Scality ARTESCA
ARTESCA from Scality is scalable, secure object storage delivered as a software-defined storage solution.
ARTESCA object storage
With ARTESCA, Scality offers scalable and secure object storage as a software-defined storage solution.
Object storage gives modern applications scalable storage they reach directly, over HTTPS. Unlike a conventional file server, object storage has a flat hierarchy: what is stored is stored as objects. Alongside the data, metadata can be attached, which lets you search for objects with a particular attribute. ARTESCA supports nearly every function Amazon defined in the S3 protocol. Versioning and object lock matter a great deal for secure backup storage, because they are what makes immutability possible.
Because it is software-defined, ARTESCA installs on standard x86 servers, and it scales both out and up.
An ARTESCA cluster can be a single server or a multi-server cluster of 3 to 6 nodes. Starting capacity is 50 TB and it scales to 8.5 PB.
Beyond the backup use case, other use cases can run on the same cluster at the same time. Popular ones include storage for Kubernetes, archiving, PACS, CMS, system logs (Splunk), CCTV and IoT.
ARTESCA features
It deploys on certified x86 hardware or as a virtual appliance. Stored data is held safely through local data protection and distributed protection. A hardened Rocky Linux is included, and Scality handles its patching and hardening. That hardening removes privileges for the root user and sudo access, for instance.
Validated designs with extended API support for application partners such as Veeam make configuring the object storage and integrating it into the application straightforward.
Separate networks let you split management traffic from data traffic: different networks for the control plane and the workload plane. Several networks on the workload plane allow a separate network per application.
Access to the ARTESCA management interface uses role-based access control, governing access to the UI and to resources through roles. The storage manager role covers data administration services (accounts, data browser, workflows); the platform admin role covers platform and storage administration services.
The ARTESCA architecture

ARTESCA’s software architecture follows a Kubernetes approach, so every function is implemented as a microservice.
Storing data with erasure coding
As is usual with software-defined storage, the data is not protected by RAID but by erasure coding. That allows distributed protection alongside local protection, which covers the loss of an entire server. Both protection levels work as follows.
Single server: local protection
Small objects (under 60 KB) are stored as three replicas spread across different disks.
Large objects (over 60 KB) are written within the server with EC 8+2. ARTESCA splits the original object into eight chunks, creates two parities and spreads them across different disks. That protects against losing any two disks at once, and allows a fast local rebuild when a disk fails.

Multi-server: dual-level protection
Network protection
The data is spread across every server over the network. Small objects are protected with two replicas; large objects are spread across the servers with erasure coding 2+1 or 5+1. The erasure coding value is set automatically from the cluster size and protects against the loss of a server.
Local protection
The data is always written to two disks. Small objects (under 60 KB) are protected by two replicas across different disks; large objects are written with local EC 9+1. That protects against the loss of any one disk and allows a fast local rebuild when a disk fails.

Updating ARTESCA
ARTESCA is updated from the web interface. On login it tells you whether a new version is available and how long the installed version is still supported. The download function fetches the update files for the OS (Rocky Linux) and for ARTESCA directly from Scality’s download server and installs them. On a cluster of 3 to 6 nodes the update runs entirely online, so you can update at any time without any restriction on service availability.

ARTESCA CORE5

With ARTESCA it is not only the software that stores your data securely; it is the whole construction and architecture that provides the protection. Scality calls the approach CORE5.
Scality’s new CORE5 functions protect data at five critical layers, from the API through to the architecture, which gives end-to-end cyber resilience:
The API layer: immutability, implemented through S3 object lock, is powerful protection, because it makes sure backups cannot be changed after they are written. Multi-factor authentication (MFA) and access control help administrators prevent breaches by insiders.
The data layer: several safeguards at the data layer stop attackers reaching stored data and exfiltrating it from the system.
The storage layer: advanced encryption prevents the destruction or exfiltration of backups by making stored data unreadable to an attacker. That holds even when they use stolen access rights to get past the protections above.
The site layer: storing data at several sites simply and cheaply means the data is not lost even when an entire data centre is attacked.
The architecture layer: the intrinsically immutable core architecture makes sure data, once stored, stays in its original form, even if an attacker obtains the necessary access rights and bypasses immutability at the API layer.
ARTESCA and Veeam
Using ARTESCA object storage as immutable backup storage is an excellent use case. Veeam supports ARTESCA for both Veeam Backup & Replication and Veeam Backup for M365.
Veeam Backup & Replication version 12 also brings direct-to-object backup, so the data does not have to be written to disk storage first. Instant VM recovery works from there too. Immutability protects the data from tampering the moment it arrives.
Worth knowing: the data is protected for the whole period defined by the retention policy. An earlier Veeam version described that rather more clearly in the interface than the current one does.

Veeam Backup for M365 relies entirely on object storage, which is Veeam’s preferred storage type for it. Object storage performs far better there than disk-based storage formatted with NTFS or ReFS, and it uses space far more efficiently: more data in less room. From version 8 of the M365 backup, Veeam supports immutability for the backup job and for the backup copy job.
The ARTESCA wizard for Veeam
The Veeam integration wizard makes configuring ARTESCA very simple. It creates the account, the user with access key and secret key, and the bucket including immutability and the matching policy.

This post was a session at the last TRT
If content like this interests you and you want to hear more or talk it over with us, come to our next Technical Round Table (TRT). We run it twice a year. More information here:
https://soultec.ch/trt
We will not leave you standing in the desert.