Marcio Cunha

Orchestrating Immutable Backups and Automated Restores with Velero and MinIO

Learn how to design a robust disaster recovery strategy in Kubernetes using Velero for data extraction and MinIO for private cloud object storage with ransomware protection.

Marcio Cunha•4 min
Also available in:EspañolPortuguês
Summary
  • Immutability in MinIO blocks the modification of backup files even during a total Kubernetes cluster compromise.
  • Velero acts as a central orchestrator mapping API resources and persistent volumes for secure copies.
  • Automated restore tests prevent the false sense of security generated by backups never validated in isolated environments.
  • Policy-based retention prevents accidental or malicious deletion of critical production data.
  • Decentralized architecture eliminates public cloud provider dependencies and reduces transfer costs.

The resilience challenge in modern clusters

Managing modern distributed systems built on Kubernetes requires a radical shift in reliability engineering mindset. When an application scales horizontally across hundreds of pods—which are ephemeral software instances running in containers—data persistence ceases to be an operational detail and becomes the core of the business. In practice, this means a cluster can be destroyed and recreated in minutes using infrastructure as code, but if transactional data and customer metadata are lost, the company ceases to exist. The core problem we face in engineering is not just taking copies of files, but ensuring those files are shielded from logical corruption, human error, and destructive cyberattacks such as ransomware.

Velero as the extraction and governance engine

To solve the need to extract cluster state, we use Velero, an open-source tool widely adopted for backing up and restoring Kubernetes resources and persistent volumes. In practice, Velero acts as an intelligent agent that communicates with the cluster API to export the object tree in JSON or YAML format, while interacting with underlying disks through snapshots or direct copies via the S3 protocol. Unlike homegrown scripts based on local commands, Velero manages complex dependencies between resources, ensuring a database is not restored before its respective PersistentVolumeClaim is properly provisioned. This orchestration drastically reduces human error during critical recovery windows.

MinIO for S3-compatible object storage

The destination for all these security copies needs to be a highly durable, scalable, and above all, secure repository. This is where MinIO comes in, a high-performance object storage system compatible with Amazon's standard S3 API, but designed to run on self-hosted infrastructure or private clouds. In practice, MinIO turns bare-metal servers or cloud instances into a secure data lake where each object is indexed and protected by encryption at rest. The great advantage of integrating Velero with MinIO lies in absolute control over the infrastructure, eliminating abusive data egress fees charged by large public cloud providers and guaranteeing total sovereignty over corporate information.

Immutability and protection against destructive attacks

The concept of immutable backup has game-changed information security in recent years. Immutability means that once a backup file is written to MinIO, it cannot be altered or deleted by any user or process—not even by administrators with maximum privileges—until the determined retention period expires. In practice, this completely blocks the action of malicious programs that invade the cluster and attempt to encrypt or delete backups to demand ransoms. MinIO applies this retention policy directly at the object level using the Object Locking feature in Compliance mode, ensuring an insurmountable barrier against internal and external threats.

Architecture and backup operational flow

Building the backup pipeline requires a clean topology where Velero executes scheduled routines through resources called Schedules. In practice, at each configured cycle—for example, every night—Velero triggers a process that captures selected namespaces, packages metadata, and sends the data stream to the immutable bucket in MinIO. During this process, the system uses encrypted TLS connections and restricted access credentials based on the principle of least privilege. In the event of a catastrophic failure in the primary datacenter, the engineering team can point a new Kubernetes cluster to the same MinIO repository and initiate the recovery procedure using the velero restore create command.

Automating restore tests in isolated environments

Having a stored and protected backup is completely useless if you cannot restore it successfully. The software industry is full of tragic stories of companies that discovered flaws in their backup files precisely on the day they needed them. To mitigate this invisible risk, we implement automated restore tests that run periodically on an ephemeral staging cluster. In practice, a Python or Bash script triggered by a CI/CD pipeline instructs Velero to restore the latest backup version in a completely isolated environment, runs a battery of smoke tests to validate database table integrity, and then destroys the test cluster, generating a compliance report.

Practical implementation with manifests and automation

To put theory into practice, we need to configure Velero pointing to our MinIO endpoint with the immutability feature enabled. Below is a practical example of Velero storage configuration using YAML manifest files adapted for this topology.

apiVersion: velero.io/v1
kind: BackupStorageLocation
metadata:
  name: default
  namespace: velero
spec:
  provider: aws
  objectStorage:
    bucket: cluster-backup-imutavel
    prefix: producao
  config:
    region: us-east-1
    s3ForcePathStyle: true
    s3Url: https://minio.empresa.internal

This manifest instructs Velero to direct all compression traffic to the internal MinIO server, using S3-compatible paths and ensuring storage remains isolated from the main infrastructure.

Final considerations on resilience and operational maturity

Combining Velero and MinIO to orchestrate immutable backups and automated restore tests elevates the operational maturity of any organization relying on Kubernetes. By transforming disaster recovery from a manual, stressful task into a continuous, predictable, and code-validated process, engineering gains the necessary peace of mind to innovate faster. In practice, resilience is not an accident, but the result of well-designed architectures that assume failures will happen and prepare to overcome them without data loss or prolonged business disruption.