Configure Google Cloud authentication, Access Nodes, a backup plan, and a VM group to start protecting your instances.
Start the configuration wizard
- From the Command Center navigation pane, go to Protect > Virtual machines.
The Overview page appears.
- In the upper-right area of the page, click Add hypervisor.
The Configure Hypervisor page appears.
-
Click Google Cloud.
-
Click Next.
The Add Hypervisor page of the configuration wizard appears.
Configure the service account
Choose how Commvault authenticates to Google Cloud. You can use the service account attached to the Access Node or authenticate by using a service account key.
Create a service account using Google Cloud Shell
-
Choose the Create service account option.
-
For Credentials, click the create credential button.
The Add credential dialog box appears.
Create a service account using Google Cloud Shell
-
Review Vendor type.
-
For Authentication type, select the authentication type for service account key authentication.
-
For Credential vault, optionally select Built-in or the default credential vault.
-
For Credential name, enter a descriptive name for the credential.
-
For Service Account ID, click Create service account.
The Create service account window appears.
-
For Organization ID, optionally enter the organization ID to create custom roles at the organization level.
-
For Project ID, enter the Google Cloud project where you want to create the service account.
To list projects, run
gcloud projects listin Google Cloud Shell. -
For Service account name, optionally enter a display name.
-
For Service account ID, enter the identifier for the service account.
-
Click Open Cloud Shell.
The generated commands perform the following operations:
-
Set the active Google Cloud project.
-
Enable the required services in the project.
-
Create the service account.
-
Create custom roles with the required permissions for Commvault operations.
-
Grant the service account the required IAM roles.
-
Generate and download a private JSON key file for the service account.
-
-
If the service account must access multiple projects, use the generated commands to associate the service account with those projects.
-
Click Close.
-
-
For Private key file, click Upload, and select the JSON key file.
-
In Description, enter a description for the credential.
-
Click Save.
-
-
Click Next.
Download the JSON key file manually
-
In Server name, enter a descriptive name for the hypervisor.
-
For Credentials, select existing credentials or create credentials.
Download the JSON key file and configure service account authentication
-
Sign in to the Google Cloud console.
-
Create a Google Cloud service account.
For information, see Create service accounts in the Google Cloud documentation.
-
Assign one of the following roles to the service account:
-
Owner
-
Compute Instance Admin (v1) and Service Account User
-
A custom role
For permissions to assign to a custom role, see Service account permissions for Google Cloud.
If you use IntelliSnap backups, assign the same permissions to the service account on the source and destination projects.
To back up instances from multiple projects, the service account must have access to all applicable projects, including the projects where Access Nodes exist.
-
-
Verify that the Cloud Resource Manager API is enabled.
-
Record the service account ID, project ID, and JSON key file name.
-
Download the JSON key file for service account authentication.
-
-
Click Next.
Use an existing service account
Use this method when the Access Node already has a service account that you want to use directly without service account impersonation.
-
Choose the Use existing service account option.
-
Enable Use Service Account associated to the Access Node.
-
Click Next.
Edit existing credentials to create custom roles
Use this method to create custom roles with the required permissions and assign them to the selected service account.
-
Choose the Use existing service account option.
-
Disable Use Service Account associated to the Access Node.
-
For Credentials, select a saved credential, and then edit the credential.
The Edit credential dialog box appears.
Create a custom role and assign it using Google Cloud Shell
-
For Service Account ID, click Create Custom Role.
The Create custom role dialog box appears.
-
For Organization ID, optionally enter the organization ID to create custom roles at the organization level.
-
Review Project ID and Service account ID.
-
Click Open Cloud Shell.
The generated commands perform the following operations:
-
Set the active Google Cloud project.
-
Enable the required services in the project.
-
Create custom roles with the required permissions for Commvault operations.
-
Grant the service account the required IAM roles.
-
-
If the service account must access multiple projects, use the generated commands to associate the service account with those projects.
-
Click Close.
-
-
Click Next.
Add an access node
Select one or more existing Access Nodes for the hypervisor, deploy a new Access Node, or download the Access Node package and install it on a Google Cloud VM.
Deploy a new access node
- Click the create Access Node button.
The Add a new Access node dialog box appears.
- Choose Deploy a new access node.
For more information, see Deploy a new Access Node.
- Click Next.
The Add Hypervisor page appears.
Download the access node package
-
Open the Add a new Access node dialog box.
-
Choose Download the access node package.
Download the Access Node package
-
Select Linux (64-bit) or Windows (64-bit).
-
Click Download, and install the package on a Google Cloud VM that meets the requirements.
-
Copy the provided Auth code. You need the code when you install the package on the Access Node.
-
After the Access Node is registered with the CommServe computer, refresh the page and select the Access Node.
-
-
Click Next.
The Add Hypervisor page appears.
Create the hypervisor
-
For Add Hypervisor, enter a name for the hypervisor.
-
Click Next.
The Select Plan page appears.
Select a plan
-
For Plan, select an existing backup plan or create a backup plan.
-
Click Next.
The Add VM Group page appears.
Create the VM group
A VM group contains the instances that you want to protect with the same settings. By default, the VM group includes all unprotected instances. You can use discovery rules or select resources by project, region, or zone.
Important
When you select instances by region or zone, the selection can include instances from multiple projects. Use Preview to verify that the VM group contains only the instances that you want to protect. Protecting additional instances can result in unnecessary costs.
-
In Name, enter a descriptive name for the VM group.
-
To select instances by using discovery rules, do the following:
-
Click Add, and then select Rules.
The Add rule dialog box appears.
-
Select a rule type, and configure the rule:
-
Browse: Select specific instances.
-
Instance name or pattern: Select instances based on their names.
-
Label: Select instances based on their labels.
-
Project: Select instances based on their project.
-
Region: Select instances based on their region.
-
Zone: Select instances based on their zone.
-
-
-
Click Save.
-
To select instances by browsing, do the following:
-
Click Add, and then select Content.
The Add content dialog box appears.
-
From Browse and select VMs, select one of the following:
-
By project: Select instances based on their project.
-
By region: Select instances based on their region.
-
By zone: Select instances based on their zone.
-
-
Click Save.
-
To use IntelliSnap to protect the VM group, enable IntelliSnap.
-
Click Preview, and verify that the VM group contains the instances that you want to protect.
-
Click Next.
The Summary page appears.
Review the configuration
- Click Finish.