Veeam TriggerInstantVmRestore

Veeam TriggerInstantVmRestore

Certified
Enterprise Edition

Trigger a Veeam instant VM recovery

Starts a vSphere instant VM recovery from a restore point and returns the id of the session created for it. This targets the vSphere-specific endpoint only; Hyper-V and Azure instant recovery use separate VBR REST API endpoints that are not covered by this task. Use sessions.Get with waitForCompletion: true to wait for the recovery to finish. additionalOptions is merged into the request body as-is for restore parameters not directly exposed (target host, datastore, network mapping, and similar), since these vary by VBR version and infrastructure.

yaml
type: io.kestra.plugin.ee.veeam.restores.TriggerInstantVmRestore

Instantly recover a VM from its latest restore point.

yaml
id: instant_vm_recovery
namespace: company.team

tasks:
  - id: recover_vm
    type: io.kestra.plugin.ee.veeam.restores.TriggerInstantVmRestore
    host: "{{ secret('VEEAM_HOST') }}"
    username: "{{ secret('VEEAM_USERNAME') }}"
    password: "{{ secret('VEEAM_PASSWORD') }}"
    restorePointId: "9a1b2c3d-4e5f-6789-a1b2-c3d4e5f6a7b8"
    reason: "Disaster recovery drill"
    powerUp: false
Properties

Veeam Backup & Replication server host

Hostname or IP address of the Veeam Backup & Replication server exposing the REST API.

Password

Password for username. Treat it as a secret, e.g. {{ secret('VEEAM_PASSWORD') }}.

Restore point id

Username

Veeam Backup & Replication account used for the OAuth 2.0 password grant.

Additional restore options

Extra fields merged into the request body, for advanced or version-specific restore parameters.

Default1.3-rev1

API version

Value sent as the mandatory x-api-version header on every request, including authentication. Must match a version supported by the target server; a missing or unsupported value causes VBR to reject the request with HTTP 400. Defaults to 1.3-rev1 (VBR 12.1 and later).

HTTP client configuration

Optional HTTP client overrides (timeouts, proxy, TLS). Veeam Backup & Replication servers ship a self-signed certificate by default: set options.ssl.insecureTrustAllCertificates: true, or provide a trust store, otherwise the first request fails with a TLS handshake error rather than a clear authentication error.

Definitions
allowFailedbooleanstring
Defaultfalse

If true, allow a failed response code (response code >= 400)

allowedResponseCodesarray
SubTypeinteger

List of response code allowed for this request

auth

The authentication to use.

type*Requiredobject
passwordstring

The password for HTTP basic authentication.

usernamestring

The username for HTTP basic authentication.

type*Requiredobject
tokenstring

The token for bearer token authentication.

type*Requiredobject
passwordstring

The password for HTTP Digest authentication.

usernamestring

The username for HTTP Digest authentication.

basicAuthPasswordDeprecatedstring

The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.

basicAuthUserDeprecatedstring

The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.

connectTimeoutDeprecatedstring
Formatduration

The time allowed to establish a connection to the server before failing.

connectionPoolIdleTimeoutDeprecatedstring
Formatduration

The time an idle connection can remain in the client's connection pool before being closed.

defaultCharsetstring
DefaultUTF-8

The default charset for the request.

enabledTcpExtendedKeepAlivebooleanstring
Defaulttrue

Whether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).

Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.

followRedirectsbooleanstring
Defaulttrue

Whether redirects should be followed automatically.

logLevelDeprecatedstring
Possible Values
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIED

The log level for the HTTP client.

logsarray
SubTypestring
Possible Values
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODY

The enabled log.

maxContentLengthDeprecatedinteger

The maximum content length of the response.

proxy

The proxy configuration.

addressstring

The address of the proxy server.

passwordstring

The password for proxy authentication.

portintegerstring

The port of the proxy server.

typestring
DefaultDIRECT
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

usernamestring

The username for proxy authentication.

proxyAddressDeprecatedstring

The address of the proxy server.

proxyPasswordDeprecatedstring

The password for proxy authentication.

proxyPortDeprecatedinteger

The port of the proxy server.

proxyTypeDeprecatedstring
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

proxyUsernameDeprecatedstring

The username for proxy authentication.

readIdleTimeoutDeprecatedstring
Formatduration

The time allowed for a read connection to remain idle before closing it.

readTimeoutDeprecatedstring
Formatduration

The maximum time allowed for reading data from the server before failing.

ssl

The SSL request options

insecureTrustAllCertificatesbooleanstring

Whether to disable checking of the remote SSL certificate.

Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.

timeout

The timeout configuration.

connectTimeoutstring

The time allowed to establish a connection to the server before failing.

readIdleTimeoutstring
DefaultPT5M

The time allowed for a read connection to remain idle before closing it.

Reference (ref) of the pluginDefaults to apply to this task.

Default9419

REST API port

TCP port of the Veeam Backup & Replication REST API. Defaults to 9419.

Defaulttrue

Power up

Whether to power on the recovered VM once mounted. Defaults to true.

Reason

Optional free-text reason recorded on the restore session.

DefaultOriginalLocation
Possible Values
OriginalLocationCustomized

Recovery mode

Where the recovered VM is registered: OriginalLocation (default) or Customized (a custom host/datastore, provided via additionalOptions).

Defaultfalse

Secure restore antivirus scan

Whether to scan the restored VM's disks for malware before making it available. Defaults to false.

Id of the session created for this restore