Adding an Amazon S3 Virtual Client with AWS STS Assume Role

To back up S3 buckets in different AWS accounts, or if you need cross AWS accounts, add the Amazon (S3) virtual client with security token service (STS) assume role.

Procedure

  1. From the CommCell Browser, right-click Client Computers, and then click New Client > Cloud Storage > Amazon S3.

    The New Amazon S3 Client dialog box appears.

  2. On the General tab, provide the following details:

    1. In the Client Name box, type a name for the new virtual client.

    2. In the Instance Name box, type a name for the instance.

    3. In the Access Node box, select the EC2 VM with Cloud Apps Package installed on the source account that can assume the role of cross account to back up the bucket.

    4. In the Storage Policy box, select a storage policy for the backup and restore operations.

    5. In the Number of Data Backup Streams box, type the number of data streams to use for backups. The maximum value is 99.

      Note: The number of streams must not exceed the maximum number configured in the subclient storage policy. The CommServe allocates streams depending on the availability of resources.

  3. On the Connection Details tab, enter the following details:

    1. In the Host URL box, type the Amazon S3 service account URL (s3.amazonaws.com).

    2. From the Authentication Type list, select AWS STS assume role with IAM role policy.

    3. Enter credentials:

      What

      Steps

      Existing credential

      From the Credential list, select the credential that you want to use.

      New credential

      1. From the Credential list, click Create New.

        The Create user credential dialog box appears.

      2. In the Credential name box, enter a name for the credentials.

      3. In the Role ARN box, enter the full IAM role Amazon resource name (ARN) of the cross account whose bucket will be backed up.

      4. Click OK.

  4. Click OK.

Results

The Commvault software creates an Amazon S3 virtual client that contains a default instance.

Loading...