You can share snapshots of Amazon EC2 instances to a different Amazon account by copying the snapshot to the target geographic region, and then by sharing the copied snapshot cross account. Tags attached to the source snapshot are not copied to the destination account or to a regional snapshot copy.
To copy the snapshots, you must map the source region to the target region.
Support
-
Replication of a snapshot from a region to the same or a different region.
-
Source account can be configured with an access key and secret key, an IAM role, or an STS role ARN. Destination account must be configured with an access key and secret key, or an STS role ARN.
-
Share a snapshot to a different account. If you are sharing encrypted snapshots, the KMS key must be shared with the destination account.
-
Sharing encrypted EC2 instance snapshot that uses the KMS key encryption is supported by using an account that has an access key and secret key, or an STS role ARN based IAM role.
Before You Begin
To replicate a copy of encrypted EC2 snapshots, the user can either have a key with alias cvlt-ec2 or cvlt-master at the destination region. If the user is using the key with a different alias, then the user must create a tag for the KMS key with the tag name cvlt-ec2 or cvlt-master at the destination region
-
Verify that the destination account user has the following permissions:
-
kms:CreateGrant
-
kms:Encrypt
-
kms:Decrypt
-
kms:ReEncrypt*
-
kms:GenerateDataKey*
-
kms:DescribeKey
-
-
Configure encryption key sharing in the AWS console:
-
Log in to the AWS Console as a user associated with the access key and secret key that is configured for the Amazon client from which you will be sharing the snapshot.
-
From the AWS Console ribbon, clickServices.
-
ClickKey Management Service.
-
Select the required destination account.
-
Under Key users, select the key tagged with
cvlt-ec2orcvlt-master. -
Under Other AWS accounts, click Add Other AWS Account.
-
The Other AWS accounts page appears.
-
In the arn:aws:iam:: box, enter the account number of the destination account to which you will be sharing the snapshot.
-
Click Save changes.
-
Procedure
-
From the CommCell Browser, go to Client Computers > client > Virtual Server > Amazon, and then click the instance.
-
Right-click the subclient, and then select Properties.
The Subclient Properties dialog box appears.
-
On the IntelliSnap Operations tab, select the snapshot sharing options:
-
Select the IntelliSnap check box.
-
From the Secondary Snap Copy list, select a secondary snapshot copy.
-
Under Region Map, from the Source Region and Destination Region lists, select the source and target regions.
You can map only one destination region to each configured source region per subclient.
-
Click Add Region to save the region mapping in the database.
-
To share to a different Amazon account, complete the following steps:
-
Select the Enable Cross Account Operations check box.
-
Click Share Only.
-
From the Destination Client list, select the destination client for the account.
-
-
Click OK.
-