Currently, the Veeam Backup & Replication installation process automatically installs PostgreSQL components, even when the customer intends to use Microsoft SQL Server as the VBR configuration database.
In environments where SQL Server is the chosen and approved database platform, the PostgreSQL installation is unnecessary and introduces additional operational and security considerations.
Requested Enhancement
When selecting Microsoft SQL Server as the VBR configuration database during installation, provide an option to:
Skip PostgreSQL installation entirely.
Install only the components required for the selected database platform.
Avoid creating PostgreSQL services, ports and associated software when they are not required.
Benefits
Reduced Attack Surface
Installing PostgreSQL unnecessarily introduces additional running services, listening ports and software components that may become targets for vulnerability scanning and security audits. Organisations following security-hardening standards typically seek to minimise the number of installed services and applications.
Simplified Patch Management
PostgreSQL security updates are released independently of Veeam product updates. Customers are currently expected to monitor PostgreSQL releases and manually apply security patches where applicable. This creates additional maintenance overhead for software that may not even be used when SQL Server is the configuration database.
Improved Compliance
Many organisations have strict requirements around software inventory, vulnerability management and approved technology stacks. Removing unnecessary PostgreSQL installations would make it easier to satisfy compliance requirements and security reviews.
Cleaner Server Deployments
Administrators expect a VBR deployment configured with Microsoft SQL Server to install only the components required for that architecture. Avoiding unnecessary software installations results in a cleaner and easier-to-maintain environment.
Example Scenario
A customer installs Veeam Backup & Replication and chooses an existing Microsoft SQL Server instance to host the configuration database. Despite PostgreSQL not being used for the VBR configuration database, PostgreSQL components are still installed on the VBR server. This requires the customer's security and infrastructure teams to monitor, patch and validate an additional database platform that provides no functional value in their deployment.
Expected Behaviour
During installation, the wizard should detect the selected configuration database platform and:
Install PostgreSQL only when it is required by the chosen deployment architecture.
Provide a clear option to omit PostgreSQL when Microsoft SQL Server is selected.
Document any Veeam features that genuinely require PostgreSQL so customers can make an informed decision.
Impact
This enhancement would improve security posture, reduce administrative overhead, simplify compliance efforts and align the installed components with the customer's selected database platform.
As security teams increasingly focus on reducing unnecessary software and services, providing a PostgreSQL-free deployment option for SQL Server-based VBR installations would be a valuable enhancement for enterprise customers.
-
Free Bird
- Novice
- Posts: 6
- Liked: 6 times
- Joined: Sep 18, 2024 9:09 am
- Full Name: Daniel Hooper
- Contact:
-
david.domask
- Product Manager
- Posts: 3966
- Liked: 962 times
- Joined: Jun 28, 2016 12:12 pm
- Contact:
Re: Provide Option to Skip PostgreSQL Installation When Microsoft SQL Server Is Selected for the Veeam Backup & Replicat
Hi Free Bird,
Understood on the request; currently it is installed to provide support for Backup for Entra Id as we use PostgreSQL as the repository, so it's not just about use of the configuration database. If you're not protecting Entra Id, then you can safely remove PostgreSQL.
As for customizable installations, understood, and we have plans, but only for the Software Appliance at this time.
Understood on the request; currently it is installed to provide support for Backup for Entra Id as we use PostgreSQL as the repository, so it's not just about use of the configuration database. If you're not protecting Entra Id, then you can safely remove PostgreSQL.
As for customizable installations, understood, and we have plans, but only for the Software Appliance at this time.
David Domask | Product Management: Principal Analyst
Who is online
Users browsing this forum: No registered users and 157 guests