Rubrik Deployment Hardware and Software Options Study Guide

Core Terminology and Definitions

  • CDM (Cloud Data Management): This refers to the core software powering the Rubrik environment. While it was initially titled Converged Data Management, the name was transitioned to "Cloud" for marketing purposes.
  • Brick: This is defined as a single Rubrik physical appliance. It comprises the rackable chassis and all internal hardware components.
  • Node: This is the individual unit of compute within a brick. A single brick contains multiple nodes that collaborate to form a Rubrik cluster.
  • FRU (Field Replaceable Unit) / CRU (Customer Replaceable Unit): These terms describe hardware components that can be exchanged or replaced on-site (in the field) rather than requiring the entire appliance to be sent back to the manufacturer.
  • TPM (Trusted Platform Module): A tamper-resistant cryptographic chip integrated into the motherboard. It handles secure tasks such as generating cryptographic keys and protecting sensitive data, including passwords and keys.

Hardware Naming Conventions

Rubrik employs a unified numbering system to identify appliance specifications. Using the example R7408, the breakdown is as follows:

  • Leading Letter: Signifies the appliance type.
    • R: Rubrik (standard).
    • F: Flash-based appliance.
  • First Digit(s): Indicates the Product Family (e.g., 70007000 or 1000010000 series).
  • Middle Digit: Indicates the number of nodes currently installed in the chassis.
    • In an R7408, the "44" means all four available slots are filled with nodes.
    • All R7000 models are equipped with 44 nodes.
  • Last Two Digits: Represents the capacity of the hard disk drives (HDDHDD) in Terabytes (TBTB).
    • In an R7408, the "0808" indicates that the nodes use 8 TB8\,TB hard disks.

Secure Foundational Standards (FIPS)

  • FIPS 140-3: All current Rubrik models include software-based encryption compliant with this standard. This is an upgrade from the previous FIPS 140-2 standard.
  • Requirements: It establishes specific security requirements for cryptographic modules, mandating robust encryption and data protection.
  • Mandates: This standard is required for government agencies and highly regulated industries.
  • Enhancements: It incorporates additional testing and implementation requirements to ensure higher security assurance.

R7000 Series: Flagship Hardware Specification

The R7000 series is the current flagship platform for disk-based Rubrik deployments.

  • Chassis: Build on a 2U2U form factor rackable chassis.
  • Nodes: Each chassis contains 44 individual nodes. Nodes are essentially commodity Intel-based computers in a 1U1U form factor.
  • Node Internal Storage Components:
    • 2×M.2 SSD2 \times M.2\,SSD: Used for the operating system, metadata, and caching. These are non-FRU components.
    • 3×HDD3 \times HDD: Used for bulk storage capacity. These are FRU components.
  • Brick-Level Total Storage:
    • 4 nodes×2 SSDs=8 SSDs per brick4\text{ nodes} \times 2\text{ SSDs} = 8\text{ SSDs per brick}.
    • 4 nodes×3 HDDs=12 HDDs per brick4\text{ nodes} \times 3\text{ HDDs} = 12\text{ HDDs per brick}.
  • External Views and Maintenance:
    • Front View: Access to nodes and disks is gained after removing the bezel. This is where users power nodes on/off or activate the UID (Unit Identification) light for service location.
    • Rear View: Contains the SFP+SFP+ networking ports.
    • Internal View: Contains the CPU, Network Interface Card (NIC), and TPM chip.
  • Disk Identification Warning: Within the R series, disk identification indexes can change after a node reboot. To reliably identify a failed disk, the command support find bad disk from the Rubrik CDM CLI guide must be used.

R7000 Networking and Connectivity

Each node in an R7000 brick features a hot-swappable quad-port NIC, available as either SFP+SFP+ or 10 Gb Base-T10\,Gb\text{ Base-T}.

  • Bonding Configuration: Ports operate in Linux Mode 11 (Active/Backup).
    • Bond 0 (Data Network): Utilizes ports 44 and 33. Connecting at least one port on Bond 0 is mandatory for the node to function.
    • Bond 1 (Management Network): Utilizes ports 22 and 11. This is an optional network configuration.
  • IPMI (Out-of-band Management):
    • Port 5: Dedicated IPMI port.
    • Requirement: Configuration of IPMI is mandatory during the initial bootstrap process.
    • Alternative: If Port 55 is not physically cabled, users can utilize Port 11 (eth0) for IPMI via the RISC (Rubrik Internal System Controller).
  • Network Flexibility: SFP+SFP+ models also support 10 Gb Base-T10\,Gb\text{ Base-T} for operation in mixed network environments.

R6000 Series: Previous Generation Hardware

The R6000 is still widely used and follows a similar naming logic with extra suffixes for encryption type.

  • Naming Example (R6408F):
    • R: Rubrik.
    • 6000: Product Family.
    • 4: Nodes sold/installed.
    • 08: 8 TB8\,TB disk capacity.
    • Trailing Letters (Encryption):
      • S: Software encrypted.
      • SE: Software encrypted enhanced (comes with a larger SSDSSD).
      • F: FIPS compliant (Utilizes hardware-encrypted SSDsSSDs and HDDsHDDs).
  • Node Internal Storage Components:
    • 1×M.2 SSD1 \times M.2\,SSD: For the OS (Non-FRU).
    • 1×2.5-inch SSD1 \times 2.5\text{-inch } SSD: For metadata and cache (FRU).
    • 3×HDD3 \times HDD: For storage capacity (FRU).
  • Networking Nuance: The system designates the fastest available port pair as Bond 0. If all ports (Copper or SFP+SFP+) have the same speed, the physical location of the bonds may switch based on hardware auto-detection. Reconfiguring these bonds requires consultation with Rubrik Support.

Mixed Hardware and Third-Party Support

  • Intra-Cluster Mixing: R6000 and R7000 nodes can coexist within the same Rubrik cluster.
  • Encryption Parity Rule: Every node in a mixed cluster must have the same encryption status. You cannot mix encrypted and unencrypted nodes.
  • Third-Party Hardware: Rubrik CDM can run on certified servers from other vendors.
    • Categories: Standard and Dense.
    • Node Requirement: A minimum of 44 nodes is required for a third-party cluster.
    • Compatibility: R6000 appliances can be mixed with all "Standard" category third-party hardware appliances.

Virtual and Cloud Deployments

Rubrik Edge

A single-node virtual appliance designed for remote and branch offices (ROBO).

  • Hypervisor Support: vSphere, Nutanix AHV, Hyper-V, and Red Hat KVM.
  • Capacity Scaling Table:
CapacityvCPUReserved MemoryMax Protected Objects
5 TB5\,TB2224 GB24\,GB4040
30 TB30\,TB161664 GB64\,GB240240
Cloud Cluster ES (Elastic Storage)

Allows CDM to run within a Virtual Private Cloud (VPCVPC).

  • Storage Model: Uses native platform object storage instead of block volumes, which reduces long-term retention costs and increases reliability.
  • Configurations: Available in "Standard" and "Dense." Mixing these configurations in one cluster is prohibited; "Dense" is preferred for stability and scale.
ROBO Nodes (Dell and HPE)

These serve as replacements for the legacy E1000 platforms.

  • Capabilities: Supports all Rubrik editions (Foundation, Business, Enterprise, Proactive) and runs full security workloads.
  • Models:
    • Dell R660 XSXL Robo: Launched May 20242024.
    • HPE DL360 Gen11: 1U1U platform with two mirrored LFF drives; launched December 20242024.

Sample Architecture: Rubrik Security Cloud (RSC)

  • Central Management: RSC acts as the "single pane of glass" for managing all environments.
  • Primary Sites: Deploy physical Rubrik clusters for direct local backups.
  • Remote Offices: Deploy Rubrik Edge virtual appliances; local backups are taken and then replicated back to the physical cluster at the primary site.
  • Archival: Data can be pushed off-site to the public cloud or another physical location for long-term retention.
  • Disaster Recovery: Facilitated via replication between clusters at different physical sites.
  • Cloud/SaaS Protection: RSC natively protects workloads in the public cloud and SaaS environments like Microsoft 365.