[Yandex Cloud documentation](../../index.md) > [Yandex Cloud Backup](../index.md) > [Concepts](index.md) > Backup policies

# Backup policies


Backups of Yandex Cloud resources are created in Cloud Backup automatically according to _backup policies_.

You can start [creating](../operations/policy-vm/create.md) the policies after you [activate](index.md#providers) Cloud Backup.

{% note info %}

You can create or [update](../operations/policy-vm/update.md) a policy using the Yandex Cloud management console, Terraform, or a [JSON](https://en.wikipedia.org/wiki/JSON) [specification](#specification) via the Yandex Cloud [CLI](../../cli/quickstart.md) or API.

The Yandex Cloud management console does not support some parameters from the JSON specification for policies.

{% endnote %}

After activation, the system automatically creates the following backup policies:
* `Default daily`: Daily incremental backup with the last 15 backups retained.
* `Default weekly`: Weekly incremental backup with the last 15 backups retained.
* `Default monthly`: Monthly incremental backup with the last 15 backups retained.

By default, VMs and Yandex BareMetal servers in Cloud Backup are not linked to any backup policies. To start creating backups, link a [VM](../operations/policy-vm/attach-and-detach-vm.md) or [BareMetal server](../operations/backup-baremetal/backup-baremetal.md#agent-install) to one or more policies.

The backup policy specifies:

* Backup type: Full or incremental. For more information, see [Backup types](backup.md#types).

  {% note info %}
  
  If you use a policy with the `fastBackupEnabled` [option](policy.md#specification) and ran an antivirus scan before creating an [incremental backup](backup.md#types), the backup time may increase significantly. Read more in [Interaction with an antivirus](av-interaction.md).
  
  {% endnote %}

* Schedule type and settings:

    * `Fixed schedule`: Backup frequency in hours, days, weeks, or months. Use [UTC±00:00](https://en.wikipedia.org/wiki/UTC±00:00).
    * `Interval between backups`: Interval, in hours or days, between the end of the previous backup and the start of the new one.

* [Backup retention](#retention) settings.

{% note info %}

Backups are created based on the VM's or Yandex BareMetal server's local time. There may be a slight delay in the schedule depending on the current service load.

{% endnote %}

## Storing backups {#retention}

You can set up backup storage for the policy. The following can be stored for each VM or BareMetal server included in the policy:

* All backups created under this policy.
* Only the last several backups.
* Only the backups younger than a certain age, e.g., those created during the last few days.

The settings apply to all VMs and BareMetal servers in the policy.

{% note info %}

You can restore neither a VM backup to a BareMetal server, nor a BareMetal server backup to a VM.

{% endnote %}

If you make changes to the backup retention rules, by default they will take effect as soon as you create another backup. For a detailed description of backup retention policy configuration parameters, see the next section.

## Backup policy specification {#specification}

In Cloud Backup, you can [create](../operations/policy-vm/create.md) or [update](../operations/policy-vm/update.md) backup policies based on a specification in [JSON](https://en.wikipedia.org/wiki/JSON) format by using the Yandex Cloud [command line](../../cli/quickstart.md) or making an API request.

The complete backup policy specification for Cloud Backup is detailed below. You can also view the current specification version in the [REST API reference](../backup/api-ref/Policy/create.md).

```json
{
  "compression": "string",
  "format": "string",
  "multiVolumeSnapshottingEnabled": bool,
  "preserveFileSecuritySettings": bool,
  "runLater": bool,
  "sectorBySector": bool,
  "validationEnabled": bool,
  "lvmSnapshottingEnabled": bool,
  "fileFilters": {
    "exclusionMasks": [
      "string"
    ],
    "inclusionMasks": [
      "string"
    ]
  },
  "reattempts": {
    "enabled": bool,
    "interval": {
      "type": "string",
      "count": "string"
    },
    "maxAttempts": "string"
  },
  "silentModeEnabled": bool,
  "splitting": {
    "size": "string"
  },
  "vmSnapshotReattempts": {
    "enabled": bool,
    "interval": {
      "type": "string",
      "count": "string"
    },
    "maxAttempts": "string"
  },
  "vss": {
    "enabled": bool,
    "provider": "string"
  },
  "archive": {
    "name": "string"
  },
  "performanceWindow": {
    "enabled": bool
  },
  "retention": {
    "rules": [
      {
        "backupSet": [
          "string"
        ],
        "maxAge": {
          "type": "string",
          "count": "string"
        },
        "maxCount": "string",
      }
    ],
    "beforeBackup": bool
  },
  "scheduling": {
    "backupSets": [
      {
        "time": {
          "weekdays": [
            "string"
          ],
          "repeatAt": [
            {
              "hour": "string",
              "minute": "string"
            }
          ],
          "repeatEvery": {
            "type": "string",
            "count": "string"
          },
          "timeFrom": {
            "hour": "string",
            "minute": "string"
          },
          "timeTo": {
            "hour": "string",
            "minute": "string"
          },
          "monthdays": [
            "string"
          ],
          "months": [
            "string"
          ],
          "type": "string"
        },
        "sinceLastExecTime": {
          "delay": {
            "type": "string",
            "count": "string"
          }
        },
      }
    ],
    "enabled": bool,
    "maxParallelBackups": "string",
    "randMaxDelay": {
      "type": "string",
      "count": "string"
    },
    "scheme": "string",
    "weeklyBackupDay": "string"
  },
  "cbt": "string",
  "fastBackupEnabled": bool,
  "quiesceSnapshottingEnabled": bool,
  "prePostCommands": [
    {
      "cmd": "string",
      "args": "string",
      "enabled": bool,
      "stopOnError": bool,
      "type": "string",
      "wait": bool,
      "workdir": "string"
    }
  ]
}
```

Specification description:

| Attribute | Description | Possible values |
|---|---|---|
| `compression` | Backup compression ratio. | <ul><li>`COMPRESSION_UNSPECIFIED`: Not specified.</li><li>`NORMAL`: Standard compression ratio.</li><li>`HIGH`: High compression ratio.</li><li>`MAX`: Maximum compression ratio.</li><li>`OFF`: Disabled.</li></ul> |
| `format` | Backup format. | <ul><li>`FORMAT_UNSPECIFIED`: Not specified.</li><li>`VERSION_11`: Deprecated format, not recommended.</li><li>`VERSION_12`: Recommended format for high-speed backup and recovery.</li><li>`AUTO`: Automatic format selection. Version 12 is used by default unless you are creating incremental backups for the images created in other versions.</li></ul> |
| `multiVolumeSnapshottingEnabled` | Backing up multiple volumes at the same time. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
| `preserveFileSecuritySettings` | Retaining file security settings. **The parameter is no longer supported.** | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
| `runLater` | If the VM was `Stopped` during a scheduled backup, all skipped backup jobs will be executed after the VM starts. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
| `sectorBySector` | Sector-by-sector backup. Backs up all disk or volume sectors, including empty areas and unallocated space. For disks with unsupported file systems, this mode applies automatically. You cannot recover app data from a backup like that. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
| `validationEnabled` | Checks the possibility of recovering data from the new backup. During procedure, a checksum is calculated for each section available for recovery, so it can take a while. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
| `lvmSnapshottingEnabled` | Uses LVM to create a volume snapshot. If the snapshot cannot be created using LVM, it will be created using the Cloud Backup agent. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
| `cbt` | Changed Block Tracking (configuration for tracking backup contents). | <ul><li>`CHANGED_BLOCK_TRACKING_UNSPECIFIED`: Not specified.</li><li>`USE_IF_ENABLED`: Use if enabled.</li><li>`ENABLE_AND_USE`: Enable and use.</li><li>`DO_NOT_USE`: Do not use.</li></ul> |
| `fastBackupEnabled` | Fast backup: setting for tracking changes to files. When enabled, file changes are detected by the file size and timestamp. When disabled, files are checked for changes by comparing their contents to backed up files. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
| `quiesceSnapshottingEnabled` | Using `quiescing` when creating backups. **The parameter is no longer supported.** | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |

Attribute sections with multiple nested values.

{% list tabs %}

- reattempts

  Setting up backup reattempts in the event of failures.

  | Attribute | Description | Possible values |
  |---|---|---|
  | `reattempts.enabled` | Retry creating a backup if a noncritical error occur (e.g., failure to connect to a target disk). | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
  | `reattempts.interval.type` | Unit of time used to set the reattempt interval. | <ul><li>`TYPE_UNSPECIFIED`: Not specified.</li><li>`SECONDS`</li><li>`MINUTES`</li><li>`HOURS`</li><li>`DAYS`</li><li>`WEEKS`</li><li>`MONTHS`</li></ul> |
  | `reattempts.interval.count` | Interval between reattempts. | Integer |
  | `reattempts.maxAttempts` | Maximum number of reattempts. If reached, the operation is considered failed. | Integer |
  | `silentModeEnabled` | Silent mode to reduce the number of user interactions wherever possible. Disabled by default. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
  | `splitting.size` | Splitting a backup into volumes of a preset size in bytes. If no value is specified, a backup is saved as a single file. | Integer |

- vmSnapshotReattempts

  Configuring backup reattempts in the event of failure.

  | Attribute | Description | Possible values |
  |---|---|---|
  | `vmSnapshotReattempts.enabled` | Retry creating a backup if errors occur. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
  | `vmSnapshotReattempts.interval.type` | Unit of time used to set the reattempt interval. | <ul><li>`TYPE_UNSPECIFIED`: Not specified.</li><li>`SECONDS`</li><li>`MINUTES`</li><li>`HOURS`</li><li>`DAYS`</li><li>`WEEKS`</li><li>`MONTHS`, months</li></ul> |
  | `vmSnapshotReattempts.interval.count` | Interval between reattempts. | Integer |
  | `vmSnapshotReattempts.maxAttempts` | Maximum number of reattempts. If reached, the operation is considered failed. | Integer |

- vss

  Volume Shadow Copy Service (VSS) setup. The service notifies applications with VSS support of the upcoming backup start. The applications save information from memory to disk, which ensures data integrity during backup.

  | Attribute | Description | Possible values |
  |---|---|---|
  | `vss.enabled` | Enable VSS. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
  | `vss.provider` | Choosing a VSS provider. | <ul><li>`VSS_PROVIDER_UNSPECIFIED`: Not specified.</li><li>`NATIVE`: Native VSS provider.</li><li>`TARGET_SYSTEM_DEFINED`: VSS provider defined in the target system.</li></ul>|
  | `archive.name` | Name of the archive being created. | String that may contain the following variables: `[Machine Name]`, `[Plan ID]`, `[Plan Name]`, `[Unique ID]`, and `[Virtualization Server Type]`. |
  | `performanceWindow` | Enable a performance window to limit the impact of backups and storage maintenance on performance. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |

- retention

  Setting up rules for storing backups. The `maxAge` and `maxCount` attributes are mutually exclusive, i.e., the use of one makes it impossible to use the other.

  | Attribute | Description | Possible values |
  |---|---|---|
  | `retention.rules.backupSet` | Set of backups for which the retention settings are specified. | String |
  | `retention.rules.maxAge.type` | Setting a backup retention rule to delete outdated backups depending on their age in specified time units. | <ul><li>`TYPE_UNSPECIFIED`: Not specified.</li><li>`SECONDS`</li><li>`MINUTES`</li><li>`HOURS`</li><li>`DAYS`</li><li>`WEEKS`</li><li>`MONTHS`, months</li></ul> |
  | `retention.rules.maxAge.count` | Maximum backup retention period in time units set by the `maxAge.type` attribute. | Integer |
  | `retention.rules.maxCount` | Setting a backup retention rule to delete outdated backups depending on the specified maximum number of stored backups. | Integer |
  | `retention.beforeBackup` | Applying backup retention rules before the end of the backup. When creating a policy by default or via the management console, the `beforeBackup=false` rule is set. The backup retention rule settings will take effect as soon as another backup is created. | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |

- scheduling

  Setting up a backup schedule. The `time` (based on preset time) and `sinceLastExecTime` (with preset interval between backups) attributes are mutually exclusive, i.e., the use of one makes it impossible to use the other.

  #|
  || **Attribute** | **Description** | **Possible values** ||
  || `scheduling.backupSets.`
  `time.weekdays` | Days of the week to create backups on. You can specify multiple values separated by commas. |
  * `DAY_UNSPECIFIED`: Not specified.
  * `MONDAY`
  * `TUESDAY`
  * `WEDNESDAY`
  * `THURSDAY`
  * `FRIDAY`
  * `SATURDAY`
  * `SUNDAY` ||
  || `scheduling.backupSets.`
  `time.repeatAt.hour` | Time to repeat backups at: hours. | Integer from 0 to 23. ||
  || `scheduling.backupSets.`
  `time.repeatAt.minute` | Time to repeat backups at: minutes. | Integer from 0 to 59. ||
  || `scheduling.backupSets.`
  `time.repeatEvery.type` | Units of time used to set the repeat backup interval. |
  * `TYPE_UNSPECIFIED`: Not specified.
  * `SECONDS`
  * `MINUTES`
  * `HOURS`
  * `DAYS`
  * `WEEKS`
  * `MONTHS`, months ||
  || `scheduling.backupSets.`
  `time.repeatEvery.count` | Backup reattempt interval in units set by the `repeatEvery.type` attribute. | Integer. ||
  || `scheduling.backupSets.`
  `time.timeFrom.hour` | Start time for the backup interval (from): hours. | Integer from 0 to 23. ||
  || `scheduling.backupSets.`
  `time.timeFrom.minute` | Start time for the backup interval (from): minutes. | Integer from 0 to 59. ||
  || `scheduling.backupSets.`
  `time.timeTo.hour` | End time for the backup interval (to): hours. | Integer from 0 to 23. ||
  || `scheduling.backupSets.`
  `time.timeTo.minute` | End time for the backup interval (to): minutes. | Integer from 0 to 59. ||
  || `scheduling.backupSets.`
  `time.monthdays` | Day of the month to create backups on. You can specify multiple values separated by commas. | Integer from 1 to 31. ||
  || `scheduling.backupSets.`
  `time.includeLastDayOfMonth` | Making backups on the last day of each month.

  {% note warning %}

  If set to `true`, this setting overrides other schedule settings: days of the week, days of the month, etc.

  {% endnote %}
  
  |
  * `true`: Enabled.
  * `false`: Disabled.
  ||
  || `scheduling.backupSets.`
  `time.months` | Months to create backups in. You can specify multiple values separated by commas. | Integer from 1 to 12. ||
  || `scheduling.backupSets.`
  `time.type` | Backup frequency. |
  * `REPEATE_PERIOD_UNSPECIFIED`: Not specified.
  * `HOURLY`
  * `DAILY`
  * `WEEKLY`
  * `MONTHLY` ||
  || `scheduling.backupSets.`
  `sinceLastExecTime.delay.type` | Units of time used to set the interval between backups. |
  * `TYPE_UNSPECIFIED`: Not specified.
  * `SECONDS`
  * `MINUTES`
  * `HOURS`
  * `DAYS`
  * `WEEKS`
  * `MONTHS`, months ||
  || `scheduling.backupSets.`
  `sinceLastExecTime.delay.count` | Interval between backups in time units set by the `delay.type` attribute. | Integer. ||
  || `scheduling.enabled` | Scheduled backup. |
  * `true`: Enabled.
  * `false`: Disabled. ||
  || `scheduling.maxParallelBackups` | Maximum number of parallel backups; unlimited if no value is specified. | Integer. ||
  || `scheduling.randMaxDelay.type` | Units of time used to set the maximum delay before running parallel jobs. |
  * `TYPE_UNSPECIFIED`: Not specified.
  * `SECONDS`
  * `MINUTES`
  * `HOURS`
  * `DAYS`
  * `WEEKS`
  * `MONTHS`, months ||
  || `scheduling.randMaxDelay.count` | Maximum delay before running parallel jobs in time units set by the `randMaxDelay.type` attribute. The delay is determined randomly but it may not exceed the value set here. | Integer. ||
  || `scheduling.scheme` | Backup schedule scheme. |
  * `SCHEME_UNSPECIFIED`: Not specified.
  * `SIMPLE`: Simple.
  * `ALWAYS_FULL`: Always full.
  * `ALWAYS_INCREMENTAL`: Always incremental.
  * `WEEKLY_INCREMENTAL`: Create an incremental backup every week.
  * `WEEKLY_FULL_DAILY_INCREMENTAL`: Create an incremental backup every day and a full one weekly.
  * `CUSTOM`: Custom.
  * `CDP`: Continuous Data Protection. ||
  || `scheduling.weeklyBackupDay` | Day of the week for the weekly backup. | Integer from 1 to 7 ||
  |#

- fileFilters

  Setting up filters. You can exclude files and folders from backups or, conversely, create backups of only specific elements of the file system.

  To include or exclude files, add some criteria, e.g., file names, paths, or masks. `*` and `?` wildcards are supported. Use a new line for each criterion. Criteria are case-insensitive.

  Exclusion filters take precedence over inclusion filters.

  | Attribute | Description | Value (example) |
  |---|---|---|
  | `exclusionMasks` | Criterion for files to exclude from the backup. | `/tmp` |
  | `inclusionMasks` | Criterion for files to include into the backup. | `/home/user*` |

- prePostCommands

  Setting actions Cloud Backup will perform before and after the backup.

  | Attribute | Description | Value (example) |
  |---|---|---|
  | `cmd` | Command or path to the executable file that needs to be executed (run). | `/usr/bin/myapp` |
  | `args` | Command line parameters to apply when executing the command (running the file). | `-d -rw` |
  | `enabled` | Enabling or disabling the command execution (running the file). | <ul><li>`true`: Enabled.</li><li>`false`: Disabled.</li></ul> |
  | `stopOnError` | Stopping the backup if there is an error during command execution (running the file). | <ul><li>`true`: Stop the backup.</li><li>`false`: Not stop the backup.</li></ul> |
  | `type` | Time of command execution (running the file). | <ul><li>`COMMAND_TYPE_UNSPECIFIED`: Not specified.</li><li>`PRE_COMMAND`: Execute the command (run the file) prior to starting the backup.</li><li>`POST_COMMAND`: Execute the command (run the file) after the backup completes.</li><li>`PRE_DATA_COMMAND`: Execute the command (run the file) immediately before data capture (taking a snapshot).</li><li>`POST_DATA_COMMAND`: Execute the command (run the file) immediately after data capture (taking a snapshot).</li></ul> You can add no more than one command of each type per policy: `PRE_COMMAND`, `POST_COMMAND`, `PRE_DATA_COMMAND`, and `POST_DATA_COMMAND`.<br><br>The `PRE_DATA_COMMAND` and `POST_DATA_COMMAND` commands run in immediate proximity to the snapshot, while `PRE_COMMAND` and `POST_COMMAND` run at the very beginning and end of the entire backup process. |
  | `wait` | Waiting for the command execution (file running) to complete before starting the backup. | <ul><li>`true`: Wait for the command to complete.</li><li>`false`: Not wait for the command to complete.</li></ul> |
  | `workdir` | Working directory to execute the command (run the file) in. | `/etc/myapp/` |

{% endlist %}

## Use cases {#examples}

* [Associating a Yandex Cloud Backup policy to a VM automatically](../tutorials/vm-with-backup-policy/index.md)


#### Useful links {#see-also}

* [Creating a backup policy](../operations/policy-vm/create.md)
* [Linking a VM or Yandex BareMetal server to a backup policy](../operations/policy-vm/attach-and-detach-vm.md)
* [Unlinking a VM or Yandex BareMetal server from a backup policy](../operations/policy-vm/detach-vm.md)
* [Updating a backup policy](../operations/policy-vm/update.md)
* [Getting information about a backup policy](../operations/policy-vm/get-info.md)