All pages
Powered by GitBook
1 of 1

Loading...

Veeam Agent Installation for CentOS 9 Stream

Overview

This document is for installing the Veeam Backup Agent Linux on CentOS 9 Stream.

Procedure

  • OS: CentOS 9 Stream, running kernel 5.14.0-344.el9.x86_64

  • Veeam repository: veeam-release-el9-1.0.8-1.x86_64.rpm

  • Veeam Agent: veeam-6.0.3.1221-1.el9.x86_64

Step 1: Download Veeam repository:

The Veeam repository for Linux can be found at . On this page, select "veeam-release-el9-1.0.8-1.x86_64.rpm".

Step 2: Install Veeam and dependencies:

  • This will download an RPM file. You will likely be unable to download this directly from this page to your Linux machine, as your server will likely not have a GUI or web browser. To get around this, it is best to download the RPM to your workstation and then use WinSCP or MobaXterm to copy the RPM file to your server via SSH.

  • Once the RPM is on your server, install it and its dependencies:

  • The modules bdevfilter and blksnap will be created in /lib/modules/$(uname -r)/extra

  • We can confirm that this module has not loaded by running lsmod, and grepping for blksnap. We will see that grep returns 0 lines of output.

Step 3: Insert modules bdevfilter and blksnap:

We need to load the module into the currently running kernel using insmod:

At this point, our agent-based backups will run fine; however, the loaded module will not persist if we reboot. We must create a file called /etc/modules-load.d/bdevfilter.conf and/etc/modules-load.d/blksnap.conf , and make sure that it has the name of the kernel module. We must also run depmod to add the loaded kernel module to the kernel module dependencies list.

Once we reboot the CentOS server, the veeamsnap module will automatically be loaded as a kernel module.

And our agent-based backups will now work correctly.

Grand permission for 3 scripts:

# chmod u+x one-time-setup sign-modules dkms-sign-module

Create 2 files for signing modules to the UEFI database.

Run the file one-time-setup first and then reboot:

During the reboot, when prompted, press any key to perform MOK management.

At the wizard's first step, select Enroll MOK and press [Enter].

At the Enroll the key(s) step, select Yes and press [Enter].

Provide the password for the root account and press [Enter].

At the final step, select Reboot and press [Enter].

After that, sign 2 modules by running file sign-modules:

Step 4: Insert modules bdevfilter and blksnap:

We need to load the module into the currently running kernel using insmod:

At this point, our agent-based backups will run fine; however, the loaded module will not persist if we reboot. We must create a file called /etc/modules-load.d/bdevfilter.conf and/etc/modules-load.d/blksnap.conf , and make sure that it has the name of the kernel module. We must also run depmod to add the loaded kernel module to the kernel module dependencies list.

Once we reboot the CentOS server, the veeamsnap module will automatically be loaded as a kernel module.

And our agent-based backups will now work correctly.

Step 1: Download Veeam repository:

The Veeam repository for Linux can be found at . On this page, select "veeam-release-el9-1.0.8-1.x86_64.rpm".

Step 2: Install Veeam and dependencies:

  • This will download an RPM file. You will likely be unable to download this directly from this page to your Linux machine, as your server will likely not have a GUI or web browser. To get around this, it is best to download the RPM to your workstation and then use WinSCP or MobaXterm to copy the RPM file to your server via SSH.

  • Once the RPM is on your server, install it and its dependencies:

  • The modules bdevfilter and blksnap will be created in /lib/modules/$(uname -r)/extra

    • We can confirm that this module has not loaded by running lsmod, and grepping for blksnap. We will see that grep returns 0 lines of output.

    Step 3: Enrolling Veeam Kernel Module Key:

    Create a directory /root/module-signing:

    Download 3 scripts from the link: and put it in the directory just created:

    Grand permission for 3 scripts:

    # chmod u+x one-time-setup sign-modules dkms-sign-module

    Create 2 files for signing modules to the UEFI database.

    Run the file one-time-setup first and then reboot:

    During the reboot, when prompted, press any key to perform MOK management.

    At the wizard's first step, select Enroll MOK and press [Enter].

    At the Enroll the key(s) step, select Yes and press [Enter].

    Provide the password for the root account and press [Enter].

    At the final step, select Reboot and press [Enter].

    After that, sign 2 modules by running file sign-modules:

    Step 4: Insert modules bdevfilter and blksnap:

    We need to load the module into the currently running kernel using insmod:

    At this point, our agent-based backups will run fine; however, the loaded module will not persist if we reboot. We must create a file called /etc/modules-load.d/bdevfilter.conf and/etc/modules-load.d/blksnap.conf , and make sure that it has the name of the kernel module. We must also run depmod to add the loaded kernel module to the kernel module dependencies list.

    Once we reboot the CentOS server, the veeamsnap module will automatically be loaded as a kernel module.

    And our agent-based backups will now work correctly.

    # dnf clean all 
    # rpm -hi veeam-release-el9-1.0.8-1.x86_64.rpm 
    # dnf install epel-release -y 
    # dnf install dkms python3 make gcc perl kernel-modules-extra -y 
    # dnf update 
    # dnf install blksnap veeam -y
    [root@centos9 ~# ls /lib/modules/$(uname -r)/extra bdevfilter.ko.xz blksnap.ko.xz
    [root@centos9 ~]# lsmod | grep blksnap 0
    [root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz 
    [root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/blksnap.ko.xz 
    [root@centos9 ~]# lsmod | grep blksnap 
    blksnap 217088 0 
    bdevfilter 20480 1 blksnap
    
    [root@centos9 ~]# depmod
    [root@centos9 ~]# echo bdevfilter > /etc/modules-load.d/bdevfilter.conf
    [root@centos9 ~]# echo blksnap > /etc/modules-load.d/blksnap.conf
    [root@centos9 ~]# cat /etc/modules-load.d/bdevfilter.conf
    bdevfilter
    [root@centos9 ~]# cat /etc/modules-load.d/blksnap.conf
    blksnap
    [root@centos9 ~]# uptime && lsmod | grep blksnap
     17:43:06 up 18 min,  1 user,  load average: 0.00, 0.00, 0.00
    blksnap               217088  0
    bdevfilter             20480  1 blksnap
    # echo POST_BUILD=../../../../../../root/module-signing/dkms-sign-module > /etc/dkms/bdevfilter.conf
    # echo POST_BUILD=../../../../../../root/module-signing/dkms-sign-module > /etc/dkms/blksnap.conf
    # /root/module-signing/one-time-setup
    # reboot
    # /root/module-signing/sign-modules /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
    # /root/module-signing/sign-modules /lib/modules/$(uname -r)/extra/blksnap.ko.xz
    [root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
    [root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/blksnap.ko.xz
    [root@centos9 ~]# lsmod | grep blksnap
    blksnap               217088  0
    bdevfilter             20480  1 blksnap
    [root@centos9 ~]# depmod
    [root@centos9 ~]# echo bdevfilter > /etc/modules-load.d/bdevfilter.conf
    [root@centos9 ~]# echo blksnap > /etc/modules-load.d/blksnap.conf
    [root@centos9 ~]# cat /etc/modules-load.d/bdevfilter.conf
    bdevfilter
    [root@centos9 ~]# cat /etc/modules-load.d/blksnap.conf
    blksnap
    [root@centos9 ~]# uptime && lsmod | grep blksnap
     17:43:06 up 18 min,  1 user,  load average: 0.00, 0.00, 0.00
    blksnap               217088  0
    bdevfilter             20480  1 blksnap
    # dnf clean all
    # rpm -hi veeam-release-el9-1.0.8-1.x86_64.rpm
    # dnf install epel-release -y
    # dnf install dkms python3 make gcc perl kernel-modules-extra -y
    # dnf update
    # dnf install blksnap veeam -y

    Important: If the server boots with Secure Boot, we can’t insert the module → Must run step 3 on Secure Boot below first.

    Index of /backup/linux/agent/rpm/el/9/x86_64/
    Index of /backup/linux/agent/rpm/el/9/x86_64/
    [root@centos9 ~]# ls /lib/modules/$(uname -r)/extra
    bdevfilter.ko.xz  blksnap.ko.xz
    [root@centos9 ~]# lsmod | grep blksnap 
    0
    # mkdir module-signing/
    # echo POST_BUILD=../../../../../../root/module-signing/dkms-sign-module > /etc/dkms/bdevfilter.conf
    # echo POST_BUILD=../../../../../../root/module-signing/dkms-sign-module > /etc/dkms/blksnap.conf
    # /root/module-signing/one-time-setup
    # reboot
    # /root/module-signing/sign-modules /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
    # /root/module-signing/sign-modules /lib/modules/$(uname -r)/extra/blksnap.ko.xz
    [root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
    [root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/blksnap.ko.xz
    [root@centos9 ~]# lsmod | grep blksnap
    blksnap               217088  0
    bdevfilter             20480  1 blksnap
    [root@centos9 ~]# depmod
    [root@centos9 ~]# echo bdevfilter > /etc/modules-load.d/bdevfilter.conf
    [root@centos9 ~]# echo blksnap > /etc/modules-load.d/blksnap.conf
    [root@centos9 ~]# cat /etc/modules-load.d/bdevfilter.conf
    bdevfilter
    [root@centos9 ~]# cat /etc/modules-load.d/blksnap.conf
    blksnap
    [root@centos9 ~]# uptime && lsmod | grep blksnap
     17:43:06 up 18 min,  1 user,  load average: 0.00, 0.00, 0.00
    blksnap               217088  0
    bdevfilter             20480  1 blksnap
    Make DKMS sign kernel modules on installation, with full script support and somewhat distro independent