![NetApp AltaVault AVA400 Administration Manual Download Page 247](http://html.mh-extra.com/html/netapp/altavault-ava400/altavault-ava400_administration-manual_1669933247.webp)
NetApp AltaVault Cloud Integrated Storage Administration Guide
247
Beta Draft
APPENDIX C
Amazon AWS IAM and S3 bucket
policies
Amazon AWS provides the ability to specify Identity and Access Management (IAM) policies and bucket policies to
control permissions related to AWS users and S3 cloud buckets. In general, IAM users and buckets should be
configured with the minimum permissions required for normal operation. For more details about Amazon’s best
practices, see
http://docs.aws.amazon.com/IAM/latest/UserGuide/IAMBestPractices.html
For more information on Amazon AWS, see the
NetApp AltaVault Cloud Integrated Storage Installation and Service
Guide for Cloud Appliances
.
This appendix includes the following sections:
“Typical AltaVault setup” on page 247
“IAM policies for AltaVault” on page 247
“Bucket policies for AltaVault” on page 249
Typical AltaVault setup
A typical AltaVault setup includes the following AWS configuration:
One IAM user created exclusively for AltaVault. Access keys are generated for the user and entered into the
AltaVault cloud configuration. AltaVault never requires access keys for the root AWS account. It is recommended
that access keys are not generated for the root account.
An IAM group is created with the AltaVault user. A policy is set on the group that allows only the permissions
used by AltaVault.
If a bucket policy is required, then a bucket is created for use by AltaVault, with a policy that allows only the
AltaVault user to access it. It is not necessary to create the bucket prior to AltaVault using it if bucket policies are
not required.
IAM policies for AltaVault
IAM policies allow access to the Amazon S3 account and its associated cloud buckets via different users with restricted
permissions, in contrast to the root account which has unrestricted access to the account and cloud buckets. It is
recommended that programmatic access (including access via appliances such as AltaVault) to Amazon AWS and S3
are done via IAM users with the appropriate permissions rather than via the root AWS account.
Summary of Contents for AltaVault AVA400
Page 2: ...Beta Draft ...
Page 10: ...Beta Draft Contents ...