Correct permissions to Restore an Aurora Backup from AWS Backup with KMS
Hello, here is the situation, we have AWS Backup configured to backup Aurora Clusters, the Aurora Cluster is encrypted with a CMK of KMS. Now, that we want to restore a backup using the AWS Backup Console, the process says it finished successfully but the restored Aurora Cluster has 0 instances. So I think there is an issue of permissions to use the KMS key, but I have tried different permissions to no avail. Is there a document that specifies the correct permissions for this to work ?
Thanks in advanced. Kind Regards,
You can look at CloudTrail event history around the time when you run the restore to see if any CreateDBInstance call is failing/giving an error. The error code would tell the missing permission.
Please also look at any other API calls around that timestamp to note any additional API calls which gave an error.
Hello Shivam, I did and I got no errors, I see the following actions: StartRestoreJob, RestoreDBClusterFromSnapshot, CreateGrant, RestoreStarted
I could not find any error in CloudTrail, the Bakcup Restore Job shows as Completed, the RDS Cluster is there with status of Available but with 0 instances.
What IAM Role permissions required to restore CMK encrypted EC2 instances ?asked 2 years ago
Correct permissions to Restore an Aurora Backup from AWS Backup with KMSasked 3 months ago
Amazon Aurora cross-account and cross-region backupasked 3 months ago
Babelfish backup and recovery optionsasked 16 days ago
CDK: How to create an encrypted Aurora MySQL-compatible cluster using an un-encrypted snapshotEXPERTasked 3 months ago
Best practices for faster seeding of cross-region replica Aurora cluster to enable failbackAccepted AnswerEXPERTasked 3 years ago
AWS Backup: Backup windowAccepted Answerasked 3 years ago
Move RDS MySQL 5.6.40 database to Aurora Serverlessasked 3 years ago
AWS Backup for AWS Organizations IAM Configuration IssueAccepted Answerasked a month ago
Copying RDS Snapshot to another accountAccepted Answerasked 2 years ago