-
- Novice
- Posts: 4
- Liked: never
- Joined: Aug 12, 2024 6:02 pm
- Full Name: Juliano Cunha
- Contact:
Permission AMI role
Hello guys,
We trying to implement the VBAWS in a high level security environment, wiches the policies rules needed to be transparent. I see some AMI rule to deploy worker are "dungerours" to be assigned, for example "create role" and "delete role".
https://helpcenter.veeam.com/docs/vbaws ... tml?ver=80
I need to understand about which actions, policies and roles are created due to the existence of the "CreateRole" permission on the worker node, which makes the use and creation of any rule broad and therefore we would like to understand what exactly is created through this "CreateRole".
We trying to implement the VBAWS in a high level security environment, wiches the policies rules needed to be transparent. I see some AMI rule to deploy worker are "dungerours" to be assigned, for example "create role" and "delete role".
https://helpcenter.veeam.com/docs/vbaws ... tml?ver=80
I need to understand about which actions, policies and roles are created due to the existence of the "CreateRole" permission on the worker node, which makes the use and creation of any rule broad and therefore we would like to understand what exactly is created through this "CreateRole".
Partner | VMCE
-
- Product Manager
- Posts: 5908
- Liked: 1236 times
- Joined: Jul 15, 2013 11:09 am
- Full Name: Niels Engelen
- Contact:
Re: Permission AMI role
Hi,
These are required to deploy our workers and for this, we follow AWS best practices and apply certain roles and policies to this. These only apply to the workers and nothing else.
A solution could be to deploy workers in production that require a different set of permissions (see our user guide).
You can also use granular IAM roles within our product to limit permissions assigned to roles.
These are required to deploy our workers and for this, we follow AWS best practices and apply certain roles and policies to this. These only apply to the workers and nothing else.
A solution could be to deploy workers in production that require a different set of permissions (see our user guide).
You can also use granular IAM roles within our product to limit permissions assigned to roles.
GitHub: https://github.com/nielsengelen
-
- Novice
- Posts: 4
- Liked: never
- Joined: Aug 12, 2024 6:02 pm
- Full Name: Juliano Cunha
- Contact:
Re: Permission AMI role
I've tried to restore operation with FLR on bucket S3 in backup account, and this solution sugested isn't adherent.
Partner | VMCE
-
- Product Manager
- Posts: 5908
- Liked: 1236 times
- Joined: Jul 15, 2013 11:09 am
- Full Name: Niels Engelen
- Contact:
Re: Permission AMI role
Could you clarify what exactly isn't working or fits your infrastructure?
GitHub: https://github.com/nielsengelen
-
- Novice
- Posts: 4
- Liked: never
- Joined: Aug 12, 2024 6:02 pm
- Full Name: Juliano Cunha
- Contact:
Re: Permission AMI role
Hello Niels
I've the instance EC2 backup stored in the bucket S3 at backup account and I trying to restore with FLR operation in the same account.
The recovery session finishes with issue message warning to add the 'create role'.
I've the instance EC2 backup stored in the bucket S3 at backup account and I trying to restore with FLR operation in the same account.
The recovery session finishes with issue message warning to add the 'create role'.
Partner | VMCE
-
- Product Manager
- Posts: 5908
- Liked: 1236 times
- Joined: Jul 15, 2013 11:09 am
- Full Name: Niels Engelen
- Contact:
Re: Permission AMI role
I would recommend opening a support case for assistance and insight since it will be hard to troubleshoot via these forums and the forums are created for general technical questions.
Could you open a case and let us know the case ID for future reference? This way we can analyse and potentially adjust or improve things in the product if it’s beneficial.
Thanks!
Could you open a case and let us know the case ID for future reference? This way we can analyse and potentially adjust or improve things in the product if it’s beneficial.
Thanks!
GitHub: https://github.com/nielsengelen
-
- Novice
- Posts: 4
- Liked: never
- Joined: Aug 12, 2024 6:02 pm
- Full Name: Juliano Cunha
- Contact:
Re: Permission AMI role
Niels, the case already opened #07598794, but the solution is still far away.
Partner | VMCE
-
- Product Manager
- Posts: 5908
- Liked: 1236 times
- Joined: Jul 15, 2013 11:09 am
- Full Name: Niels Engelen
- Contact:
Re: Permission AMI role
Hi,
I noticed there was some progress on the case. Please continue working with support as it will be the best way to find a solution due to the requirement for assistance.
I noticed there was some progress on the case. Please continue working with support as it will be the best way to find a solution due to the requirement for assistance.
GitHub: https://github.com/nielsengelen
Who is online
Users browsing this forum: No registered users and 3 guests