in Pokhara.
Ncell’s SIM Card Database:
- Backup: Incremental backups every 15 mins (stored on NAS + encrypted cloud).
- Repository: YUM for OS updates (e.g.,
yum update kernel). - DRP: If a data center floods, switch to a pre-configured backup server in Chitwan.
Daraz’s Order Processing:
- Backup: Differential backups nightly (RPO: 1 hour).
- Repository: APT for dependencies (e.g.,
apt install python3.8). - DRP: During Diwali sales, if a server crashes, spin up a new VM from a snapshot in AWS.
Practice Questions (Exam-Style)
Short Answer:
- "Explain how Ncell would implement a differential backup for its SIM card database with an RPO of 1 hour." (Hint: Full backup Sunday, differentials Mon-Sat.)
Command-Based:
- "Write Linux commands to:
a) Create a full backup of
/var/www/htmlto/backups/. b) Verify the backup’s integrity using checksums. c) Schedule a daily incremental backup at 2 AM." (Hint:tar,md5sum,cron.)
- "Write Linux commands to:
a) Create a full backup of
Scenario:
- "The primary database of a bank (like NMB) is corrupted. The last full backup was 3 days ago, and incremental backups are taken daily. Describe the recovery steps if the RTO is 4 hours." (Hint: Restore full + last 3 incrementals.)
Based on the TU BCA syllabus for Network Administration (CACS406), unit 7.
Discussion
Loading…