Configuring Backups for Amazon DynamoDB Instances with IAM Role Authentication

Updated

You can configure backups for Amazon DynamoDB instances using an IAM role. The configuration wizard guides you through the configuration process, which includes creating any new entities that are needed, such as a plan and cloud storage.

Start the Configuration Wizard

  1. From the Command Center navigation pane, go to Protect > Databases.

    The Instances page appears.

  2. In the upper-right area of the page, click Add instance, and then select Cloud database service.

    The Add Cloud DB Instance page appears.

  3. Select Amazon Web Services.

  4. Click Next.

    The Configure Amazon Database page appears.

  5. Select DynamoDB.

  6. Click Next.

    The Backup Method page appears.

  7. Review the information.

  8. Click Next.

    The IAM Role page of the configuration wizard appears.

IAM Role

  1. From the Authentication method list, select IAM role.

  2. Verify an existing MetallicRole IAM role or create a new MetallicRole IAM role:

    • If the MetallicRole IAM role was previously created for another AWS workload, do the following:

      1. Verify that the IAM policies for the AWS workload are still attached to the MetallicRole IAM role.

      2. At the bottom of the page, select the confirmation check box.

      3. Click Next.

        The Region page of the configuration wizard appears.

    • If the MetallicRole IAM role does not exist yet, create it in AWS.

Region

  1. Select the region that the databases reside in.

  2. Click Next.

    The Backup Gateway page of the configuration wizard appears.

Backup Gateway

  • If AWS EBS encryption is enabled for your region in your AWS account, the user who uses the backup gateway template must be a key user for the default encryption key. To see if EBS encryption is enabled, in your AWS account, go to EC2 > EC2 Dashboard > Settings > EBS encryption. To see a list of key users for the default encryption key, in your AWS account, go to Key Management Service > Customer managed keys. If you do not have the correct level of access to use the template, you can copy the Launch Cloud Formation Stack link and share it with someone who has the correct level of access, such as your security administrator.

  • Determine the region of your AWS S3 storage. The backup gateway must reside in the same region as the primary storage.

  1. Select an existing backup gateway or create a new backup gateway.

  2. Click Next.

    The Cloud Storage page of the configuration wizard appears.

Cloud Storage

To review the supported combinations of primary and secondary storage, see Metallic Storage Options.

Primary Copy

  1. For the primary copy of the backup data, select an existing S3 storage bucket or create a new S3 storage bucket.

  2. Click Next.

Secondary Copy

  1. Decide whether to store a secondary copy of the backup data for long-term retention.

  2. Click Next.

    The Plan page of the configuration wizard appears.

Plan

A plan specifies the storage to back up the data to and other settings such as recovery point objective (RPO) settings.

  1. Select an existing plan or create a new plan.

  2. Click Next.

    The Cloud Account page of the configuration wizard appears.

Cloud Account

The cloud account is used to access the databases for discovery, backups, and other operations.

  1. Select an existing cloud account or create a new cloud account.

  2. Click Next.

    The Backup Content page of the configuration wizard appears.

Backup Content

  1. Review the list of instances that will be protected.

  2. Click Next.

    The Summary page of the configuration wizard appears.

Summary

  1. Review the summary.

  2. Click Finish.