Loading...
Loading...
If using Veeam Kasten to protect persistent volumes provisioned with the Azure Disk CSI provisioner, and encounter the following error during the block mode export phase of a policy run: Failure in exporting restorepoint with log details similar to: Access not permitted for resource /subscriptions/REDACTED/resourceGroups/REDACTED/providers/Microsoft.Compute/snapshots/snapshot-xxxx because the network access policy is DenyAll. and "NetworkAccessPolicyIsDenyAll"
Starting with Azure CSI driver v1.33.3, public network access is disabled by default for new disk creation: [release-1.33] chore: disable public network access for new disk creation by default by @k8s-infra-cherrypick-robot in #3230 This means all Azure disks (used for Kubernetes PVCs provisioned by Azure CSI) and associated volume snapshots are created with DenyAll network access by default. This results in Kasten being unable to access snapshot data to perform export operations.
Solution: Update StorageClass to Allow Public Network Access Create or update the StorageClass with the following parameters:
Summary The error occurs due to Azure CSI's default DenyAll network policy on new disks. Update the StorageClass and/or manually adjust disk policies to AllowAll, or as a workaround, disable storage API usage for block mode operations. For further information, refer to the official Azure Disk CLI documentation. If you need more details or troubleshooting help, please contact Veeam support.
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.