CACS406 Network Administration

Network AdministrationUnit 710 min read

Backup & Software Repository Services: Types, Tools & Strategies

Unit 7 of Network Administration covers backup strategies (full, incremental, differential), repository services (YUM, APT, Docker Hub), disaster recovery plans, and Linux/Windows commands for verification—with real-world examples from eSewa’s transaction logs and Ncell’s SIM card databases.

TAKEAWAYS:

  • Backup types differ by scope (full, incremental, differential) and must align with RPO/RTO goals—e.g., Ncell’s daily incremental backups of SIM card data ensure 1-hour recovery.
  • Software repositories (YUM, APT, Docker Hub) automate package management, reducing manual updates (e.g., Daraz’s Linux servers use APT for real-time order-processing dependencies).
  • Disaster recovery requires tiered backups (local + cloud) and tested restoration—like NTC’s fiber-optic route backups to prevent outages during landslides.
  • Linux/Windows commands (tar, robocopy, apt-cache) verify backups and repositories; master these for exam scenarios (e.g., "Check if a backup file is corrupted").
  • Repository security uses GPG keys (e.g., WhatsApp’s code-signing repos) and access controls to prevent tampering.
  • Cloud vs. on-premise backups trade cost for latency—e.g., eSewa uses AWS S3 for offsite backups but keeps critical transaction logs on-premise for compliance.

1. Backup Services: Types, Strategies, and Tools

1.1 What is Backup?

Backup is the process of copying and archiving data to a secondary storage medium to prevent loss from hardware failure, cyberattacks, or human error. Key terms:

  • RPO (Recovery Point Objective): Maximum acceptable data loss (e.g., 1 hour for Ncell’s billing system).
  • RTO (Recovery Time Objective): Maximum downtime tolerated (e.g., 4 hours for Daraz’s order processing).
Scheduled (e.g., daily at 2 AM)Copied to NAS (local) + Cloud (AWS S3)Checksum verificationUse latest incremental backupSystem operationalData_CreationBackup_TriggerBackup_CopyData_CorruptionRestore_From_Backup
Backup workflow with RPO/RTO considerations (Ncell/Daraz example)

1.2 Types of Backups

Type Definition Example Use Case Pros Cons
Full Backup Copies all data every time. Monthly backup of NEPSE’s stock transaction logs. Complete recovery, simple. Time-consuming, high storage.
Incremental Copies only changes since last backup (any type). Daily backups of Pathao’s rider location data (only new trips). Fast, low storage. Complex recovery (chain-dependent).
Differential Copies changes since last full backup. Weekly differential backups of Khalti’s wallet data after monthly full backups. Faster than incremental for recovery. Storage grows over time.
Snapshot Point-in-time copy (virtual, no data moved). VMware snapshots of a test server before updates. Instant, low overhead. Not a true backup (risk of corruption).
Copies all dataFull BackupCopies only changes since last backupIncremental BackupCopies changes since last full backupDifferential BackupBackup Types
Comparison of backup types with data scope

Worked Example: Ncell’s SIM Card Database

  • RPO: 15 minutes (critical for subscriber data).
  • Strategy:
    • Full backup: Weekly (stored offline).
    • Incremental: Every 15 minutes (stored on NAS + encrypted cloud).
  • Recovery:
    • If corruption occurs at 3:45 PM, restore the full backup (Sunday) + incremental from 3:30 PM.

1.3 Backup Tools and Commands

Linux:

# Create a full backup (tar + compression)
tar -czvf backup_2024.tar.gz /var/www/html

# Verify checksum (MD5)
md5sum backup_2024.tar.gz

# Schedule daily incremental backups (cron)
0 2 * * * tar -czvf /backups/incremental_$(date +\%Y\%m\%d).tar.gz /var/log/

Windows:

# Create a full backup (robocopy)
robocopy C:\Data E:\Backup\Full\ /MIR /Z /R:3 /W:5

# Verify backup integrity
Get-FileHash -Algorithm SHA256 E:\Backup\Full\*.zip

Cloud Tools:

  • AWS Backup: Automates cross-region replication (e.g., eSewa’s transaction logs).
  • Veeam: Agentless backups for VMs (used by NTC’s core routers).

2. Software Repository Services

2.1 What is a Repository?

A software repository is a centralized storage for software packages, updates, and dependencies. It enables:

  • Version control (e.g., rolling back a misconfigured update).
  • Dependency resolution (e.g., installing nginx pulls in libssl).
  • Security patching (e.g., WhatsApp’s auto-updates from Docker Hub).

2.2 Types of Repositories

Type Example Use Case Command to Use
Package Manager YUM (RHEL), APT (Debian) Daraz’s Linux servers use APT to update order-processing scripts. apt update && apt upgrade -y
Container Registry Docker Hub, ECR Pathao’s microservices pull images from Docker Hub (e.g., nginx:latest). docker pull nginx
Private Repo Nexus, Artifactory NTC’s custom routing software stored in a private Nexus repo. mvn deploy (for Maven packages)

Worked Example: Daraz’s Order Processing System

  • Repository: APT (Ubuntu 22.04).
  • Dependency Chain:
    apt install python3-pip       # Installs Python + pip
    pip install flask==2.0.1      # Locks version for reproducibility
    
  • Why? Ensures all servers run the same flask version to avoid crashes during Black Friday sales.

2.3 Repository Security

  • GPG Keys: Sign packages to prevent tampering (e.g., WhatsApp’s .deb files).
    gpg --import whatsapp_repo.gpg
    
  • Access Control: Restrict repositories to specific IPs (e.g., Ncell’s internal Docker Hub).
  • Vulnerability Scanning: Tools like apt list --upgradable or docker scan.

3. Disaster Recovery Planning (DRP)

3.1 DRP vs. Backup

Aspect Backup Disaster Recovery Plan (DRP)
Goal Restore data. Restore entire system (hardware + data).
Scope Data only. Hardware, network, applications.
Example Restoring NEPSE’s stock data. Rebuilding a crashed NTC router cluster.

3.2 DRP Components

  1. Tiered Backups:
    • Local: NAS (fast, but vulnerable to fire).
    • Offsite: Cloud (AWS S3, encrypted).
    • Air-Gapped: Tape drives (for ransomware).
  2. Failover Testing:
    • Simulate a power outage (e.g., NTC’s UPS + generator test every quarter).
  3. Documentation:
    • Runbook: Step-by-step recovery (e.g., "Replace failed router with spare from rack B").

Worked Example: Kathmandu Traffic Outage

  • Scenario: Major fiber cut during Dashain.
  • DRP Steps:
    1. Activate backup route via NTC’s redundant fiber ring.
    2. Restore traffic data from last incremental backup (RPO: 30 mins).
    3. Notify users via SMS (using Khalti’s bulk SMS API).
Redundant Link (NTC’s fiber ring)Restored TrafficIncremental Sync (RPO: 30 mins)Primary FailureRouter_ARouter_BFiber_CutInternet_GatewayCloud_BackupKathmandu_Network
DRP activation via redundant NTC fiber (Kathmandu example)

4. Exam Tip

What Examiners Want to See:

  1. Backup Strategies:
    • Always compare full vs. incremental vs. differential with RPO/RTO examples.
    • Trace a recovery scenario (e.g., "If a backup fails at 3:00 PM, how do you restore?").
  2. Repository Commands:
    • Linux: apt, yum, docker pull.
    • Windows: robocopy, Get-FileHash.
    • Security: Mention GPG keys or access controls.
  3. DRP:
    • Tiered backups (local + cloud + air-gapped).
    • Real-world tie-in: NTC, eSewa, or Daraz examples.

Common Pitfalls:

  • Forgetting to verify backups (always include md5sum or Test-Restore in answers).
  • Confusing incremental vs. differential (draw a timeline in exams).
  • Ignoring security (e.g., encrypted backups, GPG-signed repos).

In the Real World

  1. eSewa’s Transaction Logs:

    • Backup Strategy: Full backup weekly + incremental every 15 minutes (RPO: 15 mins).
    • Repository: Private Docker Hub for microservices (e.g., esewa-payment-service:v2.1).
    • DRP: If the primary database fails, restore from AWS S3 + failover to a hot standby server in Pokhara.
  2. Ncell’s SIM Card Database:

    • Backup: Incremental backups every 15 mins (stored on NAS + encrypted cloud).
    • Repository: YUM for OS updates (e.g., yum update kernel).
    • DRP: If a data center floods, switch to a pre-configured backup server in Chitwan.
  3. Daraz’s Order Processing:

    • Backup: Differential backups nightly (RPO: 1 hour).
    • Repository: APT for dependencies (e.g., apt install python3.8).
    • DRP: During Diwali sales, if a server crashes, spin up a new VM from a snapshot in AWS.

Practice Questions (Exam-Style)

  1. Short Answer:

    • "Explain how Ncell would implement a differential backup for its SIM card database with an RPO of 1 hour." (Hint: Full backup Sunday, differentials Mon-Sat.)
  2. Command-Based:

    • "Write Linux commands to: a) Create a full backup of /var/www/html to /backups/. b) Verify the backup’s integrity using checksums. c) Schedule a daily incremental backup at 2 AM." (Hint: tar, md5sum, cron.)
  3. Scenario:

    • "The primary database of a bank (like NMB) is corrupted. The last full backup was 3 days ago, and incremental backups are taken daily. Describe the recovery steps if the RTO is 4 hours." (Hint: Restore full + last 3 incrementals.)

Based on the TU BCA syllabus for Network Administration (CACS406), unit 7.

Discussion

Loading…