Backups are ordered by date taken. If you restore to a date where backups exist after that date, then the later backups will be impacted.
Consider the following scenario, where backups have been taken on Fridays over every week.
The following dates are for illustration only and may not conform to actual backup policy.
In this example, April 17th was selected as restore.
|Backups||Available post restore|
|April 3rd, 2020||Available (still displayed)|
|April 10th, 2020||Available (still displayed)|
|April 17th, 2020||Selected for restore.
Available (still displayed)
|April 24th, 2020||No longer available (will not be displayed)|
|May 1st, 2020||No longer available (will not be displayed)|
A number of conditions result in Access Gateway showing no backups.
Backup is considered to be in an initial or empty state after any of several conditions are met. When in an initial state no backups are displayed. Conditions which result in a backup initial state include:
- Post initial deployment - After Access Gateway is initially deployed but before 24 hours have elapsed no backups are available for display.
- Post upgrade from a pre-backup version - When upgrading from a version of Access Gateway that did not support backup, to a newer version which now does, no backups are available. Note pre-administrator facing backup backups can be retrieved by Access Gateway support.
In high availability clusters it is only possible to restore to the admin node. The Access Gateway Management console interface is disabled on worker nodes. Restored configuration is propagated out to all worker nodes. The changes will automatically propagate to the workers. There may be some lag time in between restoring the admin node and the new configuration applying to the workers as requests may be in-flight.
Always be sure that the worker nodes are on a version that is the same as or newer than the admin node before restoring. Restore operations only work against configuration. Appliance version is not involved in backup or restore operations.
If you are using the admin node to proxy connections, we recommend that you remove the admin node from the load-balancer rotation while a restore is in progress.
The actual time a restore takes depends on the size of the Access Gateway high availability cluster as well as the number of applications, data stores, and other configuration. There may be some lag time in between restoring the admin node and the new configuration applying to the workers, as requests may be in-flight. If you are planning to restore from a backup in a production environment, Okta recommends scheduling a maintenance window during which downtime would be acceptable.