When you want Commvault service provider to manage the access nodes used for data protection operations, you must configure Google Cloud Storage backups using the Commvault hosted infrastructure.
Before You Begin
If you are an MSP and you want your tenant administrators to configure Google Cloud storage, see Managed Service Provider Configuration.
Navigate to Service Catalog
- From the Command Center navigation pane, go to Explore > Service catalog.
Choose Google Cloud Storage
-
On the Object Storage tile, click Configure.
-
Select Google Cloud, and then click Next.
The File & Object Trial message appears.
-
Click Continue.
The Service Account page appears.
Service Account
-
Select Use hosted infrastructure.
-
To create a new service account for configuring Google Cloud backups, select Create a new service account.
Steps to create a new service account
When configuring backups, you can create a Google Cloud service account using one of the following methods:
-
Automatically: Run a set of commands in the Google Cloud Shell to configure the service account.
-
Manually: Download the JSON key file and set up authentication yourself.
Alternatively, you can use an existing service account or edit credentials to create custom roles with all the required permissions.
-
Choose the Create service account option.
-
For Credentials, click the add button
to create new service account with the required permissions.The Add credential dialog box appears.
-
The Vendor type field contains the name of the vendor from the dropdown list.
-
The Authentication type field, contains the type of authentication to use.
-
For Credential vault (Optional), select Built-in or the default type for the credentials.
-
For Credential name, enter a descriptive name for the credentials.
-
For Service Account ID, click Create service account to set up a new service account with the required permissions.
The Create service account window appears.
-
Organization ID: (Optional) Define and organization id to create custom roles for backup, restore, and replication operations at the organization level in your Google Cloud environment.
-
Project ID: Specify the Google Cloud project where the service account will be created.
For a list of projects, you can copy and paste the following command in the Cloud Shell: gcloud projects list.
-
Service account name: (Optional) Enter the display name for the service account to be created.
-
Service account ID: Enter the identifier of the service account that will be created.
Note
A service account is automatically created using the specified service account ID when the commands are executed.
-
Click Open Cloud Shell, to log in and execute the following commands into Cloud Shell:
-
Set the active project to work on:
This command sets the active project to Google Cloud using the gcloud CLI.
-
Enable required services on the current project:
This command enables the necessary services for Commvault on the Google Cloud project.
-
Create a new service account:
This command creates a service account that will securely perform tasks for Commvault.
-
Create custom roles with the required permissions for different Commvault Cloud operations at project level:
This command defines and creates custom IAM roles with the required permissions for Commvault operations at the project level.
If an Organization ID is provided, the custom roles will be created at the organization level instead of the project level.
-
Grant your service account an IAM role on your project:
This command assigns the necessary IAM roles for backup, restore, and replication, to the service account, authorizing it to access and perform required operations within your project.
-
Generate a private key file for the service account and download the JSON file:
This command lets you specify a name for the private key file. The file will be automatically generated in Cloud Shell and downloaded as a JSON file. You can customize the file name during this step.
This key must be uploaded in the Add Credential window to enable its use in future operations.
-
To associate the service account with multiple projects:
To associate the service account with multiple projects, you have to run a series of commands that grant the service account access to each project in the provided list. This allows the service account to perform operations such as backup, restore, and replication on virtual machines (VMs) across those projects.
The following procedure is recommended:
-
Copy the Download project list command in the Cloud Shell.
-
Run the command to automatically download the list of projects in the required format.
-
Upload the previously downloaded text file.
-
Once the text file is uploaded, the projects will be automatically populated, and the relevant commands will be displayed in the window.
-
Copy these commands and run them in Cloud Shell to complete the association.
-
-
-
Click Close.
-
-
For Private key file, click Upload to choose the JSON key file.
-
In Description, enter a description for the credential.
-
Click Save.
-
-
To use an existing service account for configuring Google Cloud backups, select Use existing service account.
-
To edit an existing credentials to create custom roles and assign them to the selected service account, do the following:
-
Select Use existing service account.
-
For Credentials, choose a saved credential from the drop down list and click the edit button
.The Edit credential dialog box appears.
Steps to create a custom role and assign it to a service account using Google Cloud Shell
-
For Service Account ID, click Create Custom Role.
The Create custom role dialog box appears.
-
Organization ID: (Optional) Define and organization id to create custom roles for backup, restore, and replication operations at the organization level in your Google Cloud environment.
-
Project ID: Indicates the Google Cloud project which hosts the chosen service account.
-
Service account ID: Indicates the identifier of the service account selected.
-
Click Open Cloud Shell, to log in and execute the following commands into Cloud Shell:
-
Set the active project to work on:
This command sets the active project to Google Cloud using the gcloud CLI.
-
Enable required services on the current project:
This command enables the necessary services for Commvault on the Google Cloud project.
-
Create custom roles with the required permissions for different Commvault Cloud operations at project level:
This command defines and creates custom IAM roles with the required permissions for Commvault operations at the project level.
If an Organization ID is provided, the custom roles will be created at the organization level instead of the project level.
-
Grant your service account an IAM role on your project:
This command assigns the necessary IAM roles for backup, restore, and replication, to the service account, authorizing it to access and perform required operations within your project.
-
To associate the service account with multiple projects:
To associate the service account with multiple projects, you have to run a series of commands that grant the service account access to each project in the provided list. This allows the service account to perform operations such as backup, restore, and replication on virtual machines (VMs) across those projects.
The following procedure is recommended:
-
Copy the Download project list command in the Cloud Shell.
-
Run the command to automatically download the list of projects in the required format.
-
Upload the previously downloaded text file.
-
Once the text file is uploaded, the projects will be automatically populated, and the relevant commands will be displayed in the window.
-
Copy these commands and run them in Cloud Shell to complete the association.
-
-
-
Click Save.
-
-
-
Click Next.
Access Node
-
Select a region.
-
Click Next.
Plan
You can add a backup plan to specify the cloud storage, data retention, and backup frequency for Google Cloud Storage backups.
-
Select an existing backup plan or create a new backup plan.
Steps to create a plan
-
Click +.
The Create backup plan dialog box appears.
-
In the Plan name box, enter a name for the backup plan.
-
From the Storage list, select an existing cloud storage or create a new cloud storage.
Steps to create a new cloud storage
-
Click the add button
.The Add cloud storage dialog box appears.
-
From the Type list, select Air Gap Protect, Cloud, or Disk.
-
If you select Air Gap Protect, do the following:
a. From the Cloud storage provider list, select the provider.
b. From the Region list, select the storage region.
c. From the MediaAgent list, select the MediaAgent for object storage. By default, Automatic is selected.
d. To enable deduplication on the storage, slide the Use deduplication toggle key to the right.
e. From the DDB MediaAgent list, select the MediaAgent for the deduplication database. By default, Automatic is selected.
-
If you select Cloud, do the following:
For example, if you select Google Cloud Storage as the storage type, complete the following steps:
a. From the Type list, select the cloud storage type (for example, Google Cloud Storage).
b. In the Name box, enter a name for the cloud storage.
c. From the Storage class list, select the storage class for the type of access that you want to have for the data (for example, Standard, Nearline, Coldline, or Archive).
d. In the Service host box, enter the endpoint URL or host name for the Google Cloud Storage service (for example, storage.googleapis.com or region-specific endpoint).
e. From the MediaAgent list, select an existing MediaAgent or create a new MediaAgent for backups.
f. From the Credentials list, select existing credentials or create new credentials for the Google Cloud Storage account.
To create new credentials, click the add button (+) and provide the following information:
The way that you add credentials depends on the authentication method:
For access and secret keys:
1. From the Credential Vault list, select the credential vault (for example, Built-In).
2. In the Credential name box, enter a descriptive name for the credentials.
3. In the Access key ID box, enter the access key ID (interoperability key) for the Google Cloud Storage account.
4. In the Secret access key box, enter the secret access key for the Google Cloud Storage account.
5. Optional: In the Description box, enter a description for the credentials.
6. Click Save.
For service account:
1. From the Credential Vault list, select the credential vault (for example, Built-In).
2. In the Credential name box, enter a descriptive name for the credentials.
3. Upload or specify the service account JSON key file.
4. Optional: In the Description box, enter a description for the credentials.
5. Click Save.
g. In the Bucket box, enter the bucket name or click Detect to automatically discover available buckets.
h. To enable deduplication on the storage, slide the Use deduplication toggle key to the right.
i. From the DDB MediaAgent list, select an existing MediaAgent or create a new MediaAgent for the deduplication database.
j. Click Save.
-
If you select Disk, do the following:
a. In the Name box, type the name of the storage.
b. For Backup location, click Add to add a backup location.
-
From the MediaAgent list, select an existing MediaAgent or create a new MediaAgent for backups.
-
To set the disk access path, use either of the following options:
-
To use a local disk as the disk access path, click Local and in the Backup location box, type the full path name to the storage location.
-
To use a network drive as the disk access path, click Network and provide the following information:
-
From under the Credential section, from the Name list, select the credential that you want to use to access the network drive.
Alternatively, you can click the + sign to create new credentials to access a network drive.
-
In the Backup location box, type the full path name to the storage location.
-
-
c. To enable deduplication on the storage, slide the Use deduplication toggle key to the right.
d. From the DDB MediaAgent list, select an existing MediaAgent or create a new MediaAgent for the deduplication database.
-
-
-
Click Save.
-
-
In the Configure backups section, configure the backup schedule and retention settings:
a. Under Primary copy with schedule and retention settings, specify how frequently you would like the backup to be performed:
-
In the Frequency box, enter the backup frequency value and select the time period (Day(s), Week(s), Month(s)).
-
In the Retention period box, enter the retention value and select the time period (Day(s), Week(s), Month(s), Year(s)).
b. Optional: Select Add extended retention to configure extended retention rules.
c. Optional: Select Add second copy to add a secondary backup copy.
-
-
Click Done.
-
-
Click Next.
Cloud Account
-
From the Cloud account list, select a cloud account.
-
In Object storage instance name, enter a descriptive name for the object storage instance.
-
In Host URL, enter the Google Cloud Storage endpoint URL.
For example, storage.googleapis.com.
-
In Project ID, enter the Google project ID.
-
Click Next.
Backup Content
-
Select the backup content you want to protect, such as containers and objects.
-
Click Add, and do one of the following:
-
To enter a custom path, click Custom path, and then enter the path for the content.
-
To browse for content, click Browse, and then select the content.
-
-
To exclude some of the content you selected, move the Specify exclusion toggle key to the right, and then add the exclusion.
-
To back up ACLs, move the Backup ACL toggle key to the right.
-
Summary
- Review your selections, and then click Finish to complete the configuration.