Commvault's own documentation covers the Oracle iDataAgent well enough, and it covers Solaris well enough, but it does not walk you through the two together on a text-mode installer where one wrong answer means you reinstall. This is that walkthrough, from a clean Solaris 11.3 box to a working sbt_tape channel in RMAN.
All hostnames, addresses and group names in the screenshots are placeholders. Substitute your own.
Before you start
You need the Commvault Solaris agent package staged somewhere on the machine, the CommServe hostname, and a decision from whoever runs your backup platform about which storage policy this client belongs to. You will be asked for that at the end and you cannot skip it.
Oracle is assumed to be installed already, with a known ORACLE_HOME and the usual dba and oinstall groups.
1. Create the backup user
Commvault processes that touch the database run as a dedicated user rather than as oracle or root. Create it, give it a password, and put it in the right groups:
useradd -d localhost:/export/home/csb -m csb
passwd csb
usermod -g dba -G +oinstall,wheel csb
The dba primary group lets it reach the database. oinstall matters later — the installer will ask for a Unix group and Oracle's group is the correct answer. wheel is there for sudo.
In /etc/sudoers, the wheel group needs to run commands without being prompted for a password. The installer calls sudo repeatedly and will fail on a password prompt it cannot answer.
2. Create the target directories
mkdir /opt/commvault
mkdir /var/log/commvault
chown csb /opt/commvault
chown csb /var/log/commvault
Binaries need about 335 MB free, logs about 100 MB. The installer checks and refuses if either is short.
3. Stage the installer package
Copy the Solaris agent package to /tmp — WinSCP is fine — then hand it to the backup user:
chown -R csb /tmp/Solaris-commvault-agent/*
chmod -R 755 /tmp/Solaris-commvault-agent/*
The procedure I inherited used chmod -R 777 here. Do not. Once ownership is correct, 755 is enough, and 777 on an unpacked installer tree in a world-writable directory is exactly the kind of thing that shows up in an audit finding six months later.
4. Point Solaris at sudo
This one is Solaris-specific and it is the step people miss. Edit /etc/default/login and set the PATH= variable to include the directory where sudo lives. Without it the installer's sudo calls resolve to nothing and the run dies partway through with an error that does not mention PATH at all.
5. Run the installer
su - csb
cd /tmp/Solaris-commvault-agent
sudo ./cvpkgadd
The rest is a text-mode wizard. What follows is every screen where the answer is not obvious.
Install task. Install packages on this machine — you are not building a custom package.
Interface selection. The installer lists every interface it found. Pick the one on your backup network, not the production or admin address. Getting this wrong means backups will run over the wrong path and nobody notices until the network team asks why the production link saturates every night.
Package selection. File System Core and File System are mandatory. Add Oracle. Leave DB2 alone unless you actually run it.
Install and log directories. /opt and /var/log — the installer appends commvault itself, so you end up with /opt/commvault and /var/log/commvault/Log_Files, which is what you created in step 2.
Unix group. Answer yes to assigning a dedicated group, then enter oinstall. The installer suggests creating a commvault group and that is right for a plain file system client, but for the Oracle agent it has to be Oracle's install group or the agent cannot read what it needs to back up.
Permissions. Read and execute for other users, no write.
Client host name. The fully qualified name of the machine.
Client name. This is the label the client shows up under in the CommCell console, and it defaults to whatever the host is called. Change it to something a human can scan in a list of a few hundred entries. You will thank yourself during an incident.
Restore-only agents. No, unless you are deliberately installing a licence-free restore-only client.
Summary. Read it. This is the last screen before anything is written.
Firewall and CommServe. Answer the firewall question honestly — if there is a firewall between this client and the CommServe, say so and configure it here, because retrofitting it afterwards is worse. Then enter the CommServe hostname, fully qualified and resolvable from this machine. Check that with nslookup before you type it, not after.
Per-client certificate. No, unless your CommServe enforces it. If it does, you need a temp certificate from the CommCell console before you get this far.
Client groups. Leave everything unchecked. Group membership is a platform-side decision and the backup administrator will set it.
Subclient policy. Do not configure.
Storage policy. You have to pick something and the list is long. Pick the first entry, finish the install, then ask the backup administrator to move the client to the correct policy. They will know which one; you almost certainly will not, and guessing here means your backups land in the wrong retention bucket.
6. Relink the Oracle libraries
The agent is installed but RMAN cannot talk to it yet. Relink the SBT_TAPE library as root:
su -
cd /opt/commvault/iDataAgent
./Ora_install.sh
It asks four questions and one of them is a trap:
Please enter ORACLE_USER ID: oracle
Please enter user group for oracle [dba]: dba
Please enter ORACLE_HOME directory: /u01/app/oracle/product/12.1.0.2/dbhome_1/
Please enter the home directory of user oracle [~oracle]: /export/home/oracle
Would you like to relink $PRODUCT with different ORACLE_HOME now(y/[n])? n
Answer n to the last one. It is offering to relink against a different ORACLE_HOME than the one you just gave it, and saying yes sends you round the loop again.
7. Test the channel
Nothing above proves anything until RMAN can allocate a tape channel. From RMAN:
run {
allocate channel ch1 type 'sbt_tape'
PARMS="SBT_LIBRARY=/opt/commvault/Base64/libobk.so,ENV=(CVREG=/home/csb/CommVaultRegistry/)";
}
If that fails, the registry path is the usual reason. Depending on how the agent was installed it lives in the backup user's home or under /etc:
run {
allocate channel ch1 type 'sbt_tape'
PARMS="SBT_LIBRARY=/opt/commvault/Base64/libobk.so,ENV=(CVREG=/etc/CommVaultRegistry/)";
}
Try both before you start suspecting the library. A successful allocation means the agent, the licence and the CommServe connection are all working, and you can hand the client over to the backup team.
Comments
Post a Comment