Use this dialog box to add (or modify) Amazon S3, with AWS STS Assume Role with IAM Role Policy authentication, as a storage target.
Note
Refer to Amazon S3 documentation for additional information on the inputs required in this dialog box.
Before You Begin
Configure the EC2 IAM role details before configuring the storage library. For more information, see Configuring EC2 IAM Role Details for STS Assume IAM Role.
Configurable Options
Option |
Description |
Additional Information |
---|---|---|
Type |
Select Amazon S3 from the list. |
|
Name |
The name of the cloud library. |
|
MediaAgent |
The name of the MediaAgent to which the device is attached. Select a MediaAgent from the list to add to the cloud storage device. The list contains the names of all the MediaAgents configured in the CommCell. |
For AWS IAM Role Policy the selected MediaAgent must reside in the EC2 instance and an IAM Role must be associated with the EC2 instance. Make sure to select the specific MediaAgent from the drop-down list during library configuration. (For more information about installing the MediaAgent on the EC2 instance, see MediaAgent Installations.) |
Storage Class |
The following Amazon S3 storage classes are supported for Commvault Cloud Storage libraries:
|
Reference https://aws.amazon.com/s3/storage-classes/ for more information. |
Region |
Select the region for the cloud storage from the drop down list. |
|
Service Host |
A valid endpoint name for the Amazon S3 region provided by the agency. (Commvault transfers data using HTTPS protocol to the service host.) Default: |
|
Authentication |
Select AWS STS Assume Role with IAM Role Policy. |
For more information on this role, refer to the following links: |
Credentials |
Add the credentials and other details required to access the cloud storage space. |
Credentials must not contain blank spaces or other special characters. For instructions about creating a credential, see Adding a Credential to Credential Vault. |
Credential name |
Enter a name for the credential. |
|
Role ARN |
Name of the ARN role. |
|
External ID |
Enter the external ID used in the trust relationship. |
For more information, see How to use an external ID when granting access to your AWS resources to a third party. |
Bucket |
Click the Detect button to detect an existing bucket. |
Sometimes, existing bucket list may not get populated while detecting the buckets, as some vendors may not support this operation, or if there are no permissions to complete the operation. In such cases, type the name of the existing bucket that you want to use. The system will automatically use the existing bucket if it is available. |
The following permissions must be enabled for the bucket: |
Sample json file with these permissions. |
|
|
|
|
Use Combined Tier |
Enable the option to use a combine storage tier, with S3 Glacier Instant Retrieval, S3 Glacier Flexible Retrieval, or S3 Glacier Deep Archive Storage Classes. |
This option will be enabled when S3 Glacier Instant Retrieval, S3 Glacier Flexible Retrieval, or S3 Glacier Deep Archive Storage Class is selected. |
Combined Storage Class |
The following combined Storage options are available for the Glacier Flexible and Glacier Deep Archive storage classes:
|