Data Protection for Red Hat OpenShift with Rubrik

November 25, 2025

Rubrik Security Cloud provides a unified, cyber-resilience platform to protect your entire Red Hat OpenShift environment. As organizations consolidate workloads by running both modern containerized applications and traditional virtual machines (Windows and Linux servers) on OpenShift Virtualization, a siloed backup strategy is no longer viable. Rubrik’s solution eliminates this complexity by offering a single, policy-driven platform to secure, protect, and rapidly recover both containerized and virtualized workloads from a single interface.

Key Solution Components

Rubrik’s integration with OpenShift is a software-based solution composed of several key components:

  • Rubrik Security Cloud: The central management platform used to define and apply data protection policies (SLAs) across your entire hybrid cloud, including all your OpenShift clusters.
  • Custom Resource Definitions (CRDs): Rubrik installs its own CRDs into your OpenShift cluster, extending the Kubernetes API to make backup and recovery functions native to the platform. This allows you to manage protection as code, just like any other Kubernetes object.
  • Rubrik Backup Agent: A lightweight, containerized agent that is instantiated on-demand as a pod within your cluster to perform backup and restore operations. It does not run continuously, ensuring a minimal footprint.
  • GraphQL APIs: A robust set of APIs that allow for deep automation and scripting of all backup and recovery operations, integrating protection directly into your DevOps and CI/CD pipelines.

How It Is Implemented and Used

The Rubrik solution is designed to be non-disruptive and integrates seamlessly with OpenShift’s native storage and scheduling mechanisms.

The Automated Backup Process

The backup process is fully automated and triggered by the SLA policy you set:

  1. Policy Application: An administrator applies an SLA policy to the asset needing protection. This can be as broad as an entire cluster, as specific as a single namespace, or as granular as a single virtual machine.
  2. Agent Instantiation: When a backup is scheduled, Rubrik automatically instantiates its backup agent pod in a dedicated namespace within the cluster.
  3. PV Snapshot: The agent creates a snapshot of the Persistent Volume (PV) associated with the application or virtual machine.
  4. Data Ingest: The PV snapshot is mounted to the agent pod via a new Persistent Volume Claim (PVC), allowing the agent to read the data blocks.
  5. Secure and Store: The agent copies the data to the Rubrik cluster, where it is secured and made immutable.
  6. Cleanup: Once the copy is complete, the agent pod, its temporary PVC, and the PV snapshot are all automatically destroyed, leaving the cluster in its original state.

The Rapid Restore Process

Restoration follows a similar, on-demand logic:

  1. Agent Instantiation: The Rubrik agent is instantiated to handle the restore.
  2. PV Creation: New Persistent Volumes are created in the target namespace.
  3. Data Copy: The agent copies the data from the Rubrik cluster into the new PVs.
  4. Object Restoration: Once the data is in place, all the associated Kubernetes objects (like Deployments, StatefulSets, or VirtualMachine definitions) are restored, reconnecting the application to its data.
  5. Cleanup: The agent pod is destroyed, and the application or virtual machine is fully recovered.

Protection for OpenShift Apps and Virtual Servers (VMs)

Rubrik’s platform protects all workloads on OpenShift by treating both applications and virtual machines as first-class citizens. When Rubrik backs up any workload, it captures two critical things:

  1. The Data: The Persistent Volume(s) containing the application data or the virtual machine’s disk.
  2. The Configuration: The Kubernetes objects and metadata that define the pod, which includes the VirtualMachine resource for a Windows or Linux server.

By capturing both, Rubrik ensures a consistent and complete backup. This means you can confidently protect a legacy Windows VM on OpenShift Virtualization using the exact same policy and process you use to protect a new, cloud-native containerized application, all from a single platform.

Key Benefits

  • Unified Management: Protect both containers and virtual machines (Windows/Linux) from a single interface, eliminating protection silos.
  • Policy-Driven Automation: Define and apply a single SLA policy globally, automating protection for all your OpenShift workloads.
  • Kubernetes-Native Integration: Leverages CRDs and OpenShift-native tools, like OpenShift APIs for Data Protection (OADP), for a seamless, non-disruptive experience.
  • Cyber Resilience: Secures data against threats and provides rapid, reliable recovery for both applications and VMs, ensuring business continuity.
  • Multi-Cluster Support: Protect and manage multiple OpenShift clusters from a single Rubrik instance, scaling protection as your environment grows.

Ready to unify your architecture? If you are running OpenShift Virtualization and want to see how this ephemeral agent architecture works in your environment, contact us today. 

Recent Posts

Open Infrastructure for Modern Workloads: Why Fusion HCI Matters

Open Infrastructure for Modern Workloads: Why Fusion HCI Matters

The push for AI is accelerating, but so is the need for strict data sovereignty, security, and performance. At Li9, we are seeing many organizations struggle to balance these demands. They want to leverage the open global AI ecosystem, but they...

IBM Fusion HCI as a Catalyst: Accelerating Growth in IBM watsonx

IBM Fusion HCI as a Catalyst: Accelerating Growth in IBM watsonx

Most IT leaders have been told they “need an AI strategy.” The pressure usually arrives before the foundations are ready: use cases are vague, data is scattered, and the current platform was built for traditional workloads, not for the demands of...

Managing OpenShift / Kubernetes Environments at Scale Whitepaper

Managing OpenShift / Kubernetes Environments at Scale Whitepaper

While Red Hat OpenShift is a powerful platform for innovation, managing it at an enterprise scale introduces significant complexity and risk. Li9’s pre-architected operational framework solves this challenge by using GitOps principles to automate...

IBM watsonx Virtual Assistant for Maximo Application Suite

IBM watsonx Virtual Assistant for Maximo Application Suite

Discover how a watsonx-powered virtual assistant brings GenAI chat and voice to IBM Maximo field service, speeding lookups and updates, guiding approvals, and reducing manual effort. Get the 2-page brief to see the benefits and integration...