Discussions related to using object storage as a backup target.
Post Reply
sankler.bergman
Novice
Posts: 3
Liked: never
Joined: May 15, 2024 1:45 pm
Full Name: Sankler Bergman de Jesus Castanho
Contact:

S3 role connection on object storage

Post by sankler.bergman »

Hello, im having security issues as we growth in tenants that we send backup jobs to an S3 bucket

On VBR console we only have the option to add an key and secret informations but doesnt allow me to add trought an role instead
sfirmes
Veeam Software
Posts: 265
Liked: 129 times
Joined: Jul 24, 2018 8:38 pm
Full Name: Stephen Firmes
Contact:

Re: S3 role connection on object storage

Post by sfirmes »

Sankler,

Thanks for reaching out. You can control what role(s) the user has via IAM policies. Here is an example of an IAM policy that can be used with VBR. Example IAM policy

Hope this helps.

Steve
Senior Solutions Architect, Product Management - Alliances @ Veeam Software
sankler.bergman
Novice
Posts: 3
Liked: never
Joined: May 15, 2024 1:45 pm
Full Name: Sankler Bergman de Jesus Castanho
Contact:

Re: S3 role connection on object storage

Post by sankler.bergman »

but steve as you can on these kind of policy is that we have to implicit let them to deleteobjects, so if you have the power throught the primary key you can also do malisous activity on the side of this bucket if in any kind you have access to this kind of information
sankler.bergman
Novice
Posts: 3
Liked: never
Joined: May 15, 2024 1:45 pm
Full Name: Sankler Bergman de Jesus Castanho
Contact:

Re: S3 role connection on object storage

Post by sankler.bergman »

i have another question, how can i suggest this as an future feature on Veeam?
sfirmes
Veeam Software
Posts: 265
Liked: 129 times
Joined: Jul 24, 2018 8:38 pm
Full Name: Stephen Firmes
Contact:

Re: S3 role connection on object storage

Post by sfirmes »

sankler.bergman wrote: May 15, 2024 3:04 pm but steve as you can on these kind of policy is that we have to implicit let them to deleteobjects, so if you have the power throught the primary key you can also do malisous activity on the side of this bucket if in any kind you have access to this kind of information
The IAM policy example is to grant the account/credentials used by VBR in order to put/get/delete, etc.... objects within the bucket used for the repository. In this scenario VBR needs to be able to delete objects as part of its normal backup data management processes.

Hope I was able to clarify what the documented IAM policy's intent was.

Steve
Senior Solutions Architect, Product Management - Alliances @ Veeam Software
sfirmes
Veeam Software
Posts: 265
Liked: 129 times
Joined: Jul 24, 2018 8:38 pm
Full Name: Stephen Firmes
Contact:

Re: S3 role connection on object storage

Post by sfirmes »

sankler.bergman wrote: May 15, 2024 6:48 pm i have another question, how can i suggest this as an future feature on Veeam?
Sankler,

If you can PM me and provide me the details of what you are requesting, I will place this request into our system.

Thanks

Steve
Senior Solutions Architect, Product Management - Alliances @ Veeam Software
Post Reply

Who is online

Users browsing this forum: No registered users and 9 guests