Portworx Backup 3.1.0 is now GA

Hello Everyone,

We are excited to announce that Portworx Backup 3.1.0 is now Generally Available!

This release expands Portworx Backup Federated mode to AWS and GCP, bringing secretless authentication to AWS S3 and Google Cloud Storage. It also adds immutable GCS backup locations, extends support for Gardener-managed Kubernetes clusters, and delivers security, monitoring, and usability improvements for backup operations at scale.

Key features

  • Federated mode for AWS S3 with IRSA: Portworx Backup now supports AWS S3 backup locations using IAM Roles for Service Accounts. EKS and Gardener AWS shoot clusters authenticate directly to S3 through IRSA, without storing cloud credentials centrally on the Portworx Backup server. This requires Portworx Enterprise 3.6.2 or later, Stork 26.4.0 or later, and Portworx Operator 26.3.0 or later.

  • Federated mode for GCS with GCP Workload Identity: GKE and Gardener GCP shoot clusters can authenticate directly to Google Cloud Storage using GCP Workload Identity Federation, without centrally stored credentials. This requires Portworx Enterprise 3.6.2 or later, Stork 26.4.0 or later, and Portworx Operator 26.3.0 or later.

  • Immutable GCS backup locations: GCS buckets with bucket-level retention policies can now be used as immutable backup locations in both Classic and Federated modes. Portworx Backup detects the retention policy during validation and applies WORM protection, with support for locked retention policies such as Bucket Lock.

  • Gardener-managed Kubernetes on AWS and GCP: Federated mode now supports Gardener shoot clusters running on AWS and GCP, including Garden Linux-based clusters. AWS clusters use IRSA and GCP clusters use Workload Identity Federation for secretless backup-location authentication.

  • Updated monitoring and security: New Grafana 11.x-compatible dashboards provide global operations, namespace/application protection, and VM/KubeVirt protection views. OpenShift telemetry components now use the nonroot-v2 SCC, reducing the security footprint of the deployment.

  • Improved administration and usability: New Helm values support custom backend-service annotations and source-IP restrictions for LoadBalancer-based UI access. The web console is private by default with ClusterIP, and backup locations in the Create Backup view are now searchable.

These are just the highlights. Portworx Backup 3.1.0 also includes fixes along with additional enhancements captured in the release notes linked below.

Documentation and Resources

On behalf of the Portworx Backup Team,
Vijay Nagarajan