Does Druva support RDS Airgap backups using AWS Managed Keys (AMK)?
Does Druva support RDS Airgap backups using AWS Managed Keys (AMK)?
Druva supports RDS Airgap backup only with Customer Managed Keys (CMK).
Orchestration of RDS backups are supported using both CMK and AMK only within the same AWS Region or Account.
However, if your backup strategy requires cross-account or cross-region snapshots, you must use Customer Managed Keys.
Why does RDS Airgap backup fail with AMK even in the same region?
Why does RDS Airgap backup fail with AMK even in the same region?
When Airgap backup is enabled, Druva manages the backups within a different AWS account. AWS does not support cross-account backups for RDS instances encrypted with AMK, even if the backups reside within the same region.
This is a limitation enforced by AWS. For more information, refer to AWS documentation.
What is the recommended solution for using RDS Airgap with encryption?
What is the recommended solution for using RDS Airgap with encryption?
To enable RDS Airgap backups successfully we recommend using Customer Managed Keys (CMK), instead of AWS Managed Keys. CMK allows cross-account encryption support and is fully compatible with Druva's RDS Airgap functionality.
