SAP Business One with SAP HANA on AWS: Architecture and Day-to-Day Operations

September 29, 20269 min read
SAPSAP HANAAWSSAP Business OnePower BI

Introduction

"SAP Business One HANA AWS" joins three things the AWS console does not join for you. Business One stays the ERP. HANA stays the in-memory database. AWS is the place that pair runs, with disk, network, and backup written down.

HANA is not an RDS engine. It runs on EC2, on an instance type from the SAP certified list for the version you operate. Picking a size "because there is RAM left" is how the Power BI refresh goes back to fifteen minutes. Query tuning for that load is in the SAP HANA queries article.

This article covers what sits around it: volume, port, a read-only user, and backup. The report does not point at production HANA. It reads the replica, as in the SAP Business One with Power BI and Aurora article.


Two volumes, two jobs

HANA separates data and log. On EBS that becomes two volumes. Putting both on the same disk is the fastest way to lose the recovery point.

  • /hana/data. Columns, the persisted in-memory data. I ask for gp3 or io2, with provisioned IOPS.
  • /hana/log. Redo log. Its own volume, smaller, with high IOPS.
  • /backup. HANA FILE backup. gp3, away from the data disk.
  • Root. Operating system. The smallest disk the OS accepts.
  • aws ec2 create-volume \
      --availability-zone sa-east-1a \
      --volume-type gp3 \
      --size 500 \
      --iops 6000 \
      --throughput 250 \
      --tag-specifications 'ResourceType=volume,Tags=[{Key=Name,Value=hana-data}]'

    The log volume is created apart, with the same command and another tag. Both stay in the instance availability zone. HANA in one AZ and the disk in another is not high availability. It is latency.

    The instance is memory-optimized and has to appear on the SAP certification note for that HANA version. I do not pin a type in this text because the list changes. The check is: the SAP note names that instance type for that revision. If it does not, change the instance before installing Business One.


    Who may talk to port 30015

    The default indexserver port is 3 plus the instance number plus 15. Instance 00 listens on 30015. That port is not open to the whole VPC. Only the Business One application security group gets in.

    aws ec2 authorize-security-group-ingress \
      --group-id "$SG_HANA" \
      --protocol tcp \
      --port 30015 \
      --source-group "$SG_B1APP"

    The user the report uses is not SYSTEM. It is a read-only user, created in HANA, with a grant only on the views the replica job needs.

    CREATE USER ANALYTICS PASSWORD "$PASSWORD" NO FORCE_FIRST_PASSWORD_CHANGE;
    GRANT SELECT ON "OINV" TO ANALYTICS;
    hdbsql -n hana-prod:30015 -u ANALYTICS -p "$HANA_PASSWORD" <<'SQL'
    SELECT "CardCode", "DocEntry", "DocTotal"
    FROM "OINV"
    WHERE "DocStatus" = 'O'
    LIMIT 5;
    SQL

    If ANALYTICS can SELECT and cannot INSERT, the replica job is on the right user. Power BI should not even have that connection string. It talks to Aurora, at the endpoint the other article shows how to find.


    A backup that is not a blind snapshot

    An EBS snapshot while HANA is writing is a torn disk copy. The order is: a HANA logical backup onto the /backup volume, and only then a snapshot of that volume.

    hdbsql -n localhost:30015 -u SYSTEM -p "$HANA_PASSWORD" \
      "BACKUP DATA USING FILE ('/backup/hana/COMPLETE')"
    

    VOL_ID=$(aws ec2 describe-volumes \ --filters Name=tag:Name,Values=hana-backup \ --query "Volumes[0].VolumeId" --output text)

    aws ec2 create-snapshot \ --volume-id "$VOL_ID" \ --description "hana-complete $(date -I)"

    A real restore, once a quarter, is worth more than the written policy. Bring up a separate instance, restore the FILE backup, and open Business One read-only. If nobody does that, the backup is just a file.

    The execution plan of the queries that run on this HANA stays in the optimization article. This text does not replace that one: there it is SQL, here it is the server that holds the SQL.


    What not to do

    Do not point the Power BI gateway at production 30015. Do not put data and log on the same volume. Do not open 30015 to 0.0.0.0/0 "just for this week". Do not pick an instance off the certified list because the month's price closed better.

    Business One on AWS works when HANA has its own disk, port, and backup, and analytics live in another database. Everything else is a shortcut that shows up on the bill and in the audit at the same time.

    Related Articles