Infrastructure Setup

Configure S3 infrastructure to enable Unified Data Vault for tenants. MSP administrators perform this setup.

MSP Setup Workflow

Step 1: Configure Storage Infrastructure

  1. Create or use a Storage Resource Pool for the region and assign MediaAgents to a group. See Adding Storage Resource Pool.

  2. Select storage: Choose AGP Storage or Bundled Storage.

  3. Deploy MediaAgents (if needed): Installing a MediaAgent

Note

For AGP, these MediaAgents serve as DDB and Index MediaAgents. For Unified Data Vault, they serve as backend S3 endpoints (configured in next step).

Step 2: Deploy S3 Service Nodes

  1. Select Linux MediaAgents from the Storage Resource Pool (all or subset) and use the existing Client Group or create a new one for S3 Service MediaAgents.

  2. Install CVS3Service package on selected Linux MediaAgents. See Create an S3 Endpoint.

Step 3: Configure Reverse Proxy

  1. Identify Network Gateway (NWP) for the region.

  2. Create Client Group named "S3 Reverse Proxy" for the NWP.

  3. Configure S3 topology between:

    • S3 Service MediaAgents (Client Group from Step 2)

    • Reverse Proxy Client Group

    See Reverse Proxy and Load Balancing.

Step 4: Publish the Public S3 Endpoint

  1. Get public third-party certificates for the S3 endpoint. Procure a third-party CA certified TLS certificate with multiple SANs to support host-style and path-style addressing. See Enable HTTPS for S3 Endpoint.

    The certificate must:

    • Come from a publicly trusted Certificate Authority with complete CA certificate chain.

    • Include SANs for both addressing styles. For example, for reverse proxy reverse-proxy.company.com:

      • *.reverse-proxy.company.com (host-style)

      • *.company.com or reverse-proxy.company.com (path-style)

  2. Import certificates into the reverse proxy or load balancer.

    • Import the server certificate, private key, and complete CA chain, and confirm that the chain is valid and trusted by clients that connect to the S3 endpoint.
  3. Create DNS aliases to support host-style endpoint addressing.

    • Create a wildcard DNS alias for the reverse proxy. For example, *.reverse-proxy.company.com should resolve to reverse-proxy.company.com.

Public endpoint is listed as S3 endpoint under UDV client.

×

Loading...