Learn about AWS credentials and permissions
Learn how BlueXP uses AWS credentials to perform actions on your behalf and how those credentials are associated with marketplace subscriptions. Understanding these details can be helpful as you manage the credentials for one or more AWS accounts in BlueXP. For example, you might want to learn about when to add additional AWS credentials to BlueXP.
Initial AWS credentials
When you deploy a Connector from BlueXP, you need to provide the ARN of an IAM role or access keys for an IAM user. The authentication method that you use must have the required permissions to deploy the Connector instance in AWS. The required permissions are listed in the Connector deployment policy for AWS.
When BlueXP launches the Connector instance in AWS, it creates an IAM role and an instance profile for the instance. It also attaches a policy that provides the Connector with permissions to manage resources and processes within that AWS account. Review how BlueXP uses the permissions.
If you create a new working environment for Cloud Volumes ONTAP, BlueXP selects these AWS credentials by default:
You can deploy all of your Cloud Volumes ONTAP systems using the initial AWS credentials, or you can add additional credentials.
Additional AWS credentials
You might add additional AWS credentials to BlueXP in the following cases:
-
To use your existing BlueXP Connector with an additional AWS account
-
To create a new Connector in a specific AWS account
-
To create and manage FSx for ONTAP file systems
Review the sections below for more details.
Add AWS credentials to use a Connector with another AWS account
If you want to use BlueXP with additional AWS accounts, then you can either provide AWS keys for an IAM user or the ARN of a role in a trusted account. The following image shows two additional accounts, one providing permissions through an IAM role in a trusted account and another through the AWS keys of an IAM user:
You would then add the account credentials to BlueXP by specifying the Amazon Resource Name (ARN) of the IAM role, or the AWS keys for the IAM user.
For example, you can switch between credentials when creating a new Cloud Volumes ONTAP working environment:
Add AWS credentials to create a Connector
Adding new AWS credentials to BlueXP provides the permissions needed to create a Connector.
Add AWS credentials for FSx for ONTAP
Adding new AWS credentials to BlueXP provides the permissions needed to create and manage an FSx for ONTAP working environment.
Credentials and marketplace subscriptions
The credentials that you add to a Connector must be associated with an AWS Marketplace subscription so that you can pay for Cloud Volumes ONTAP at an hourly rate (PAYGO) or through an annual contract, and to use other BlueXP services.
Note the following about AWS credentials and marketplace subscriptions:
-
You can associate only one AWS Marketplace subscription with a set of AWS credentials
-
You can replace an existing marketplace subscription with a new subscription
FAQ
The following questions are related to credentials and subscriptions.
How can I securely rotate my AWS credentials?
As described in the sections above, BlueXP enables you to provide AWS credentials in a few ways: an IAM role associated with the Connector instance, by assuming an IAM role in a trusted account, or by providing AWS access keys.
With the first two options, BlueXP uses the AWS Security Token Service to obtain temporary credentials that rotate constantly. This process is the best practice—it's automatic and it's secure.
If you provide BlueXP with AWS access keys, you should rotate the keys by updating them in BlueXP at a regular interval. This is a completely manual process.
Can I change the AWS Marketplace subscription for Cloud Volumes ONTAP working environments?
Yes, you can. When you change the AWS Marketplace subscription that's associated with a set of credentials, all existing and new Cloud Volumes ONTAP working environments will be charged against the new subscription.
Can I add multiple AWS credentials, each with different marketplace subscriptions?
All AWS credentials that belong to the same AWS account will be associated with the same AWS Marketplace subscription.
If you have multiple AWS credentials that belong to different AWS accounts, then those credentials can be associated with the same AWS Marketplace subscription or with different subscriptions.
Can I move existing Cloud Volumes ONTAP working environments to a different AWS account?
No, it's not possible to move the AWS resources associated with your Cloud Volumes ONTAP working environment to a different AWS account.
How do credentials work for marketplace deployments and on-prem deployments?
The sections above describe the recommended deployment method for the Connector, which is from BlueXP. You can also deploy a Connector in AWS from the AWS Marketplace and you can manually install the Connector software on your own Linux host.
If you use the Marketplace, permissions are provided in the same way. You just need to manually create and set up the IAM role, and then provide permissions for any additional accounts.
For on-premises deployments, you can't set up an IAM role for the BlueXP system, but you can provide permissions using AWS access keys.
To learn how to set up permissions, refer to the following pages: