NetApp ONTAP, Fujitsu ETERNUS HX/AX, Lenovo ThinkSystem DM/DG Permissions
Built-In Storage Systems
The account used to connect to NetApp ONTAP, Fujitsu ETERNUS HX/AX, Lenovo ThinkSystem DM/DG storage system must have permissions described in this section. The commands are provided for the console, UI names may differ.
Required permissions depend on what you add to the storage infrastructure. If you add a whole cluster, use the permissions listed for the cluster. If you add a storage virtual machine (SVM), use the permissions listed for the SVM.
Cluster (VMware Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
DEFAULT |
readonly |
|
cluster |
readonly |
|
metrocluster |
readonly |
|
vserver fcp |
readonly |
|
volume file |
readonly |
|
lun igroup |
all |
|
vserver iscsi |
all |
|
network |
readonly |
|
system node |
readonly |
|
security |
readonly |
|
security login |
readonly |
|
set |
readonly |
|
snapmirror |
all |
|
system |
readonly |
|
version |
readonly |
|
volume qtree |
readonly |
|
lun |
all |
|
vserver nfs |
all |
|
volume snapshot |
all |
|
volume |
all |
|
vserver |
all |
SVM (VMware Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
DEFAULT |
none |
|
lun |
all |
|
lun igroup |
all |
|
network |
readonly |
|
security |
readonly |
|
security login |
readonly |
|
snapmirror |
all |
|
system |
readonly |
|
version |
readonly |
|
volume |
all |
|
volume file |
readonly |
|
volume qtree |
all |
|
volume snapshot |
all |
|
vserver |
all |
|
vserver fcp |
all |
|
vserver iscsi |
all |
|
vserver nfs |
all |
Cluster (NAS Backup Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
DEFAULT |
readonly |
|
security |
readonly |
|
security login |
readonly |
|
volume snapshot |
all |
|
vserver |
all |
|
vserver nfs |
all |
|
snapdiff |
all Note: Required if Use native changed files tracking is enabled. |
SVM (NAS Backup Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
DEFAULT |
none |
|
lun |
readonly |
|
network |
readonly |
|
security |
readonly |
|
security login |
readonly |
|
snapmirror |
readonly |
|
version |
readonly |
|
volume |
readonly |
|
volume snapshot |
all |
|
vserver |
all |
|
snapdiff |
all Note: Required if Use native changed files tracking is enabled. |
Cluster (Veeam Agent Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
cluster |
readonly |
|
lun |
all |
|
metrocluster |
readonly |
|
network |
readonly |
|
system license |
readonly |
|
system node |
readonly |
|
version |
readonly |
|
volume |
all |
|
volume snapshot |
all |
|
vserver |
all |
SVM (Veeam Agent Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
lun |
all |
|
network |
readonly |
|
version |
readonly |
|
volume |
all |
|
volume snapshot |
all |
|
vserver |
all |
US API Storage Systems
The account used to connect to NetApp FAS/AFF/ASA/ASA r2 storage system must have permissions described in this section. The commands are provided for the console, UI names may differ.
Basic Permissions
The following permissions are required for all integration types. These permissions are required for backup, restore, replication and snapshot workflows on both AFF/unified and ASA r2 systems. Permissions can be provided on the SVM or cluster level; otherwise it is stated in the table.
|
API Endpoint |
Access Level |
|---|---|
|
/api/cluster |
readonly |
|
/api/cluster/jobs |
readonly |
|
/api/cluster/licensing/access-tokens |
read_create |
|
/api/cluster/licensing/licenses |
readonly (cluster level only) |
|
/api/cluster/metrocluster |
readonly (cluster level only) |
|
/api/cluster/nodes |
readonly (cluster level only) |
|
/api/cluster/peers |
read_create |
|
/api/network/ip/interfaces |
readonly |
|
/api/protocols/nfs/export-policies |
all |
|
/api/protocols/nfs/services |
readonly |
|
/api/protocols/san/fcp/services |
readonly |
|
/api/protocols/san/igroups |
all |
|
/api/protocols/san/iscsi/services |
readonly |
|
/api/protocols/san/lun-maps |
all |
|
/api/snapmirror/relationships |
all |
|
/api/storage/aggregates |
readonly (cluster level only) |
|
/api/storage/luns |
all |
|
/api/storage/qtrees |
all |
|
/api/storage/snaplock/compliance-clocks |
readonly |
|
/api/storage/volumes |
all |
|
/api/svm/svms |
readonly |
ASA r2-Only Permissions
These permissions are required only for ASA r2 systems.
|
API Endpoint |
Access Level |
|---|---|
|
/api/application/consistency-groups |
all |
|
/api/storage/storage-units |
all |