Configure SecureFS immutable checkpoints

Last published : Jun 19, 2026
InfoScale offers the ability to configure secure file systems (SecureFS). SecureFS provides a recovery mechanism in case of a data corruption or deletion, and a ransomware event. The SecureFS feature helps protect your data through the use of snapshots and non-modifiable checkpoints.
The secure file system feature is enhanced to identify the underlying application (generic application, Oracle, or PostgreSQL) and then secure the file system accordingly. In earlier versions SecureFS feature was available only for general applications and for Oracle. With 9.0 release, SecureFS supports PostgreSQL databases. You can configure immutable checkpoint on a file system that is mounted on a InfoScale volume. Immutable checkpoints are supported only on VxFS. Hence all directories including the subdirectories should be VxFS mount points.
Prerequisites
  • Before you configure SecureFS immutable checkpoints, refer to the InfoScale Storage Foundation Administrator's Guide - Linux for more details about the SecureFS feature.
  • To configure immutable checkpoint for an application, ensure that you select the host and the volume on which the application is installed or configured.
  • To perform this task, your user group must be assigned the Admin role on the host or the Server perspective. The permission on the host may be explicitly assigned or inherited from a parent Organization.
To configure an immutable checkpoint
  1. In the Management Server console, go to the Server perspective and expandManage in the left pane.
  2. Expand Organization orUncategorized Hosts to locate and select the host.
  3. Expand the host and Volumes to locate the volume on which you want to configure immutable checkpoints.
  4. Right-click the volume and select File System > Configure SecureFS>Immutable Checkpoint.
    image
  5. In the Secure FS - Immutable checkpoints panel, from the Select application dropdown field, select the application, and then enter the required information.
  6. For a generic application, choose General and go to step 9.
  7. For Oracle database, choose Oracle and then specify the following information and then go to step 9:
    image
    Orahome Enter the Oracle home directory path that is set for the ORACLE_HOME environment variable. It is the path to the Oracle binaries and configuration files.
    Username Enter the Oracle user who has the privileges to start and stop the Oracle database instance.
    SID Enter the Oracle instance name that is specified for the $ORACLE_SID variable.
  8. For PostgreSQL database, choose Postgres and then specify the following information:
    image
    Username Enter the dedicated OS user name that is created when PostgreSQL is installed. This user has the privileges to start, stop, and monitor the PostgreSQL database server operations.
    Data directory Enter the absolute path of the directory that contains the database that the PostgreSQL instance manages.
    Archive location Enter the archive location that is configured to store the PostgreSQL Write-Ahead Log (WAL) files.
    To prevent SecureFS failures, this location must be on a different VxFS file system than where the PostgreSQL instance is deployed.
    Authentication method Choose the authentication method from the dropdown list.
    The following options are available:
    - Trust This method assumes that any user who can connect to the PostgreSQL server is authorized to access the database with whatever database user name they specify.
    - Peer This method relies on the operating system user to connect to the PostgreSQL database.
    System user Enter the operating system user that can connect to the PostgreSQL database.
    Specify this parameter only if the Authentication method is selected as Peer.
  9. Specify the following details for the checkpoint creation:
    Mode Specifies the mode of the file system. While configuring SecureFS on an existing file system, the mode cannot be switched to compliance mode (Compliance mode refers to soft WORM) if the file system has WORM enabled.
    On the other hand, if WORM (WORM refers to Enterprise mode) is not enabled, the configuration process automatically converts the file system to Enterprise mode.
    Compliance mode is a default mode. You can change the mode later if required.
    Audit log Specifies the logging of certain events to the persistent storage. You can choose to enable or disable it.
    By default, it is enabled. Once enabled it cannot be disabled.
    Interval Specify the time interval frequency at which the SecureFS checkpoint creation must trigger. You can specify the time duration in Hours, Days, and Weeks.
    The minimum supported time duration is one hour, which means that the checkpoint creation gets triggered every hour.
    Total checkpoints Enter the maximum number of checkpoints to create and store.
    Retention Specify the time duration for which you want to retain the checkpoint. You can specify the retention time duration in hours, days, and weeks.
    The minimum recommended retention period is one hour.
  10. Click Finish to trigger the SecureFS checkpoints creation process.
  11. The Secure FS - Result pane displays the progress of the operation and the commands that InfoScale Operations Manager uses to configure the checkpoints. After the process completes successfully, click OK.
Depending on the checkpoint interval configuration, InfoScale Operations Manager runs the commands to create the SecureFS checkpoints. Once the retention period is reached, the oldest checkpoint is automatically deleted and a new checkpoint is created. The process repeats for the defined time interval.