Skip to main content
Version: 3.1

EKS Cluster Prerequisites

Applicable to both Classic and Federated modes

Before adding an Amazon EKS cluster to Portworx Backup, ensure that the following prerequisites are met:

  • Stork is installed on all application clusters.

  • Create an IAM role in AWS console with the following permissions:

    • ec2:DeleteSnapshot
    • ec2:DescribeInstances
    • ec2:CreateTags
    • ec2:CreateSnapshots
    • ec2:DescribeVolumes
    • ec2:CreateSnapshot
    • ec2:DescribeRegions
    • ec2:DescribeSnapshots
    • ec2:CreateVolume
  • When you try to create a backup using a cloud account, make sure either the bucket is already created, or your credentials include permissions to create a bucket. If a bucket is not already created, you must add the s3:CreateBucket permission to your IAM role.

  • If Portworx Enterprise is not yet installed on the cluster you wish to back up, you must add the following permissions to your IAM role:

    • s3:ListBucketMultipartUploads
    • s3:ListBucketVersions
    • s3:ListBucket
    • s3:GetBucketAcl
    • s3:GetBucketObjectLockConfiguration
    • s3:ListMultipartUploadParts
    • s3:PutObject
    • s3:GetObjectAcl
    • s3:GetObject
    • s3:ListAllMyBuckets
    • s3:GetObjectVersionAcl
    • s3:DeleteObject
    • s3:PutObjectAcl

    note

    To configure object lock in Portworx Backup, you need to enable additional permissions for the IAM role. For more information, refer to Prerequisites in Create object lock enabled backups.

note

The S3 permissions listed above are also required when you use AWS S3 as a backup location in Portworx Backup. When you create an AWS cloud account and add an S3 backup location, ensure that the associated IAM role or credentials have the same S3 permissions.

Related topic: