To protect Google RDS for Oracle resources, Commvault requires a Google Cloud service account with the appropriate Identity and Access Management (IAM) permissions. The service account must have access to Google RDS for Oracle, Cloud Storage, and Compute Engine resources, and the Dataflow API must be enabled.
Important
If Dataflow worker VMs use only internal IP addresses, enable Private Google Access on the subnet used to run Cloud Spanner import or export backup jobs.
The required IAM permissions vary depending on whether the service account is used for backup or restore operations.
-
Backup permissions: Lists the IAM permissions required to back up Google RDS for Oracle resources.
-
Restore permissions: Lists the IAM permissions required to restore Google RDS for Oracle resources.
For information about creating and assigning custom IAM roles in Google Cloud, see the Google Cloud IAM documentation.