๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Backup Storage

Choose where your computers' backups are kept: Lavawall storage in Canada or your own S3 bucket. See how much data is protected and how much space it uses, per computer.

Open Backup Storage in your console

Where to find it
Backup & Recovery › Backup Storage
Who can use it
Administrators can see it. Adding buckets, entering access keys, choosing where backups go, copying backups to another bucket and choosing who can use your bucket need a super-admin. An MSP's super-admin can also do this for its client organizations.
For
Computers backed up with Endpoint Backup
Plan
Lavawall Backup. See pricing

What the page is for

Backup Storage is a page in the Lavawall® console, in the Backup & Recovery area. Lavawall is the RMM, security, and compliance platform from ThreeShield, built and hosted in Canada.

By default your backups are kept in Lavawall storage in Canada. Use this page if you would rather keep them in a bucket your organization owns, at Amazon S3, Wasabi, OVHcloud, The Object Store or another S3-compatible provider, for all computers or only some. The page also shows how much data each computer protects, the space its backups use, and how many restore points it has.

Backups are encrypted on each computer before they leave it, so a bucket only ever holds encrypted data. The access key you enter for your own bucket is locked in your browser to the backup relay and to your recovery keys before it is saved. You can instead keep it in the Vault, locked to the backup relays that use the bucket. Either way, Lavawall stores only the locked copy.

When you choose a Lavawall bucket, the page shows its price per TB per month and an estimate of what your backups would cost there. You can also let your child companies keep their backups in a bucket your organization owns.

What you see

  1. Where backups go: the Relay serving your computers, Its standard storage, your Region, and New backups go to, the bucket new computer backups go to and why. Choose a bucket in New backups of your computers go to; the first choice, Lavawall default, follows Lavawall's default for your region. Lavawall buckets show their price, buckets your parent organization shares show shared by and its name, and the line below the choice describes the bucket you picked. MSPs also see an Organization list to work on a client organization.
  2. Your buckets: each bucket of your own, with its provider, bucket name, its Keys, which relay may use it, Price and access (who may use it, and how many companies keep backups there), how many computers keep backups in it, and whether it is on. Buttons: Edit, Enter keys or Enter keys here instead, Re-lock with recovery key, Who can use it, Allow on relay or Stop relay using it, and Turn off or Turn on.
  3. Computers using a different bucket: computers whose new backups go somewhere other than your organization's choice.
  4. Copy to another bucket: copy backups already kept in one bucket to another, and optionally switch to it, with the progress and history of every copy.
  5. Usage: for each computer, the data backed up, the space it uses in the bucket, the number of stored objects, catalogue rows and size, restore points, its size limit, the Estimated monthly cost in a priced Lavawall bucket, and when it was last counted. A tile shows the Estimated monthly cost for your organization.

How to use Backup Storage

How to add your own bucket (super-admin)

  1. At your provider, create the bucket with versioning turned on, and an access key that can only read, write, list and delete in that bucket.
  2. Make sure your organization has a recovery key on the Endpoint Backup page. The access key is locked to it as well.
  3. Under Your buckets, click Add bucket. Enter a Name, choose the Provider, and fill in the Endpoint (leave it empty for Amazon S3), Region, Bucket name and, optionally, a Folder inside the bucket.
  4. Tick Versioning is turned on for this bucket (or The bucket was created with Object Lock) and click Save bucket.
  5. Click Allow on relay on the bucket's row. When asked, enter the Access key ID and Secret access key, click Continue, check who the keys are locked to, and click Lock and save.

Where backups go if you do not choose

If your organization has not chosen a bucket, new computer backups go to the bucket Lavawall sets as the default for your organization's region. Region shows your region and where it comes from: Set for this organization, Inherited from its parent organization, or The default region.

New backups go to names the bucket and gives the reason in brackets:

  • Default for your region: Lavawall's default bucket for the region.
  • Chosen for your organization, Chosen for this organization or Chosen for this computer: a bucket someone chose.
  • Standard storage of the relay that serves your organization: the region has no default, or its default cannot be used for your organization. A note says why, for example because the bucket is not offered to your organization or is not ready on your relay.
  • Lavawall's original storage location: no other choice applies.

US government organizations only use buckets in US government regions. A change to a default never moves backups that already exist.

How to choose where backups go (super-admin)

  1. Under Where backups go, choose a bucket in New backups of your computers go to, or keep Lavawall default to follow the default for your region. A note such as Choosing a bucket here overrides the default for your region tells you what a choice replaces. For a Lavawall bucket, the line below shows its price and the estimated monthly cost if all of your computers' backups were kept there. Click Save.
  2. To send one computer somewhere else, under Computers using a different bucket choose the Computer and the Bucket, then click Use this bucket.
  3. Computers that already have backups keep them where they are. The choice applies to computers starting their first backup. To move existing backups, copy them to the other bucket and switch.

How to choose a bucket for a client organization (MSP super-admin)

  1. Under Where backups go, choose the client in Organization. The card now shows Relay serving its computers and that organization's region and bucket.
  2. Choose a bucket in New backups of this organization's computers go to. The list holds the buckets that organization may use: Lavawall buckets offered to it, its own buckets, and buckets your organization shares with it.
  3. Click Save. New backups go to then shows Chosen for this organization.

You can choose for your direct client organizations that are active. The choice applies to the whole organization, not to single computers.

How to copy backups to another bucket (super-admin)

Use Copy to another bucket to copy computer backups already kept in one bucket to another, for example to Lavawall storage in another region or to your own bucket. Every object is checked after it is copied, and backups keep running while the copy runs.

  1. Under Copy to another bucket, choose Whose backups: Your organization, or one of your client organizations.
  2. Choose the From bucket. The line below shows how many computer backups it holds and how much is stored. Then choose the To bucket.
  3. Under After copying, choose Keep using the current bucket (copy only) for an extra copy, or Switch backups to the new bucket after I confirm to move backups to the new bucket.
  4. Click Start copy, check the summary in Start the copy?, and click Start copy.
  5. Follow the copy in the table: Status, Progress, Data copied, Speed and Time left. It goes from Waiting to start to Copying, Checking the copy and Done.
  6. For a copy and switch, the status stops at Copied: waiting for you to switch. Nothing changes until you click Switch now on the row, then Switch now in the dialog (or Not yet).
  7. The switch pauses those backups for a few minutes while the last changes are copied and checked; the status shows Switching (these backups are paused). Then new backups go to the new bucket, and the status shows Switched to the copied bucket.

Copy only and copy and switch differ in what happens afterwards:

  • Copy (copy only): new backups keep going to the current bucket. The copy holds the backups as they were when it ran. Because it adds stored backups, it needs Lavawall Backup enabled with storage left in your plan.
  • Copy and switch: after you confirm, new backups go to the new bucket. Moving backups does not add to your plan's usage.

The original is never deleted, by a copy or by a switch. When you no longer need it, remove it at the storage provider; for a Lavawall bucket, Lavawall support does this.

To stop a copy, click Cancel on its row and then Cancel the copy (or Keep going). Objects already copied stay in the new bucket, and nothing in the original changes. A switch that has started cannot be cancelled; it usually finishes within minutes. Use Filter copies and the status list (In progress, Waiting for you to switch, Done, Failed, Cancelled) to find a copy.

How price and access work

  • Lavawall sets each Lavawall bucket's price per TB per month, its currency (CAD or USD), and any minimum, and chooses which companies may use it. The price is shown as, for example, $25.00 CAD per TB per month, minimum 100 GB, or Not priced.
  • 1 TB is 1,000 GB stored in the bucket after deduplication and compression. With a minimum, each company is counted as storing at least that much in the bucket each month.
  • You only see the buckets your organization may use. Standard storage of the relay (not available to your organization) means you need to choose another bucket.
  • For your own bucket, you pay your storage provider directly, so it shows no price here.

How to read the cost estimates

  • When you choose a Lavawall bucket, the estimate is the space your computers' backups use now (or the minimum, if that is more) at that bucket's price.
  • In Usage, Estimated monthly cost uses the latest count of each computer's space in a priced Lavawall bucket. Your organization's total includes any minimum per bucket; a single computer's figure does not.
  • These are estimates to help you plan, not an invoice.

How to let your child companies use your bucket (super-admin)

  1. Under Your buckets, click Who can use it on the bucket's row.
  2. Under Who may use this bucket, choose Your organization and its child companies, or Only your organization to keep it to yourselves.
  3. Click Save.
  4. Click Allow on relay for the relay that serves your child companies, if it is not allowed already.

Child companies can then choose the bucket for their computers. They never see its keys or its address, and your organization pays your provider for everything stored in it. Child companies means your direct child companies that are active clients.

If narrowing who may use a bucket would cut off companies that already keep backups there, you are asked Change who may use the bucket first, with how many companies and computers would lose access. Their backups and restores stop until they are allowed again; nothing in the bucket is deleted. Type the number of companies and click Save anyway to go ahead.

How to keep a bucket's keys in the Vault (super-admin)

  1. Open the Vault, unlock it, and click the Script secrets tab.
  2. Under Backup storage keys, click Keep keys in the vault on the bucket's row, enter the Access key ID and Secret access key, and click Save keys.
  3. Back on this page, the bucket's Keys show Keys kept in the vault and Ready.

A bucket whose keys are in the Vault shows one of these:

  • Ready: every relay allowed to use the bucket can read its keys.
  • A relay is missing them: a relay was allowed after the keys were saved. Click Manage keys in the vault, then Seal to new relays.
  • Not linked yet: no keys have been saved in the Vault for this bucket. Click Manage keys in the vault.

To go back to entering the keys on this page, click Enter keys here instead.

How to give a new relay the keys without typing them (super-admin)

  1. Click Re-lock with recovery key on the bucket's row.
  2. Choose the Recovery key and select its Recovery key file. The file is read in your browser only and is never uploaded.
  3. Check the list and click Lock and save.

How to read the usage table

  • Data backed up is the size of the files protected in the newest backup of each folder.
  • Space in bucket is what the encrypted, compressed and de-duplicated backups take up, across all restore points. It is often smaller than the data backed up.
  • Catalogue rows and Catalogue size are the file listings Lavawall keeps so you can search and browse past backups.
  • Counts refresh every few hours. Counted shows when.
  • Estimated monthly cost shows Not priced for buckets without a price, including your own.

Tips

  • Keep versioning on. If a backup is ever removed by mistake, your provider can bring it back.
  • Set a size limit per computer on the Endpoint Backup page, and choose how far back you can restore in each backup set.
  • Turning a bucket off stops backups and restores for the computers that use it. Nothing in the bucket is deleted.
  • After you change the access key at your provider, click Enter keys and enter the new one.

Troubleshooting

"A relay is missing them"
The bucket is allowed on a relay that has no copy of its access key. Click Re-lock with recovery key, or Enter keys again. If the keys are kept in the Vault, click Manage keys in the vault, then Seal to new relays.
"Give the relay the keys"
You allowed a relay on a bucket whose keys are kept in the Vault. Click Manage keys in the vault to give it the keys; until then it cannot use the bucket.
"Update the keys in the vault"
The bucket's location changed, so the keys in the Vault still name the old bucket. Save them again in the Vault with Manage keys in the vault.
"Change who may use โ€ฆ?"
The new choice would stop companies that already keep backups in the bucket. Cancel to keep things as they are, or type the number of companies and click Save anyway.
"Create a backup recovery key first"
Create a recovery key on the Endpoint Backup page, then enter the keys again.
"Enter this bucket's access keys first, so the relay can use it"
Save the bucket's keys before you send computers to it.
"Computers already keep backups in this bucket, so where it points cannot change"
Add another bucket for the new location and send new computers there.
"This file is not the private key for the selected recovery key"
Choose the key file that belongs to the recovery key selected in the list.
Usage shows nothing yet
Counts appear a few hours after the first backup.
"The default for โ€ฆ is not used: โ€ฆ"
Lavawall's default bucket for your region cannot be used for your organization, for the reason given. New backups go to the relay's standard storage instead, or you can choose a bucket.
"The chosen bucket cannot be used right now (โ€ฆ)"
The bucket is turned off, not offered to this organization, or not ready on its relay. New backups do not start until this is fixed, or until you choose another bucket.
"The relay's standard storage is not available to this organization. Choose a bucket."
Choose a bucket in New backups of your computers go to and click Save.
"Both buckets must be turned on."
Turn on both buckets, or choose others.
"This organization has no backups in that bucket."
Choose the bucket that holds its backups as the From bucket.
"A copy adds stored backups, so it needs Lavawall Backup enabled with storage left."
Ask your provider to turn on Lavawall Backup or add capacity, or choose Switch backups to the new bucket after I confirm to move the backups instead.
"The copy would pass the destination bucket's size limit."
Choose another destination bucket.
"The copy would pass this organization's backup storage ceiling."
A copy only would take the organization past its plan's capacity. Ask your provider to add capacity, or choose Switch backups to the new bucket after I confirm to move the backups instead.
"No backup relay can use both buckets. Allow one relay on both buckets, with their keys, first."
Click Allow on relay on both buckets for the same relay, and give it their keys.
A destination says "not ready for a switch"
It can receive a copy, but backups cannot be switched to it until it is ready on the relay that serves these computers. Allow the relay on it and give it the keys.
"A US government organization's backups can only go to a bucket in a US government region."
Choose a bucket in a US government region.
A copy shows Failed
The reason is shown under the status. Nothing in the original bucket changed. Fix the cause and start the copy again.
"The switch is under way and cannot be stopped now. It usually finishes within minutes."
Wait for the switch to finish. Stop the switch appears only if the relay doing the switch stops responding; stopping releases the paused backups.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on: