Skip to main content

IBM Storage Defender: Protecting Red Hat OpenShift Containers and Virtual Machines

Published: 30 September 2026

Abstract

This document provides implementation guidance for protecting Red Hat OpenShift containerized applications and virtual machines using IBM Storage Fusion Backup and Restore integrated with IBM Storage Defender Data Resiliency Service.

IBM Storage Fusion delivers policy-driven backup and restore capabilities through a Hub and Spoke architecture, supporting application-consistent backups and cross-cluster recovery for both containers and OpenShift Virtualization virtual machines. IBM Storage Defender Data Resiliency Service adds orchestration and governance, providing centralized visibility, compliance monitoring through governance profiles, and automated recovery workflows.

The document covers planning, installation, configuration, and operations for both platforms. It emphasizes practical implementation patterns and operational considerations rather than duplicating product documentation, focusing on the decisions and configurations that matter in production environments.

Authors

Phillip Gerrard, Marcelo Capile, Reginald D'Souza, Maxwell Ferreira, Gerd Franke, Andre Gaschler, Kavish Ghogale, Pallavi Singh, Prajakta Tendulkar, Jörg Walter and Daniel Wendler

  • Introduction
    • Purpose of this document
    • Section overview
    • Authors
    • Feedback

Introduction

Purpose of this document

This document provides practical guidance for implementing data protection and cyber resilience for Red Hat OpenShift environments using IBM Storage Fusion and IBM Storage Defender. It is written for architects, administrators, and operations teams who need to design, deploy, and manage enterprise-grade backup, restore, and recovery orchestration capabilities for containerized applications and Red Hat OpenShift Virtualization virtual machines.

The focus is on implementation rather than theory. Although this guide refers to IBM product documentation where appropriate, it emphasizes the decisions you need to make, the configurations that matter in production, and the operational patterns that help you recover successfully when incidents occur.

Who should read this document

This document is intended for the following readers:

  • Infrastructure architects designing data protection strategies for Red Hat OpenShift environments
  • Platform administrators responsible for implementing and managing backup and restore services
  • Site reliability engineers who need to understand recovery procedures and operational patterns
  • Security teams evaluating cyber resilience capabilities and governance controls
  • Operations teams who will execute backup policies and perform recovery operations

You should have working knowledge of Red Hat OpenShift, Kubernetes concepts, and basic storage principles. Familiarity with IBM Storage products is helpful but not required.

Section overview

Introduction to Container Protection with IBM Storage Defender establishes the foundational concepts necessary for understanding data protection in containerized environments. This section introduces container technology, explains how Red Hat OpenShift orchestrates containerized applications, and outlines the unique protection requirements for Red Hat OpenShift environments. You will learn about IBM's comprehensive data protection portfolio, including IBM Storage Protect for Containers, IBM Fusion Backup and Restore, and IBM Storage Defender Data Protect. The section also addresses the critical aspects of protecting the Red Hat OpenShift cluster infrastructure itself, including control plane components, configuration management, and disaster recovery strategies.

IBM Storage Fusion Backup and Recovery covers the planning, architecture, installation, and operation of IBM Storage Fusion Backup and Restore. You will learn how to implement the Hub and Spoke model, configure protection policies, create application-consistent backups using recipes, and execute recovery operations for both containers and virtual machines. The section includes detailed procedures for installation, configuration, and day-to-day operations.

IBM Storage Defender Data Protect explains how to protect Red Hat OpenShift workloads using IBM Storage Defender Data Protect. This section covers environment preparation, pushing software images to a private registry, registering Red Hat OpenShift clusters as backup sources, creating backup policies and protection groups, and performing backup and restore operations for both containerized applications and Red Hat OpenShift Virtualization virtual machines. It also covers application-consistent backups using pre- and post-snapshot hooks, auto-protect for namespaces, single file and folder restores, and the key considerations for protecting KubeVirt-based virtual machines.

IBM Storage Defender DRS Integration describes how to integrate IBM Storage Fusion and IBM Defender Data Protect with the Data Resiliency Service (DRS). You will learn how to configure Connection Manager, establish backup system integrations for both IBM Fusion and IBM Storage Defender Data Protect, create recovery groups with governance profiles, and leverage DRS capabilities for orchestrated recovery workflows. This section also covers DRS visibility concepts—including applications, recovery groups, governance profiles, clean room profiles, and dependency mapping—and ties together the backup mechanics from earlier chapters with the orchestration and governance layer that DRS provides.

Authors

Phillip Gerrard is a Project Leader for the International Technical Support Organization working out of Beaverton, Oregon. As part of IBM® for over 20 years he has authored and contributed to hundreds of technical documents published to IBM.com and worked directly with IBM's largest customers to implement storage solutions and resolve critical situations. As a team lead and Subject Matter Expert for the IBM Spectrum Protect support team, he is experienced in leading and growing international teams of talented IBMers, developing and implementing team processes, creating and delivering education. Phillip holds a degree in computer science and business administration from Oregon State University.

Marcelo Capile is a hands-on technology professional with over 15 years of experience in IT and a career built within IBM. His background spans critical environments, complex operations, and the kind of challenges that require not only technical knowledge, but also composure, consistency, and sound judgment. He has developed strong expertise in infrastructure, automation, cloud, observability, and platforms such as Linux, AIX, Kubernetes, and Red Hat OpenShift. Throughout his career, he has worked with Unix administration, backup strategies, storage, networking, Ansible automation, and Python and Shell scripting, as well as IBM Cloud, AWS, and GCP. Known for his practical mindset and collaborative approach, he combines technical depth with clear communication and a genuine willingness to help others grow.

Reginald D'Souza also known as Reg, is an APAC Storage Software Subject Matter Expert (SME) based in Australia. With over 20 years of experience in infrastructure, multi-vendor storage, and data protection solutions, Reg has been with IBM since 2008, working in various business units including delivery, managed services, and sales. His expertise spans across different software portfolios, including IBM and Red Hat. Currently, Reg's focus is on software-defined storage and modern data protection solutions, specifically IBM Fusion and IBM Storage Ceph, which aid clients in their hybrid cloud and AI journey. With his extensive work with Red Hat, he has earned a nickname, “Reg Hat”.

Maxwell Ferreira is a Senior IT Analyst at IBM Brazil. As a member of the IBM Storage Protect Support Team, working to support customer service requests from IBM's global accounts he is focused on IBM Storage Protect Plus, IBM Storage Protect for Cloud and IBM Fusion. He has over 20 years of experience in customer service, handling analysis requests, providing solutions for backup, restore, and data protection requests with IBM software. Since 2005, he has worked as an IT analyst, mostly with IBM Storage Protect, implementing and managing backup and restore environments with data storage on disk, tape, and cloud. He earned a degree in IT Management, a postgraduate degree in Cybersecurity, and an MBA in Industry 4.0.

Gerd Franke is a Senior IT Architect in the EMEA Storage team of IBM Client Engineering. He is known as an expert for Storage strategy and architecture, focusing on Cyber Security and Resiliency, Hybrid Cloud Storage and Modern Data Protection. He often leads large and complex client projects and is a regular speaker at IBM conferences. Gerd has worked for IBM in various national and international roles for more than 30 years. He holds an engineer’s degree in Electrical and Communications Technology.

Andre Gaschler is an IBM Certified IT Specialist based in Frankfurt, Germany. He has over 20 years of experience with IBM’s Data Protection portfolio. As senior technical specialist for IBM Systems Andre helps international clients deploy, modernize, and efficiently manage data resiliency infrastructure in enterprise environments. He is part of the Expert Labs DACH team as Solution Architect working in service development, delivery, and training for various strategic IBM Storage products.

Kavish Ghogale is a Senior Solution Architect with IBM Expert Labs Centre of Excellence (CoE), based in Mumbai, India. Since joining IBM in 2006, he has developed more than two decades of expertise in data protection and storage technologies. He began his IBM career under the Tivoli Software brand while working with IBM Software Labs before joining IBM Systems Lab Services in 2015. Over the following eight years, he led the design and delivery of IBM Storage and modern data protection solutions while driving client enablement across the ISA, ASEAN, ANZ, and MEA regions. Since 2023, Kavish has been part of the IBM Expert Labs Solutioning team, where he focuses on pre-sales solution architecture, project planning, and strategic customer engagements for IBM clients worldwide.

Pallavi Singh is a Senior Technical Staff Member in IBM Storage, based in Pune, India, with over several years of experience in enterprise storage, observability, and system health management. Pallavi has led key initiatives in diagnostics and platform integration, driving scalable automation and improved customer outcomes. Pallavi provides strong technical leadership across cross-functional teams and currently focuses on advancing AI-driven capabilities such as anomaly detection and predictive monitoring. Pallavi has been a co-author on several IBM Redbooks publications and holds a master's degree in Computer Applications.

Prajakta Tendulkar is a QA Architect for IBM Fusion, with more than five years of hands-on experience working on the Fusion platform. In this role, Prajakta plays a critical part in shaping the overall quality strategy and test architecture for Fusion across releases. Having worked extensively across both Software‑Defined Storage (SDS) and Hyperconverged Infrastructure (HCI) paradigms, Prajakta brings deep, end‑to‑end understanding of Fusion’s architecture and deployment models. This includes strong expertise across key Fusion software components such as backup and restore, remote mount, and Data Foundation storage, along with a solid grasp of underlying hardware components, including compute and network infrastructure.

Jörg Walter is an IBM Certified IT Specialist based in Frankfurt, Germany. He joined IBM in 2000 and has held various technical roles throughout his career. Starting in network engineering and design, Joerg shifted his focus to storage, data protection, and retention in 2005. From 2011 to 2022, he was part of IBM’s Systems Storage Lab Services team, where he supported clients in planning and implementing hardware and software solutions for data protection and retention. Since 2023, Joerg has been working as a Senior Platform Engineer within IBM Client Engineering EMEA, helping clients pilot advanced storage solutions using IBM’s comprehensive storage hardware and software portfolio. He holds a diploma in Electrical Engineering and Computer Science from the University of Applied Sciences in Bingen am Rhein, Germany.

Daniel Wendler is a Client Engineer in IBM Global Sales EMEA, specializing in Cyber Resilient Storage architectures and IBM Storage Defender. He joined IBM in 2005 and spent more than a decade in IBM's worldwide last-level support organization, developing deep expertise across hardware and software storage solutions. He subsequently served four years as an IT Consultant within the European Storage Competence Center (ESCC), delivering IBM Expert Labs engagements to design and implement Modern Data Protection and Retention Solutions for clients across the EMEA region. Since 2023, Daniel has been working in Global Sales EMEA as a Client Engineer, where he focuses on architecting Cyber Resilient Storage solutions with IBM Storage Defender, running proofs of concept to demonstrate the value of IBM's Defender portfolio, and enabling clients to build robust, resilient infrastructures. He holds a Diplom-Informatiker degree from the Rhein-Main University of Applied Sciences, Germany.

Feedback

This document reflects practical experience implementing these technologies in production environments. If you encounter issues not covered here, or if you have suggestions for improving the guidance, your feedback helps make this resource more valuable for the community.

Contact IBM Redbooks