Please enter search query.
Search <book_title>...
NetBackup™ Snapshot Manager Guide d'installation et de mise à niveau
Last Published:
2022-10-28
Product(s):
NetBackup (10.1)
- Introduction
- Section I. Installation et configuration de NetBackup Snapshot Manager
- Préparation de l'installation de NetBackup Snapshot Manager
- Déploiement de NetBackup Snapshot Manager à l'aide d'images de conteneurs
- Déploiement d'extensions NetBackup Snapshot Manager
- Installation de l'extension Snapshot Manager sur une machine virtuelle
- Installation de l'extension Snapshot Manager sur un cluster Kubernetes géré (AKS) dans Azure
- Installation de l'extension Snapshot Manager sur un cluster Kubernetes géré (EKS) dans AWS
- Installation de l'extension Snapshot Manager sur un cluster Kubernetes géré (GKE) dans GCP
- Plug-ins cloud de NetBackup Snapshot Manager
- Remarques relatives à la configuration du plug-in AWS
- Remarques relatives à la configuration du plug-in Google Cloud Platform
- Remarques relatives à la configuration du plug-in Microsoft Azure
- Remarques relatives à la configuration du plug-in Microsoft Azure Stack Hub
- Agents d'application et plug-ins de NetBackup Snapshot Manager
- Installation et configuration de l'agent Snapshot Manager
- Configuration du plug-in d'application Snapshot Manager
- Plug-in Microsoft SQL
- Étapes supplémentaires requises après une restauration de snapshot d'instance SQL Server
- Plug-in Oracle
- Plan de protection NetBackup
- Protection des biens à l'aide de la fonction sans agent de NetBackup Snapshot Manager
- Chiffrement de volume dans NetBackup Snapshot Manager
- Sécurité de NetBackup Snapshot Manager
- Préparation de l'installation de NetBackup Snapshot Manager
- Section II. Maintenance de NetBackup Snapshot Manager
- Consignation dans NetBackup Snapshot Manager
- Mise à niveau de NetBackup Snapshot Manager
- Migration et mise à niveau de Snapshot Manager
- Tâches suivant une mise à niveau :
- Désinstallation de NetBackup Snapshot Manager
- Dépannage de NetBackup Snapshot Manager
Autorisations AWS requises par Snapshot Manager
L'exemple suivant est une définition de rôle IAM (au format JSON) permettant à Snapshot Manager de configurer le plug-in AWS et de découvrir des biens, de gérer les snapshots, etc.
{ "Version": "2012-10-17", "Statement": [ { "Sid": "EC2AutoScaling", "Effect": "Allow", "Action": [ "autoscaling:UpdateAutoScalingGroup", "autoscaling:AttachInstances", "autoscaling:DescribeScalingActivities", "autoscaling:TerminateInstanceInAutoScalingGroup" ], "Resource": [ "*" ] }, { "Sid": "KMS", "Effect": "Allow", "Action": [ "kms:ListKeys", "kms:Encrypt", "kms:Decrypt", "kms:ReEncryptTo", "kms:DescribeKey", "kms:ListAliases", "kms:GenerateDataKey", "kms:GenerateDataKeyWithoutPlaintext", "kms:ReEncryptFrom", "kms:CreateGrant" ], "Resource": [ "*" ] }, { "Sid": "RDSBackup", "Effect": "Allow", "Action": [ "rds:DescribeDBSnapshots", "rds:DescribeDBClusters", "rds:DescribeDBClusterSnapshots", "rds:DeleteDBSnapshot", "rds:CreateDBSnapshot", "rds:CreateDBClusterSnapshot", "rds:ModifyDBSnapshotAttribute", "rds:DescribeDBSubnetGroups", "rds:DescribeDBInstances", "rds:CopyDBSnapshot", "rds:CopyDBClusterSnapshot", "rds:DescribeDBSnapshotAttributes", "rds:DeleteDBClusterSnapshot", "rds:ListTagsForResource", "rds:AddTagsToResource" ], "Resource": [ "*" ] }, { "Sid": "RDSRecovery", "Effect": "Allow", "Action": [ "rds:ModifyDBInstance", "rds:ModifyDBClusterSnapshotAttribute", "rds:RestoreDBInstanceFromDBSnapshot", "rds:ModifyDBCluster", "rds:RestoreDBClusterFromSnapshot", "rds:CreateDBInstance", "rds:RestoreDBClusterToPointInTime", "rds:CreateDBSecurityGroup", "rds:CreateDBCluster", "rds:RestoreDBInstanceToPointInTime", "rds:DescribeDBClusterParameterGroups" ], "Resource": [ "*" ] }, { "Sid": "EC2Backup", "Effect": "Allow", "Action": [ "sts:GetCallerIdentity", "ec2:CreateSnapshot", "ec2:CreateSnapshots", "ec2:DescribeInstances", "ec2:DescribeInstanceStatus", "ec2:ModifySnapshotAttribute", "ec2:CreateImage", "ec2:CopyImage", "ec2:CopySnapshot", "ec2:DescribeSnapshots", "ec2:DescribeVolumeStatus", "ec2:DescribeVolumes", "ec2:RegisterImage", "ec2:DescribeVolumeAttribute", "ec2:DescribeSubnets", "ec2:DescribeVpcs", "ec2:DeregisterImage", "ec2:DeleteSnapshot", "ec2:DescribeInstanceAttribute", "ec2:DescribeRegions", "ec2:ModifyImageAttribute", "ec2:DescribeAvailabilityZones", "ec2:ResetSnapshotAttribute", "ec2:DescribeHosts", "ec2:DescribeImages", "ec2:DescribeSecurityGroups" , "ec2:DescribeNetworkInterfaces" ], "Resource": [ "*" ] }, { "Sid": "EC2Recovery", "Effect": "Allow", "Action": [ "ec2:RunInstances", "ec2:AttachNetworkInterface", "ec2:DetachVolume", "ec2:AttachVolume", "ec2:DeleteTags", "ec2:CreateTags", "ec2:StartInstances", "ec2:StopInstances", "ec2:TerminateInstances", "ec2:CreateVolume", "ec2:DeleteVolume", "ec2:DescribeIamInstanceProfileAssociations", "ec2:AssociateIamInstanceProfile", "ec2:AssociateAddress", "ec2:DescribeKeyPairs", "ec2:AuthorizeSecurityGroupEgress", "ec2:AuthorizeSecurityGroupIngress", "ec2:DescribeInstanceTypeOfferings", "ec2:GetEbsEncryptionByDefault" ], "Resource": [ "*" ] }, { "Sid": "EBS", "Effect": "Allow", "Action": [ "ebs:ListSnapshotBlocks", "ebs:GetSnapshotBlock", "ebs:CompleteSnapshot", "ebs:PutSnapshotBlock", "ebs:ListChangedBlocks" ], "Resource": [ "*" ] }, { "Sid": "EKS", "Effect": "Allow", "Action": [ "eks:DescribeNodegroup", "eks:DescribeUpdate", "eks:UpdateNodegroupConfig", "eks:ListClusters" "eks:DescribeCluster" ], "Resource": [ "*" ] }, { "Sid": "IAM", "Effect": "Allow", "Action": [ "iam:ListAccountAliases", "iam:SimulatePrincipalPolicy" ], "Resource": [ "*" ] } ] }
Si une extension Snapshot Manager est installée sur un cluster Kubernetes géré dans AWS, ajoutez les politiques suivantes pour un compte d'utilisateur ou un rôle avant de configurer le plug-in :
AmazonEKSClusterPolicy AmazonEKSWorkerNodePolicy AmazonEC2ContainerRegistryReadOnly AmazonEKS_CNI_Policy AmazonEKSServicePolicy
Autorisations IAM supplémentaires requises pour le déploiement du marketplace
{ "Sid": "AWSMarketplacePermissions", "Effect": "Allow", "Action": [ "autoscaling:UpdateAutoScalingGroup", "autoscaling:AttachInstances", "sns:Publish", "sns:GetTopicAttributes", "secretsmanager:GetResourcePolicy", "secretsmanager:GetSecretValue", "secretsmanager:DescribeSecret", "secretsmanager:RestoreSecret", "secretsmanager:PutSecretValue", "secretsmanager:DeleteSecret", "secretsmanager:UpdateSecret" ], "Resource": [ "*" ] }
Autorisations IAM supplémentaires requises par les charges de travail PaaS
{ "Sid": "DynamoDB", "Effect": "Allow", "Action": [ "dynamodb:ListTables", "dynamodb:DescribeTable", "dynamodb:CreateTable", "dynamodb:BatchWriteItem", "dynamodb:DescribeContinuousBackups", "dynamodb:ExportTableToPointInTime", "dynamodb:DescribeExport", "dynamodb:DeleteTable", "dynamodb:UpdateTable", "dynamodb:UpdateContinuousBackups" ], "Resource": [ "*" ] }, { "Sid": "S3Permissions", "Effect": "Allow", "Action": [ "s3:PutObject", "s3:GetObject", "s3:ListBucket", "s3:DeleteObject" ], "Resource": [ "*" ] }