Druva CloudRanger requires an Identity Access Management (IAM) role to access and manage your AWS workloads. To configure your Druva CloudRanger account, you will need to grant CloudRanger third-party access to your AWS account.
To create an IAM role, Druva CloudRanger provides a CloudFormation template that provisions the CloudFormation stack within your AWS environment. This then generates the following IAM permissions for Druva CloudRanger to access your AWS Account:
IAM Role
IAM Instance Profile
IAM Policy
The generated Amazon Resource Name (ARN) of the IAM role is then linked back to CloudRanger so that it can run backup and restore jobs on your AWS workloads.
Roles and Permissions
The following table provides detailed information about the permissions allowed for various roles:
Category | Permission Name | Permission Description |
Resource-specific permissions |
|
|
EC2 Backup permissions |
| Permissions required to backup EC2 instances. |
EC2 Restore permissions |
| Permissions required to restore EC2 instances. |
EC2 Core permissions |
| Permissions required to manage core EC2 components as well as the resource on/off schedules. |
RDS Backup permissions |
| Permissions required to backup RDS databases. |
RDS Restore permissions |
| Permissions required to restore RDS databases. |
RDS Core permissions |
| Permissions required to manage core RDS components. |
Redshift Backup permissions |
| Permissions required to backup Redshift resources. |
Redshift Restore permissions |
| Permissions required to restore Redshift resources. |
DynamoDB Backup permissions |
| Permissions required to backup DynamoDB tables. |
DynamoDB Restore permissions |
| Permissions required to restore DynamoDB tables. |
Resource Scheduling permissions |
| Permissions required as part of the resource on/off schedules. |
CloudFormation stack-level permissions | CloudFormation:createstack cloudformation:describestacks cloudformation:describestackevents cloudformation:ListStackResources cloudformation:DescribeStackResource cloudformation:DescribeStackResources cloudformation:DeleteStack | Permissions required to configure and manage the AWS CloudFormation stack. |
S3 Archive permissions |
| Permissions required to perform backup operations on S3 Archive (to move EC2 backups to S3).
๐ Note
|
|
| Permissions required to perform backup operations on S3 Archive (to move EC2 backups to S3).
๐ Note
|
Automated Disaster Recovery permissions |
|
|
VPC Cloning permissions |
| Permissions required for VPC Cloning as part of ADR workflow. |
|
| Permissions required as part of mapping the core VPC Cloning components within ADR. |
|
| Permissions required as part of VPC Cloning teardown. |
Policy-level permissions |
|
|
KMS Encryption Keys |
| Permissions required as part of cross-region and cross-account copy of encrypted backups. |
Policy-level permissions |
| Permissions to enable VSS-consistent snapshots. |