AWS Backup
AWS Backup is a secure Amazon Web Services service that automates and governs data backup and protection in the AWS cloud and on-premises.
Key points
- Scheduled backup plans (policies) automate backup of AWS resources across AWS accounts and regions.
- Incremental backup minimizes storage costs.
- Backup retention plans retain and expire backups automatically.
- Dashboard in the AWS Backup console to monitor backup and restore activities.
- Supports different encryption keys for encrypting multiple AWS resources.
- Lifecycle policies can be configured to transition backups from warm to cold storage automatically for supported resource types, including Amazon Elastic File System (EFS).
- Supports a broad set of AWS resources beyond compute and storage, including Amazon EC2/Amazon Elastic Block Store (EBS), Amazon S3, DynamoDB, RDS and Aurora (including Aurora DSQL), Amazon Elastic File System (EFS), Amazon FSx for Lustre, Amazon FSx for Windows File Server, FSx for NetApp ONTAP, FSx for OpenZFS, AWS Storage Gateway Volume Gateway volumes, DocumentDB, Neptune, Redshift (including Redshift Serverless), Timestream for LiveAnalytics, VMware Cloud on AWS, CloudFormation stacks, and Amazon EKS clusters.
- AWS Backup Vault Lock enforces a write-once-read-many (WORM) model on a backup vault, preventing anyone — including the account owner — from deleting backups or shortening their retention period.
- Supports on-demand or scheduled cross-Region copy of backups, and cross-account copy of backups to other accounts within an AWS Organizations structure, for added resilience and compliance.
- Centralizes and automates backup that was previously performed service-by-service, removing the need for custom scripts and manual processes.
- Distinct from AWS Storage Gateway: AWS Backup automates backup and restore of already-provisioned AWS resources (compute, storage, database), not on-premises hybrid access to cloud storage.