Projects/ANAF Back-up

Public sector·Tax administration·Backup, archive & recovery

Every filing the country makes,
recoverable from two data centres.

A backup and restore platform for the National Tax Administration Agency estate — built twice, in two national data centres two hundred kilometres apart, and accepted only after every class of system had been backed up and restored in front of the client.

ClientNational Tax Administration Agency
ProgrammeHardware-software solution for backup and restore
SitesTwo national data centres, ~200 km apart
In scopeBackup, restore and long-term archive
Our roleDesign, delivery, installation, configuration, acceptance testing
Scale304 systems · 800+ TB of live data
ANAF Back-up. On the left, a compromised estate: a screen reading COMPROMISED, damaged hardware and rejected documents. On the right, the same data protected — documents and databases flowing behind a shield into two lit server rooms, marked Data Center 1 and Data Center 2 on a map of Romania. Caption: Protejăm datele critice ale ANAF pentru continuitate și încredere, chiar și în situații neprevăzute.

01The mandate

A tax administration cannot lose a document.
Not one, not ever.

The estate behind Romanian tax administration is not a modern greenfield platform. It is thirty years of accumulated public service: partitioned enterprise servers, database estates that predate the cloud era, several virtualisation platforms running side by side, an enterprise messaging system, and an electronic archive that has been accepting citizens' documents continuously since 2009.

All of it has to be recoverable — more than eight hundred terabytes of live data, and an archive of over 150 million documents. A declaration filed through the public portal, a document lodged at a counter in a county tax office, a database that clears payments: each one carries a legal obligation that does not soften because the system holding it is fifteen years old.

So the platform was delivered twice — a complete, independent instance in each data centre, two hundred kilometres apart, with each site holding a copy of the other's backups. Losing a site does not mean losing the ability to recover from it.

—Two complete, independent platforms, two hundred kilometres apart
—Each data centre holds a copy of the other's backups and archive
—Every class of system backed up and restored before acceptance
—Legacy systems carried forward, not left out of the protection scope

02Overview

Disk, object and tape,
under one policy engine.

Each data centre received a complete protection stack: a deduplicating disk tier holding the daily recovery point, an object tier for long-term archive with a flash cache in front of it, and a tape library for the copies that have to leave spinning disk. One policy engine drives all three, with agents installed on the protected systems themselves. Capacity was sized for three years of growth, and the existing network and storage fabrics were reused rather than replaced.

—Three storage tiers per site, each with a different job
—One policy engine covering every system in the estate
—Capacity sized for a three-year retention horizon
—304 systems onboarded across the two data centres

03What was delivered

Six components,
delivered identically in both data centres.

01

Racks & power

Three full-height enclosures per site, each on metered, dual-fed power. Draw and cooling load were calculated and declared to the client before anything was installed, then measured against the declaration.

02

Backup & restore platform

An enterprise data-protection suite licensed for the entire estate at each site — every processor socket and the full storage footprint allocated to servers, virtual machines, databases, messaging and file systems.

03

Deduplicating disk tier

The primary landing zone for every backup, on high-capacity disk with inline deduplication, sized for three years of retention and connected to both the storage and the network fabric already in the data centre.

04

Object archive tier

A multi-node object platform for data that has to be kept for years, behind its own redundant switching, with an all-flash array acting as the cache tier in front of it and a policy engine moving data between them.

05

Tape libraries

A library at each site, presented to the platform as a single logical unit, for the copies that have to leave spinning disk — including write-once media for records that must not be alterable after they are written.

06

Agent rollout & integration

Protection agents installed across every operating-system family in the estate, with application-aware modules for the databases, the messaging platform and each virtualisation stack, then registered, grouped and bound to policies.

04What is protected

Five classes of system,
each with its own way of being backed up.

Class 01Partitioned enterprise serversThe oldest tier, and the least forgiving
Supported partitions
Protection agent installed into the logical partition and registered against the backup platform, then driven by the same policy set as everything else.
End-of-life partitions
Too old for any supported agent. Protected instead by presenting storage from the backup appliance directly to the partition — no agent required.
Licensed footprint
Every processor socket carrying these partitions is licensed, in both data centres, with no sampling and no exclusions.
Restore proven
Backup and restore executed on partitions chosen by the client, not by us.
Class 02VirtualisationSeveral platforms, running in parallel
Management-plane integration
Where the platform exposes one, its management layer is registered directly with the backup server and machines are grouped and driven by policy rather than configured one by one.
Host-agent integration
Where it does not, federated backup runs through agents installed on each host, so the guests are captured consistently from underneath.
More than one stack
The estate runs several virtualisation platforms side by side. All of them fall under the same policy set and the same reporting.
Licensed footprint
Every virtualisation socket in both data centres is covered.
Class 03DatabasesApplication-aware, not crash-consistent
Application-aware modules
Each database technology is protected through its own module, so a backup is a consistent database rather than a copy of files that happened to be open.
More than one engine
Several database technologies are in production across the two centres, on both clustered and standalone systems, each with the right agent.
The largest footprint
Databases account for the single biggest share of the data in scope — more than a third of the total.
Restore proven
A database server selected by the client was backed up and restored end to end at each site.
Class 04Messaging & file systemsLive systems that never stop
Enterprise messaging
Mail and application servers protected together with their detached attachment stores, without interrupting the automated agents that run on them around the clock.
Application databases
308 messaging application databases inventoried by server, path and size, then scheduled according to their own rate of change rather than as one block.
File systems
Exported file systems backed up and restored as a distinct scenario in both data centres.
Standalone servers
Physical servers outside the virtualisation platforms, across every operating-system family in the estate.
Class 05The electronic archiveIn production since 2009
What it holds
Over 150 million documents — every category of electronic filing lodged with the institution, through the public portal and through counter services — growing by roughly three million files a month.
Moved off legacy media
The archive was migrated onto the new disk platform, including the bulk of it that had been held on ageing magnetic tape and was slow to reach.
Re-pointed at disk
The archive application's storage definitions and per-document-type migration policies were reconfigured onto the new volumes, with the service left running throughout.
Verified document by document
Sample filings were located through the archive application, then on disk in the primary data centre, then on the replicated copy in the secondary.

05Services

What the work
actually involved

Our solutions →

The contract was for a working platform, not for a delivery of boxes. That meant understanding an estate nobody had documented end to end, designing around what was already there, installing into two live data centres without interrupting them, proving the result against a plan agreed in advance, and leaving the client's own team able to run it.

Design

Turning a stated requirement into an architecture that fits the estate as it actually is — including the parts of it that are older than the products being installed.

Requirements analysisInfrastructure auditSolution architectureCapacity sizingMigration planningDetailed specifications

Delivery & integration

Installation into two live national data centres, integrated with the network and storage fabrics already in place rather than alongside a second set of our own.

Physical installationConfigurationFabric integrationAgent rolloutPolicy designData migration

Proving it

Two formal test campaigns against a plan agreed before the work started, with the client choosing which systems were put through it.

Test planningComponent verificationRedundancy testingBackup & restore testingAcceptance reports

Handover

A platform the client's own specialists can operate, with the documentation and the legal title to go with it.

Knowledge transferAdministrator trainingOperating documentationLicence transferWarranty & supportProject management

06The solution

One platform,
built twice.

Everything running in the estate is reached by a single policy engine, every backup lands on three storage tiers with three different jobs, and the whole arrangement exists twice — once in each national data centre, with each site holding a copy of the other's backups.

What was built — the same platform delivered twice, once in each national data centre. In each one the protected estate (server partitions, virtual machines, standalone servers, databases, messaging and file systems) feeds into the backup platform — one policy engine for the whole estate, an agent on every protected system, disk, archive and tape from one place, restore proven rather than assumed — and from there backups land on three storage tiers: deduplicated disk for the daily recovery point, an object archive for long-term retention behind a flash cache, and a tape library for offline copies. Every backup is replicated to the second site, so each data centre also holds the other's replicated backups. Separately, the electronic archive was moved off legacy tape onto the new disk platform, re-pointed at it without interrupting the service, and replicated to the second data centre. Open full-size diagram →

07The numbers

The scale it had to hold
on the day it went live.

All projects →
2
National data centres, identically equipped
~200 km
Between the primary and secondary site
304
Systems onboarded to the platform
800+ TB
Live data inside the protection scope
150M+
Documents held in the electronic archive
3M
New filings added every month
3 years
Retention horizon the capacity was sized for
11
Archive volumes migrated and verified from both sides

Databases alone account for more than a third of the protected footprint; the electronic archive, the virtualisation estate and the file systems carry most of the rest. Every figure above was measured on the delivered platform, not estimated from a datasheet.

08The hard part

Sixteen years of filings,
moved without losing one.

The electronic archive has been accepting documents since 2009, through the institution's public portal and through the counters of county tax offices — over 150 million of them, growing by around three million a month. Most of its older content sat on magnetic tape: safe, but slow to reach and tied to media that was ageing. Moving it onto the new disk platform was the part of the programme with the least margin for error.

01
Re-point the archive, don't rebuild itThe archive application's device definitions, storage classes, storage groups and per-document-type migration policies were reconfigured onto volumes exported by the new platform — the application kept working throughout.
02
Migrate in volumes, not in one moveEleven separate volumes, each verified for occupied capacity on the storage side and again from the host running the archive, so the numbers had to agree from both directions.
03
Replicate before declaring successEvery migrated volume replicates to the second data centre. The replicated copies were mounted back onto the source host so the same documents could be read from both sites.
04
Prove it on real documentsIndividual filings were retrieved through the archive application, then located on disk in the primary data centre, then located again on the replicated copy in the secondary — three independent confirmations for the same document.

09How it was accepted

Two test campaigns,
run against a plan agreed in advance.

Campaign 01

Infrastructure verification

Every delivered component inventoried through its own management interface — capacity, connectivity and the health of controllers, power supplies and cooling modules — then tested for redundancy by disconnecting one power feed and one of each type of data path at a time, and confirming the platform stayed up.

Campaign 02

Backup and restore procedures

For each class of system, in each data centre: confirm the agent is installed, confirm the system appears as a client, confirm the disk and tape targets are registered as devices, run a backup to completion without errors, verify the data landed on both disk and tape, then run a restore to completion.

Throughout

The client chose the systems

The test plan did not name the partitions, virtual machines or databases to be tested. It specified that a relevant system be selected by the client for each scenario — so acceptance was never demonstrated on a system picked because it was convenient.

10Next step

Carrying an estate you cannot afford to lose?

Legacy platforms, several virtualisation stacks and an archive nobody wants to touch is the normal starting point, not the exception. We can assess what is genuinely recoverable today, design the protection around it, and prove the restore before you need it.

Connect with us →