Backup Frequently Asked Questions
- I want to restore a later backup. Will I lose my earlier backups?
- Where are my backups?
- Where do I perform a restore?
- Can I restore across versions? Are there any version constraints for restore?
- I have a high availability cluster fronted by a load balancer. Are there any special considerations for this architecture?
- How long do restores take?
Backups are ordered by date taken. If you restore to a date where backups exist after that date then the later backups will be impacted.
Consider the following scenario, where backups have been taken on Fridays over every week.
Note the following dates are for illustration only and may not conform to actual backup policy.
In this example April 17th was selected as restore
|Backups||Available post restore|
|April 3rd, 2020||Available (still displayed)|
|April 10th, 2020||Available (still displayed)|
|April 17th, 2020||Selected for restore.
Available (still displayed)
|April 24th, 2020||No longer available (will not be displayed)|
|May 1st, 2020||No longer available (will not be displayed)|
A number of conditions result in Access Gateway showing no backups.
Conditions which result in a backup initial state include:
Backup is considered to be in an initial or empty state after any of several conditions are met. When in an initial state no backups are displayed.
- Post initial deployment - After Access Gateway is initially deployed but before 24 hours have elapsed no backups are available for display.
- Post upgrade from a pre-backup version - When upgrading from a version of Access Gateway which did not support backup, to a newer version which now does, no backups are available. Note pre-administrator facing backup backups can be retrieved by Access Gateway support.
In High Availability clusters it is only possible to restore on an restore on the adminAn abbreviation of administrator. This is the individual(s) who have access to the Okta Administrator Dashboard. They control the provisioning and deprovisioning of end users, the assigning of apps, the resetting of passwords, and the overall end user experience. Only administrators have the Administration button on the upper right side of the My Applications page. node. The Access Gateway console interface is disabled on worker nodes. Restored configuration is propagated out to all worker nodes.
the changes will automatically propagate to the workers.
There may be some lag time in between restoring the admin node and the new configuration applying to the workers, as requests may be in-flight.
Always be sure that the worker nodes are on a version that is the same as or newer than the admin node before restoring. Restore operations only work against configuration. Appliance version is not involved in backup or restore operations.
If you are using the admin node to proxy connections, we recommend that you remove the admin node from the load-balancer rotation while a restore is in progress.
The actual time a restore takes is dependent on the size of the Access Gateway HA cluster as well as the number of applications, data stores and other configuration.
There may be some lag time in between restoring the admin node and the new configuration applying to the workers, as requests may be in-flight. If you are planning to restore from a backup in a production environment, Okta recommends scheduling a maintenance window in which downtime would be acceptable.