-
- Novice
- Posts: 3
- Liked: never
- Joined: May 15, 2024 1:45 pm
- Full Name: Sankler Bergman de Jesus Castanho
- Contact:
S3 role connection on object storage
Hello, im having security issues as we growth in tenants that we send backup jobs to an S3 bucket
On VBR console we only have the option to add an key and secret informations but doesnt allow me to add trought an role instead
On VBR console we only have the option to add an key and secret informations but doesnt allow me to add trought an role instead
-
- Veeam Software
- Posts: 304
- Liked: 146 times
- Joined: Jul 24, 2018 8:38 pm
- Full Name: Stephen Firmes
- Contact:
Re: S3 role connection on object storage
Sankler,
Thanks for reaching out. You can control what role(s) the user has via IAM policies. Here is an example of an IAM policy that can be used with VBR. Example IAM policy
Hope this helps.
Steve
Thanks for reaching out. You can control what role(s) the user has via IAM policies. Here is an example of an IAM policy that can be used with VBR. Example IAM policy
Hope this helps.
Steve
Steve Firmes | Senior Solutions Architect, Product Management - Alliances @ Veeam Software
-
- Novice
- Posts: 3
- Liked: never
- Joined: May 15, 2024 1:45 pm
- Full Name: Sankler Bergman de Jesus Castanho
- Contact:
Re: S3 role connection on object storage
but steve as you can on these kind of policy is that we have to implicit let them to deleteobjects, so if you have the power throught the primary key you can also do malisous activity on the side of this bucket if in any kind you have access to this kind of information
-
- Novice
- Posts: 3
- Liked: never
- Joined: May 15, 2024 1:45 pm
- Full Name: Sankler Bergman de Jesus Castanho
- Contact:
Re: S3 role connection on object storage
i have another question, how can i suggest this as an future feature on Veeam?
-
- Veeam Software
- Posts: 304
- Liked: 146 times
- Joined: Jul 24, 2018 8:38 pm
- Full Name: Stephen Firmes
- Contact:
Re: S3 role connection on object storage
The IAM policy example is to grant the account/credentials used by VBR in order to put/get/delete, etc.... objects within the bucket used for the repository. In this scenario VBR needs to be able to delete objects as part of its normal backup data management processes.sankler.bergman wrote: ↑May 15, 2024 3:04 pm but steve as you can on these kind of policy is that we have to implicit let them to deleteobjects, so if you have the power throught the primary key you can also do malisous activity on the side of this bucket if in any kind you have access to this kind of information
Hope I was able to clarify what the documented IAM policy's intent was.
Steve
Steve Firmes | Senior Solutions Architect, Product Management - Alliances @ Veeam Software
-
- Veeam Software
- Posts: 304
- Liked: 146 times
- Joined: Jul 24, 2018 8:38 pm
- Full Name: Stephen Firmes
- Contact:
Re: S3 role connection on object storage
Sankler,sankler.bergman wrote: ↑May 15, 2024 6:48 pm i have another question, how can i suggest this as an future feature on Veeam?
If you can PM me and provide me the details of what you are requesting, I will place this request into our system.
Thanks
Steve
Steve Firmes | Senior Solutions Architect, Product Management - Alliances @ Veeam Software
Who is online
Users browsing this forum: No registered users and 19 guests