Data Protection with HPE and Zerto

CTO Advisor podcast host, Keith Townsend has been a long time follower of Zerto data protection. Zerto has traditionally provided data protection via replication for hardware agnostic environments. In this sponsored podcast, Verma Deepak, VP of Product at Zerto, an HPE Company discusses the idea of Zerto as an HPE GreenLake product. Does HPE GreenLake [...]

Transcript 3,228 words · about 22 min to read

Machine-generated from the episode audio and not hand-corrected, so names and technical terms may be imperfect. The audio is authoritative.

All right, you're listening to another episode of the CTO Advisor podcast. This is a special sponsored podcast by HPE, specifically I have Deepak Verma, who is the VP of product at what we used to call Zerto, and now that we're now calling HPE GreenLake, data protection services. Data protection, I think, Deepak, is a good overall idea to look at the portfolio? Absolutely, yeah. As you mentioned, classically, it's a Zerto on-prem product that everybody knows and loves that still continues and exists, but as part of HPE, we have a portfolio that includes both a cloud version of Zerto on the GreenLake platform called GreenLake for Disaster Recovery alongside with that is GreenLake for Backup and Recovery, or GLBR, and combined these products offer essentially the data protection that you're referring to.

So yeah, the combined portfolio under my jurisdiction is the data protection services that HPE offers. Now back in April, I attended a HPE GreenLake storage day, and they demoed the backup and recovery solution for me, and we had this whole conversation and argument about whether or not backup in the cloud or a SAS-based backup solution makes sense, and I think the conclusion is more or less that is definitely a future. The control plane of the data center is moving to the public cloud.

It's been a premise of the CTO Advisor, so no surprise there that backup and recovery, we can put the control plane in the public cloud and run it from there. It's a proven model. What's less of a proven model though is disaster recovery, the control plane in the public cloud. We are accustomed to Zerto being on-prem, the VMware native solutions being on-prem. This critical part of the business, business continuity technology being on-premises technology made the argument for me for kind of outsourcing the control plane for this critical component to the public cloud, to GreenLake.

Yeah, absolutely. So Keith, interesting question, right, because a lot of traditional Zerto customers, they've been loyal with us for over 12 years. Hundreds and thousands are going to ask the same question, so I'm glad you brought it up. I probably asked myself that question, right, post-acquisition, and so where it starts making sense is to move a DR, a control plane, to cloud as a SaaS offering is twofold, and I'll have an exception to that, and I'll explain that in a minute. So the first and foremost, if you take the cloud administrator, the role of the IT administrator in the cloud context has changed, right?

You're no longer a specialist that is covering just network or just storage or just DR, just backup, et cetera, right? So we know from a cloud perspective that admin role comes in and is able to do everything from provisioning, setting up security policies, even networking, et cetera, all the way to protection. So what we wanted to do first and foremost by moving it up to the cloud control plane is really go after that 80% of the time you're using very basic functionality. You're protecting the VM, you're making sure that the VM is hitting RTOs, RPOs that you want, you're reporting on that, and then you're occasionally doing tests and fillers.

So if you consider the basic functionality, putting that into a cloud control plane makes it a lot easier to absorb, to manage, and then it also gives it a seamless transition as you're provisioning, going into DR, going into backup. So kind of the public cloud or hyperscaler model version of Zerto. So that's one, right? It's just the simplicity in that simple use case. The second part is interesting because our larger customers, right? So you think about the customers that have 20 instances of Zerto because they have such large data centers that they're supporting that many VMs.

So they've scaled out. They have often asked us, boy, it would be really nice if you could aggregate everything I have onto a single master, if you will. And doing that on-prem starts becoming harder, right? You've been in IT long enough, you understand that you've got to have a distributed architecture, then you've got to put it all together and then manage it globally, et cetera. So this global management concept makes sense to put it again into a cloud control plane because it'll aggregate all the sites no matter where they are and bring them into a single entity.

So it's aggregated from two dimensions. One is simplicity to get up and running ease, what I'll consider the kind of the 80% use case. But then also from a scale perspective, it just makes organic sense to have this up on the top. Now, I did mention exception. So the exception is let's say you have a disaster event that has to do with ransomware or any cyber event. And the first thing most customers that I have talked to, and I'm sure you've talked to, knee-jerk reaction are going to start disconnecting things from the network because they don't want their data exfiltrated and they don't want more infection spreading.

So they'll start shutting things down, disconnecting from the network, pretty organic human reaction. In that case, whatever we offer in the cloud from a DR perspective, the concept is that I'll still have a break glass in case of emergency, so you can still operate the core functions of recovery, et cetera, on-prem. When you're in that mode, you're probably not going to be provisioning new VMs, protecting new VMs, doing your daily operations. You're in emergency mode, so it's break glass in case of emergency.

So I still think the control plane has a lot of value moving forward to have it as a SaaS I do think that there's a break glass in case of emergency need, especially for disaster recovery because as you asked earlier, DR is a little different. So let's talk about that break glass piece because it's real. We've seen enough examples in the industry of where ransomware has been top of mind when it comes to DR. As I think about data protection, whether it's backup or if it's DR replication, the lines are starting to be blurred because of ransomware.

Matter of fact, before I'm going to show kind of my deep cut knowledge of Zerto, I've been following Zerto for years and before HPE acquired Zerto, Zerto was on the path of adding backup and recovery solutions to the portfolio. And I kind of questioned it at the time. I'm like, yeah, you guys do really, really great job at replication and DR and an orchestration of bringing workloads up on prem on a private cloud. But backup is kind of a different game. Now we're at the point where those two solutions have to be integrated.

What's the HPE GreenLake solution for bringing these two worlds together? Yeah, perfect question. And you're absolutely right. The number one disaster we see today from customers is ransomware recovery. And you've been following Zerto enough to know that we excel at that and we've done that organically over a long period of time. I like to say we accidentally fell, our technology fell into this use case. We designed it for recovery and rollback. So very good setup. Yes, we were going down the path of adding a backup component to Zerto.

And it was driven purely by customer demand. The ask was, hey, Zerto, I love the fact that you've got a 30-day journal and I know I can recover very, very quickly the file, the VM, the volume level. However, it'd be really nice if you could give me an immutable copy that I can check the box, give my auditors, satisfy them and say, I have this. In case everything else goes away, I have a copy sitting somewhere that I can recover. That was the need, right?

That was the need that drove us to go down to the backup market. What's changed since the HPE acquisition, as I mentioned with the backup as a service component of the GreenLake for backup and recovery, is that they can fulfill an entire use case that Zerto doesn't need to build. So what I've done is down tuned what we were building internally, which was the LTR, long-term retention functionality, and utilize a lot of the existing HP technology, things such as store-one-state duplication, ability to protect more than just VM workloads.

And so that's the setup. And really what we're headed towards is you've got GreenLake for disaster recovery, which lives on the GreenLake platform, and you've got GreenLake for backup and recovery, which also lives on the GreenLake platform. And the two are side-by-side, offering that data protection service. The DR service, it's traditional Zerto behind the scenes. What that means, it's your low RPO, low RTO, journal-based, quick recovery in these events. And the backup recovery side of it offers the daily backups, the immutability, the long-term retention, the deduplication to save you cost on storage, etc.

And by being on the same platform, on the same console, on the same cloud-based platform, you get inherent operational efficiency, right? if you were on-prem, a traditional customer today, you're going into a Zerto console for your DR, you're going into some backup console for your normal backup operation. So operationally, these can collapse onto a single platform. Reporting-wise, I think that's also absolutely critical, right? Being able to hand an auditor a report that says, this VM, this set of applications, or this set of VAMs that belong to this application have been backed up, they've been DR-protected, this is our RTO that we achieved, this is our retention, this is our immutability.

We have satisfied those regulatory requirements that are needed in the industry, and now more so because of ransomware. So I think that the two of them now sitting side-by-side, instead of Zerto having to build an entire backup product, we get to benefit from all the achievements that HP has already provided and then marry that with the GreenLake DR side of things and really provide that complete solution. Yeah. So ironically, this answered one of my first kind of skepticisms when I heard Zerto say that they're going to go into backup.

It's a completely different approach to data protection. It's a new product, feature set, dedupe, all of the things that you need to do to make a decent backup platform was kind of like, wow, that's years in the process and you pretty much accelerated the development and integration of that by not having to build a new backup solution. So that absolutely is a synergy. Now, one of the things that Zerto has been traditionally known to be able to do, and I think this is where I think a lot of people may have a challenge with the branding, the GreenLake branding, because when we first thought of GreenLake, we thought of HPE being able to sell me their gear on-premises through a cloud-like consumption model.

When I think of Zerto, I think of the basic building block of being able to say, I can replicate a VM from one location to another location. That location traditionally may have been another cold or warm data center, or in the later versions of Zerto, more mature versions of Zerto, from the data center to the public cloud. Now, as we introduce the GreenLake brand into this equation, are we now saying that I need to only replicate from my on-premises data center into another on-premises data center running HPE gear?

Not at all. So the confusion, we need a little bit of a decoder ring. So let me try a little bit to clear that sense of confusion up. Now, I went through that organically as well. There's a GreenLake flex model, right? So new terminology and branding. This is the traditional, you can buy anything on a consumption-based contract from GreenLake. So that is just the traditional GreenLake and what HPE has been doing. HPE has been doing for a number of years now.

The GreenLake platform is just control plane running in a cloud, right? It's running somewhere in a cloud. As far as the customer is concerned, they're hitting an IP address that's in public land rather than in private land. There is no hardware associated with this. There are no traditional services. There's no data center associated with this. This is purely a service that we're providing where a console is lifted up into the cloud, as I described earlier. So with these products, you can still achieve the same functionality that you used to do it earlier.

You can go on-prem to on-prem, the console being running in the cloud. You can go on-prem to public cloud. You can back up on-prem to public cloud. You can back up on-prem to on-prem. So your data, the data layer, or the data path remains exactly the same. It's the control plane that has moved up to cloud. So GreenLake is really that control console. So I want to drive this home, and I know this is sponsored by HPE, but we're talking about what has been a SaaS, what's basically a SaaS solution.

So I have to bring some other brands in to the conversation. So you're saying that I can still protect my vSAN-based VMs running on a Dell PowerEdge platform up to whatever destination that I would want it to run on. You got it. Exactly. So the source and the target of your data, that remains exactly how you want it, how you've always done it, how you've done it with Zerto, how you've done it with other products. It's the control plane that we've abstracted up to the public cloud, with GreenLake for DR and GreenLake for backup recovery.

So one of the advantages of moving cloud services up to, or on-premises services up to the cloud is that, you know, I kind of shortcut this ability or this need to create automations on my own or create my own APIs. If I want to programmatically create data protection policies as part of my CICD process, in theory, I should be able to do this with GreenLake, any one of the GreenLake data protection solutions. Is that a option? So can I build Terraforms that automatically create backup policies and data protection policies?

I'm glad you went there. Absolutely, 100%, because it's still API first. So even though you're in the GreenLake cloud platform, you've got API access and all the services there, not just GreenLake for DR and backup, which I cover, but all the other services, PCB, block, file, et cetera. All of them offer APIs that you can integrate with and automate your operations with. So you want to use Terraform? Go for it. Call the APIs. The GreenLake, you essentially, the layers are going to be, you go from your CICD, Terraform, whatever automation platform you use, you're going to call GreenLake APIs, and the GreenLake APIs are then going to make those abstracted calls to the gears that's running on-prem.

And so, in theory, if I understand this correctly, I can have some HPE gear in Equinix under the GreenLake model. I can basically have the Equinix folks provision all of that for me. I can never see it, and I can administer or I can consume it via GreenLake with these services. You got it. That's the theory. Yes, you got it. Or you could be managing existing gear that you may have, or your data center, or Equinix, or public cloud.

So that's the whole idea is let's abstract the control plane regardless of where the actual physical may be. So last question, am I missing any big picture capability around moving my control plane for disaster recovery into the public cloud? Are there key components of what this enables me to do that I couldn't do before? Other than what we just said, that was actually pretty cool. I was not expecting you to say yes to it, but anything other than that? So two things I'll bring up.

First, day two operations. think of all the components on-prem that you would have to manage, monitor, upgrade, patch just as an administrator, right? So by moving the control plane to cloud, you're essentially giving that ownership to the service, right? If we think along the lines of O365, right? your email administrator doesn't manage Exchange servers anymore, right? They manage an outcome for the customer, which is email and services are provided. So by moving that control plane up to a cloud platform, we're delivering the same kind of capabilities for the customer.

You're not managing those bits and bytes on-prem. What you're focused on is an outcome that you want for your data, which is good RPOs, RTOs, protection against ransomware, et cetera, so on and so forth. So that's one side of it, and I said the second half. The second half of this isn't something that we're going to be announcing later on this year, so I'll kind of let the cat out of the bag. We did announce with Zerto inline ransomware detection at a block level at Zerto 10 launch.

Bringing that knowledge and that capability up to cloud from a reporting and aggregation standpoint starts making sense. So now, I will not expose your data, Keith, to another customer. However, because I can see now what's happening across a global level, I can start providing you more value because I can understand what's happening beyond just your data center. So there's some inherent benefits that are going to come in. Just the technologies that have been limited to one data center, one instance of Zerto, now have ability to span across globally.

And I'm anxious to see what some of my product managers and some of the engineers come up with because now they have a global view on an entire customer base, and it can really start providing value from what they're seeing in that environment. So I think that's where inherent later on benefits of having a SaaS-based control plane start showing. Yeah, you get rid of this shelfware problem that we've had in the enterprise where we buy an ELA for something like a Zerto, and we simply don't have the time to upgrade it.

Super critical to us, unless there's an emergency security patch, the priority is just extremely low. This is just another peace of mind. And while we're bullish on the concept of moving the data center control plane up to the cloud while we benefit from having on-prem assets without the burden of administration. Deepak, I really appreciate you spending the time, and we appreciate HPE for sponsoring another CTO Advisor podcast. com, now a Futurum Group company. If you want to learn more about me, you can find me on the web at ctoadvisor on almost every platform.

Until then, talk to you later. Thanks, Deepak. Thanks, Keith. Always a pleasure. Thank you.