Configuring Backups for Amazon DynamoDB Intances with Access Key and Secret Key Authentication

Updated

You can configure backups for Amazon DynamoDB instances using access key/secret key authentication for dev/test or proof-of-concept environments.

Important: As a best practice, AWS recommends using IAM roles instead of access keys. For more information, see Security best practices in IAM in the AWS documentation.

Start the Configuration Wizard

  1. From the Command Center navigation pane, go to Protect > Databases.

    The Instances page appears.

  2. In the upper-right area of the page, click Add instance, and then select Cloud database service.

    The Add Cloud DB Instance page appears.

  3. Select Amazon Web Services.

  4. Click Next.

    The Configure Amazon Database page appears.

  5. Select DynamoDB.

  6. Click Next.

    The Backup Method page appears.

  7. Review the information.

  8. Click Next.

    The IAM Role page of the configuration wizard appears.

IAM Role

  1. From the Authentication method list, select Access and secret key.

  2. Verify an existing MetallicUserGroup IAM user group or create a new MetallicUserGroup IAM user group:

    • If the MetallicUserGroup IAM user group was previously created for another AWS workload, do the following:

      1. Verify that the IAM policies for the AWS workload are still attached to the MetallicUserGroup IAM user group.

      2. At the bottom of the page, select the confirmation check box.

      3. Click Next.

        The Region page of the configuration wizard appears.

    • If the MetallicUserGroup IAM user group does not exist yet, create it in AWS.

Region

  1. Select the region that the databases reside in.

  2. Click Next.

    The Backup Gateway page of the configuration wizard appears.

Backup Gateway

  • If AWS EBS encryption is enabled for your region in your AWS account, the user who uses the backup gateway template must be a key user for the default encryption key. To see if EBS encryption is enabled, in your AWS account, go to EC2 > EC2 Dashboard > Settings > EBS encryption. To see a list of key users for the default encryption key, in your AWS account, go to Key Management Service > Customer managed keys. If you do not have the correct level of access to use the template, you can copy the Launch Cloud Formation Stack link and share it with someone who has the correct level of access, such as your security administrator.

  • Determine the region of your AWS S3 storage. The backup gateway must reside in the same region as the primary storage.

  1. Select an existing backup gateway or create a new backup gateway.

  2. Click Next.

    The Cloud Storage page of the configuration wizard appears.

Cloud Storage

  1. For the primary copy of the backup data, select an existing S3 storage bucket or create a new S3 storage bucket.

  2. Click Next.

    The Plan page of the configuration wizard appears.

Plan

A plan specifies the storage to back up the data to and other settings such as recovery point objective (RPO) settings.

  1. Select an existing plan or create a new plan.

  2. Click Next.

    The Cloud Account page of the configuration wizard appears.

Cloud Account

The cloud account is used to access the instances for discovery, backups, and other operations.

  1. Select an existing cloud account or create a new cloud account.

  2. Click Next.

    The Backup Content page of the configuration wizard appears.

Backup Content

  1. Review the list of instances that will be protected.

  2. Click Next.

    The Summary page of the configuration wizard appears.

Summary

  1. Review the summary.

  2. Click Finish.