After you create AWS Service Catalog products for accounts, you can use those products to create a Commvault shared services account and Commvault member accounts in AWS Control Tower Account Factory.
Important
You must create the Commvault shared services account first, as documented below. Then, you create the Commvault member account.
Go to Account Factory in AWS Control Tower
-
Sign in to an AWS account that meets the following policy and permission requirements:
-
The AWSServiceCatalogEndUserFullAccess policy must be enabled.
-
The account must have the following permissions:
-
CreateAccount
-
DescribeCreateAccountStatus
This set of permissions is part of the Admin role and is given automatically when you assume the Admin role. If permissions to provision accounts are delegated in your AWS environment, this set of permissions might need to be added directly to your AWS user account.
-
-
-
Go to AWS Control Tower.
-
In the navigation pane, go to Account factory.
The Account factory page appears.
Create the Commvault Shared Services Account
-
Click Create account.
The Create account page appears.
-
In the Account details section, enter the account email and display name.
-
In the Access configuration section, enter the IAM Identity Center email and user name.
-
In the Organizational unit section, select the Infrastructure OU.
-
Expand the Account factory customization section.
-
For Account that contains your AWS Service Catalog products, enter the ID of the blueprint hub account that contains your AWS Service Catalog products, and then click Validate.
For more information about blueprint hub accounts, see Customize accounts with Account Factory Customization (AFC).
-
For Select a product, select the Commvault shared services account product.
-
If the blueprint contains parameters, you can specify values for the parameters.
-
For Deployment Regions, select the Regions to deploy the Commvault shared services account to, either Home Region or All governed Regions.
Global resources such as Route 53 or IAM might need to be deployed to a single Region only. Regional resources, such as Amazon EC2 instances or Amazon S3 buckets, can be deployed to all governed Regions.
-
Select Create account.
The Account factory page appears, with a message stating that AWS Control Tower is provisioning your account.
Create a Commvault Member Account
-
Click Create account.
The Create account page appears.
-
In the Account details section, enter the account email and display name.
-
In the Access configuration section, enter the IAM Identity Center email and user name.
-
In the Organizational unit section, select the Workloads OU.
-
Expand the Account factory customization section.
-
For Account that contains your AWS Service Catalog products, enter the ID of the blueprint hub account that contains your AWS Service Catalog products, and then click Validate.
For more information about blueprint hub accounts, see Customize accounts with Account Factory Customization (AFC).
-
For Select a product, select the Commvault member account product.
-
For Product version, select the version of the Commvault member account product to use.
-
Expand Blueprint parameters.
-
For CommvaultSharedServicesAccountID, enter the ID of the Commvault shared services account.
-
For Deployment Regions, select the Regions to deploy the Commvault shared services account to, either Home Region or All governed Regions.
Global resources such as Route 53 or IAM might need to be deployed to a single Region only. Regional resources, such as Amazon EC2 instances or Amazon S3 buckets, can be deployed to all governed Regions.
-
Select Create account.
The Account factory page appears, with a message stating that AWS Control Tower is provisioning your account.