Step 4. Specify Restore Settings
At the Account step of the wizard, choose whether you want to use an IAM role or one-time access keys of an IAM user to allow Veeam Backup for AWS to perform the restore operation, and whether you want Veeam Backup for AWS to deploy worker instances in the production account. For information on the permissions that the IAM role or IAM user must have to perform the restore operation, see EC2 Restore IAM Permissions.
Important |
Make sure that the specified IAM role or one-time access keys belong to an AWS account to which you plan to restore EBS volumes. |
To specify an IAM role, select the IAM role option and choose the necessary IAM role from the list.
For an IAM role to be displayed in the IAM Role list, it must be added to Veeam Backup for AWS with the Amazon EC2 Restore operation selected as described in section Adding IAM Roles. If you have not added the necessary IAM role to Veeam Backup for AWS beforehand, you can do it without closing the Volume Restore wizard. To do that, click Add and complete the Add IAM Role wizard.
Important |
It is recommended that you check whether the selected IAM role has all the permissions required to perform the operation. If some permissions of the IAM role are missing, the restore operation will fail to complete successfully. To run the IAM role permission check, click Check Permissions and follow the instructions provided in section Checking IAM Role Permissions. |
Specifying One-Time Access Keys
To specify one-time access keys, select the Temporary access keys option, and use the Access key and Secret key fields to provide the access key ID and the secret access key.
Note |
Veeam Backup for AWS does not store one-time access keys in the configuration database. |
Enabling Worker Deployment in Production Account
[This option applies only if you restore volumes from image-level backups and have selected the IAM role option]
By default, Veeam Backup for AWS deploys worker instances used to perform restore operations in the backup account. However, you can instruct Veeam Backup for AWS to deploy worker instances in a production account — that is, an account to which the volumes will be restored. To do that, set the Deploy workers in production account toggle to On, and specify an IAM role that will be attached to the worker instances and used by Veeam Backup for AWS to communicate with these instances. The specified IAM role must belong to the same account to which the IAM role specified to perform the restore operation belongs, and must be assigned permissions listed in section Worker Deployment Role Permissions in Production Accounts.
For an IAM role to be displayed in the IAM role list, it must be added to Veeam Backup for AWS with the Production worker role selected as described in section Adding IAM Roles. If you have not added the necessary IAM role to Veeam Backup for AWS beforehand, you can do it without closing the Volume Restore wizard. To do that, click Add and complete the Add IAM Role wizard.
Important |
If you instruct Veeam Backup for AWS to deploy worker instances in production accounts, you must assign additional permissions to the IAM role used to perform the restore operation. For more information on the required permissions, see EC2 Restore IAM Permissions. |