Identity and access management (AWS)

CSM Proxy is assigned an IAM role. It requires sqs, cloudformation, ecs, ebs.*, and iam.* permissions to securely transfer data to PowerProtect DD Virtual Edition.

The AWS cloud account that is used must be a role-based account to copy snapshots to DDVE.
NOTE: Follow instructions in Step 5 under Configure a role-based IAM user for AWS, to establish a trust relationship to copy data from a cloud account to PowerProtect DD Virtual Edition (DDVE) or restore data from DDVE.

The AWS permissions that are required are available at AWS minimum permissions. To understand why Cloud Snapshot Manager needs these specific permissions, see AWS permission usage.

The proxy communicates with services that are hosted in the Dell Data Center using the AWS SQS service. If DDVE and CSM Proxy are in different VPCs, VPC peering is required and you have to configure it outside Cloud Snapshot Manager.