Catalogic Software

DPX feature

S3 Object Storage Backup

Object storage is not backed up just because it is durable. Catalogic DPX is S3 backup software that protects your buckets as a source, keeps the copy on your own storage, and can also use S3 as the archive tier for everything else you protect.

Durability is not a backup

S3 platforms replicate objects and survive hardware failure, which is why buckets often end up outside the backup plan entirely. Replication does not help when someone deletes a prefix, an application overwrites objects with bad data, or credentials are used to empty a bucket on purpose. DPX treats an S3-compatible store as a backup source in its own right, reads the buckets you select, and writes the copy to storage you control.

S3 buckets protected as a backup source

Validated S3 sources

The DPX compatibility guide validates these S3-compatible platforms as backup sources. Each is added as an S3 Object Storage node with an endpoint, access key, secret key, and region.

AWS S3 backup

AWS

Protect Amazon S3 buckets and keep the recovery copy on infrastructure you own, outside the account that holds the original.

Backblaze B2 backup

Backblaze

Back up Backblaze B2 buckets alongside the rest of the estate, managed from the same DPX job list.

DataCore Swarm backup

DataCore Swarm

Protect Swarm buckets on versions 17.0.2 and 16, giving an on-premises object store an independent backup copy.

MinIO backup

MinIO

Back up MinIO buckets, including retrieval of individual files from the vStor copy when a full bucket restore is not what you need.

How an S3 backup job runs

S3 Object Storage backup is a dedicated DPX job type, configured and run from the web interface:

  • Add the S3-compatible store as a node with its endpoint, access key, secret key, and region, then use Test to confirm the Master Server can reach it.
  • Select the buckets to protect. vStor creates a separate volume for each bucket in the job, so protected buckets stay isolated from each other.
  • Object versions come across too: the five most recent versions are included by default, configurable up to ten.
  • Schedule the job like any other DPX job, with base and incremental cycles so later runs move only what changed.
DPX S3 object storage backup job configuration

The copy lands on your storage, not another bucket

A backup of object storage that lives in object storage at the same provider shares too much fate with the original. DPX writes S3 backup data to vStor, the software-defined repository you run on your own hardware or as a virtual appliance. vStor 4.12 or newer is required for this job type. That puts the recovery copy on infrastructure with a different failure domain, a different credential set, and protection controls you administer.

S3 backup data stored on an on-premises vStor repository

Immutability where it counts

The value of an independent copy depends on whether it can be removed by whoever compromised the original.

Deletion locks with a retention period

On vStor, snapshots and volumes take a deletion lock with a retention period. A fixed lock cannot be changed by an administrator and releases only when the period ends. A flexible lock can be adjusted or removed, and lifting one requires an MFA code.
Stolen S3 credentials do not reach that copy, and neither does an administrator acting in haste.

Checked before you trust it

Protection preserves a recovery point; it says nothing about whether the contents are clean. GuardMode scans backup data for ransomware indicators and encrypted files, so you know the state of a recovery point before you push it back into a live bucket.
See cyber-resilient recovery for how detection and protected storage work together.

Restoring a bucket

S3 Object Storage restore is bucket-level, and the documentation is direct about what that means:

  • Choose the S3-compatible node to restore into, which can be the original store or a different one.
  • Restored buckets are created with an auto-generated `-restore-<timestamp>` suffix rather than overwriting the source bucket.
  • Object versions are restored along with the objects.
  • Restoring individual objects through the restore job is not supported. When you need a handful of files rather than a bucket, retrieve them from the vStor copy instead.
DPX S3 object storage restore options

S3 as the archive tier, not only the source

The same S3 compatibility works in the other direction. DPX archive jobs move Block backup and VMware Agentless backup data to cloud object storage for off-site retention, which is where most teams meet S3 first. Object Lock is available on Amazon S3 series, Backblaze B2, Wasabi Object Storage, and Microsoft Azure Blob Storage, and DPX can encrypt agentless VMware archive data before it leaves for the target. Per-object retention periods and legal holds are not supported.

DPX archiving backup data to S3-compatible cloud object storage

Before you configure the first job

Four things decide whether an S3 backup job behaves predictably. Two of them are easy to miss until an incremental quietly stops catching changes.

RequirementWhat to checkWhy it matters
DestinationvStor 4.12 or newerIt is the only supported backup storage for this job type, and it creates one volume per protected bucket.
Clock synchronisationThe S3 store and the DPX Master Server agree on the timeDPX documents this as mandatory. Without it, incremental backups can miss changes, which is the kind of gap you find during a restore.
Bucket addressingVirtual host-style or path-styleAWS recommends virtual host-style and treats path-style as deprecated, but some S3-compatible platforms still require path-style.
CredentialsAccess key, secret key, region, endpointProviders name these differently. Use Test when adding the node to confirm the Master Server can actually reach the endpoint.

Version limits and platform support change between releases. Confirm against the DPX compatibility guide for the version you run before sizing a deployment.

Why teams protect object storage with DPX

One console

Buckets sit in the same job list as VMs, databases, file servers, and physical systems, on one schedule and one retention model.

A different failure domain

The copy lives on your vStor repository, under your credentials, not in the account that holds the original.

Protected at rest

Deletion locks with retention periods, MFA on release, and GuardMode scanning of the stored copy.

S3 backup FAQ

Which S3 platforms can DPX back up?
The DPX compatibility guide validates AWS, Backblaze, DataCore Swarm (17.0.2 and 16), and MinIO as S3 Object Storage backup sources. Each is registered as a node with an endpoint, access key, secret key, and region name, and bucket addressing can be virtual host-style or path-style depending on what the provider requires.
Where does the backup data go?
To vStor, version 4.12 or newer, which is the only supported destination for this job type. vStor creates one volume per protected bucket. Keeping the copy on storage you run is the point: it does not share credentials or a failure domain with the source.
Can I restore a single object?
Not through the restore job, which works at bucket level and creates the restored bucket with a -restore-<timestamp> suffix. For a small number of files, retrieve them from the vStor copy instead of restoring the whole bucket.
How are object versions handled?
Versioning is supported for both backup and restore. The five most recent versions of an object are included by default, and that limit is configurable up to ten.
Can DPX also archive backups to S3?
Yes, and the two are independent. Archive jobs send Block backup and VMware Agentless backup data to S3-compatible cloud storage for long-term retention, covered under cloud integration and long-term retention and archival.
Is the archived copy immutable?
Object Lock is supported on Amazon S3 series, Backblaze B2, Wasabi Object Storage, and Microsoft Azure Blob Storage. Setting retention periods or legal holds per object is not supported. On-premises, immutable backup storage on vStor provides deletion locks with retention periods.

Related DPX resources

More on object storage protection and cloud archive with Catalogic DPX.

Protect your S3 buckets with DPX

See how Catalogic DPX backs up S3-compatible object storage to your own vStor repository, with immutable snapshots and ransomware scanning. Book a personalized demo with our team.

Request Demo