⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All FinOps & System Design Interview Questions Scenario 82 of 98 in FinOps & System Design
Staff SRE / Security Architect System Design Disaster Recovery & Ransomware Protection System Design

Q: A ransomware group compromises your primary cloud administrative credentials, encrypts production EBS volumes, and attempts to delete all snapshots and backups to extort payment. How do you design an air-gapped, immutable backup platform that guarantees backups cannot be deleted or encrypted by any attacker, and enables complete recovery of 50 Kubernetes clusters within 4 hours?

Engineering a ransomware-proof, air-gapped enterprise backup and rapid recovery architecture across Kubernetes and databases using Velero, S3 Object Lock (WORM), and isolated backup security accounts.

#System Design #Backup & Restore #Velero #Ransomware #S3 Object Lock #Air Gap #Kubernetes
🎙️ Candidate Opening & Architectural Context
"Modern ransomware actively targets backup repositories first. If backups reside in the same cloud account, compromised admin credentials will delete them instantly. We designed an air-gapped, tamper-proof enterprise backup platform using Velero, AWS S3 Object Lock, and isolated cryptographic vault accounts."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? The Linux Foundation's FinOps Certified Practitioner (FOCP) Program covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Establish Physically Isolated Backup Vault Cloud Account

Separate backup storage from production management planes entirely:

  • Air-Gapped Vault Account: Created an isolated AWS account (Security-Backup-Vault) with zero shared IAM users, zero SSO trust from production, and MFA hardware security tokens locked in a physical safe.
  • One-Way Ingress: Production clusters are granted strict write-only (PutObject) permissions to the backup bucket via cross-account IAM roles, with zero delete (DeleteObject) permissions permitted.
Pro Tip: Even if an attacker gains AdministratorAccess in the production cloud account, they have ZERO permissions to delete or modify objects in the vault account.
2️⃣

Enforce Immutable WORM Storage via S3 Object Lock (Compliance Mode)

Make backup deletion physically impossible at the storage layer:

  • Object Lock Compliance Mode: Backups are written with Object Lock Compliance mode enabled for 90 days.
  • Zero Administrative Override: In Compliance mode, objects cannot be deleted, altered, or shortened by ANY IAM role, the root account holder, or AWS support.
  • KMS Key Separation: Buckets are encrypted with an HSM-backed KMS key residing strictly in the vault account.
Pro Tip: Compliance mode guarantees that even a root user in the vault account cannot destroy backup archives before the retention timer expires.
3️⃣

Automate Application & Persistent Volume Backups with Velero & CSI Snapshots

Capture full Kubernetes declarative state and persistent volume data:

  • Velero Deployment: Deployed Velero with CSI plugin across all Kubernetes clusters.
  • Atomic Schedules: Scheduled hourly backups capturing namespace metadata, ConfigMaps, Secrets, and persistent volume snapshots via CSI VolumeSnapshot.
  • Kopia Deduplication: Integrated Velero with Kopia for file-level volume backups, achieving 65% deduplication efficiency and slashing storage consumption.
Pro Tip: Velero captures both the container declarative manifests and the underlying persistent disk storage simultaneously in a single atomic recovery point.
4️⃣

Execute Automated Clean-Room Rapid Recovery Drills

Prove recoverability into a clean, uncompromised target environment:

  • Clean-Room Automation: Terraform pipeline automatically provisions a fresh, sanitized Kubernetes cluster in an alternate region.
  • Restore Execution: Velero restores the complete production environment from the immutable vault bucket: velero restore create --from-backup prod-daily-backup.
  • Measured RTO: Complete cluster restoration (400 pods, 12 TB data) verified in 2 hours 18 minutes (well under 4-hour SLA).
Pro Tip: Backups that are not regularly restored in automated recovery drills must be assumed to be corrupted and unrecoverable.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Ransomware-proof enterprise backups require an air-gapped vault cloud account with write-only cross-account IAM, S3 Object Lock Compliance mode WORM retention, Velero Kubernetes orchestration, and automated clean-room restore drills."
⚡ 60-Second Elevator Pitch Talking Points
  • Store all backups in an isolated vault AWS account with zero shared IAM or SSO access.
  • Enforce S3 Object Lock Compliance mode to make backup deletion impossible even for root admins.
  • Use Velero with CSI volume snapshots to orchestrate atomic Kubernetes application backups.
  • Validate rapid 2-hour clean-room recovery drills quarterly to mathematically guarantee business continuity.
Advertisement
Want more FinOps & System Design scenarios?
Explore our complete collection of scenario-based FinOps & System Design interview runbooks.
Browse All FinOps & System Design Questions →