NetAppDocs / bluexp-cloud-volumes-ontap

https://docs.netapp.com/us-en/bluexp-cloud-volumes-ontap/
Other
1 stars 7 forks source link

Cloud provider update for Top Secret and Secret #232

Closed wilshields closed 6 months ago

wilshields commented 1 year ago

Page URL

https://docs.netapp.com/us-en/bluexp-setup-admin/reference-permissions-aws.html

Page title

AWS permissions for the Connector

Summary

I would like the C2S references to be changed to "Top Secret". This is more appropriate. C2S was the old contract name and no longer is valid. The new contract name is C2E but, that may change in the future as to where Top Secret will remain the same.

We also need a new IAM role created for the "Secret" Cloud. It can mimic was is currently listed for "C2S" with 2 minor changes noted below.

ARNs that begin with arn:aws: must be replaced with arn:aws-iso-b. If a resource requires an ARN with a region, use us-isob-east-1 for the region.

We also need some documentation similar to what we have currently for "C2S" for AWS Secret.

Important: We need to update the steps for manually adding the "Amazon Root 4" certificate to the BXP Connector. I have those steps in a Word Doc that I received from engineering if you have trouble getting information from them.

Public issues must not contain sensitive information

netapp-bcammett commented 1 year ago

Doc updates are in the works.

netapp-bcammett commented 1 year ago

@wilshields, can you please take a look at the policies page and confirm that it looks good from your perspective: https://docs.netapp.com/us-en/bluexp-setup-admin/reference-permissions-aws.html

The policy for Secret Cloud is the same as Top Secret, except that the arn was changed to arn:aws-iso-b

Thanks, Ben

netapp-bcammett commented 1 year ago

@wilshields, can you please take a look at my previous comment? Thanks!

wilshields commented 1 year ago

Apologies, this on got lost in my inbox. I think it looks great.

netapp-bcammett commented 1 year ago

Content updates for the setup and admin docs are complete. Passing this over to the Cloud Volumes ONTAP repo where the remaining doc updates need to be made.

netapp-manini commented 6 months ago

Tracked internally through BLUEXPDOC-93. Closing this issue.