Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
KNOWLEDGE BASE ARTICLEVEEAMVERIFIED

PUBLISHER UPDATE · KB4910

KB4910 release notes and known issues

Applications Restored by Veeam Kasten Disaster Recovery Fail to Export with: invalid repository password

Scope: Veeam products. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Applications Restored by Veeam Kasten Disaster Recovery Fail to Export with: invalid repository password KB ID: 4910 Product: Veeam Kasten for Kubernetes Published: 2026-09-04 Last Modified: 2026-09-04 Challenge After a Veeam Kasten Disaster Recovery (KDR) restore is performed on an instance of Veeam Kasten for Kubernetes running a version earlier than 8.5.4, and that instance is later upgraded to version 8.5.4 or newer, export and backup actions for the restored applications fail with an error similar to the following: invalid repository password The restore points imported by the KDR restore are present in the catalog, but any policy or export action that references them afterward fails. Cause This issue occurs because Veeam Kasten for Kubernetes versions earlier than 8.5.4 import application restore points into the local catalog without correctly linking the encryption key artifact (EKA) to the corresponding repository artifact. The catalog entry appears complete, but the repository password derived from it does not match, so any later operation that requires decrypting or reconnecting to that repository fails. The binding behavior was corrected in version 8.5.4. That correction applies to restore points imported after the upgrade, so restore points that were already imported under the earlier binding remain broken in the catalog. Solution Starting in Veeam Kasten for Kubernetes 9.0.5, the KastenDRRestore resource supports the forceReimportAppRestorePoints option. When this option is set to true , every application restore point being imported is reprocessed and its repository artifact is rebound to a valid encryption key, including restore points that were already imported successfully by an earlier KDR restore. The repair is applied by running a new KDR restore with this option enabled. The option is a field on the KastenDRRestore resource, so the repair restore is performed using the CLI or API method, regardless of how the original KDR restore was performed. Confirm that the Veeam Kasten for Kubernetes instance is running version 9.0.5 or later. Edit or create the KastenDRRestore resource for the affected restore, and set forceReimportAppRestorePoints to true : apiVersion: dr.kio.kasten.io/v1alpha1 kind: KastenDRRestore metadata: name: sample-kdrrestore namespace: kasten-io spec: sourceClusterInfo: profileName: my-profile sourceClusterID: <cluster-id> forceReimportAppRestorePoints: true Copy Alternatively, reference a restore point from an existing KastenDRReview resource: apiVersion: dr.kio.kasten.io/v1alpha1 kind: KastenDRRestore metadata: name: sample-kdrrestore namespace: kasten-io spec: kastenDRReviewDetails: kastenDRReviewRef: name: <KastenDRReview Name> namespace: kasten-io id: <KDR Restore Point ID from KastenDRReview RestorePointList> forceReimportAppRestorePoints: true Copy Run the KDR restore as described in Recovering Veeam Kasten from a Disaster via CLI . Once the restore has completed, verify that the export or backup action that previously failed for the affected application now succeeds. More Information Note: Do not enable forceReimportAppRestorePoints for a KDR restore performed on a clean installation, or for the first KDR restore performed on a cluster. In those cases no existing bindings are present to repair, so the option is unnecessary. Veeam Kasten Documentation > Operating Veeam Kasten > Veeam Kasten Disaster Recovery Veeam Kasten Documentation > API > KastenDR Resources If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Improvements and security content

  • Applications Restored by Veeam Kasten Disaster Recovery Fail to Export with: invalid repository password KB ID: 4910 Product: Veeam Kasten for Kubernetes Published: 2026-09-04 Last Modified: 2026-09-04 Challenge After a Veeam Kasten Disaster Recovery (KDR) restore is performed on an instance of Veeam Kasten for Kubernetes running a version earlier than 8.5.4, and that instance is later upgraded to version 8.5.4 or newer, export and backup actions for the restored applications fail with an error similar to the following: invalid repository password The restore points imported by the KDR restore are present in the catalog, but any policy or export action that references them afterward fails. Cause This issue occurs because Veeam Kasten for Kubernetes versions earlier than 8.5.4 import application restore points into the local catalog without correctly linking the encryption key artifact (EKA) to the corresponding repository artifact. The catalog entry appears complete, but the repository password derived from it does not match, so any later operation that requires decrypting or reconnecting to that repository fails. The binding behavior was corrected in version 8.5.4. That correction applies to restore points imported after the upgrade, so restore points that were already imported under the earlier binding remain broken in the catalog. Solution Starting in Veeam Kasten for Kubernetes 9.0.5, the KastenDRRestore resource supports the forceReimportAppRestorePoints option. When this option is set to true , every application restore point being imported is reprocessed and its repository artifact is rebound to a valid encryption key, including restore points that were already imported successfully by an earlier KDR restore. The repair is applied by running a new KDR restore with this option enabled. The option is a field on the KastenDRRestore resource, so the repair restore is performed using the CLI or API method, regardless of how the original KDR restore was performed. Confirm that the Veeam Kasten for Kubernetes instance is running version 9.0.5 or later. Edit or create the KastenDRRestore resource for the affected restore, and set forceReimportAppRestorePoints to true : apiVersion: dr.kio.kasten.io/v1alpha1 kind: KastenDRRestore metadata: name: sample-kdrrestore namespace: kasten-io spec: sourceClusterInfo: profileName: my-profile sourceClusterID: <cluster-id> forceReimportAppRestorePoints: true Copy Alternatively, reference a restore point from an existing KastenDRReview resource: apiVersion: dr.kio.kasten.io/v1alpha1 kind: KastenDRRestore metadata: name: sample-kdrrestore namespace: kasten-io spec: kastenDRReviewDetails: kastenDRReviewRef: name: <KastenDRReview Name> namespace: kasten-io id: <KDR Restore Point ID from KastenDRReview RestorePointList> forceReimportAppRestorePoints: true Copy Run the KDR restore as described in Recovering Veeam Kasten from a Disaster via CLI . Once the restore has completed, verify that the export or backup action that previously failed for the affected application now succeeds. More Information Note: Do not enable forceReimportAppRestorePoints for a KDR restore performed on a clean installation, or for the first KDR restore performed on a cluster. In those cases no existing bindings are present to repair, so the option is unnecessary. Veeam Kasten Documentation > Operating Veeam Kasten > Veeam Kasten Disaster Recovery Veeam Kasten Documentation > API > KastenDR Resources If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Veeam products

Affected versions

  • 8.5.4
  • 9.0.5

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence

VEEAMVERIFIED

Applications Restored by Veeam Kasten Disaster Recovery Fail to Export with: invalid repository password

Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source