Amazon Backups or Restores Fail When EBS Encryption By Default Setting Is Enabled in the Region

Article ID: 62686

Article Type: Troubleshooting

Last Modified:

When Amazon EBS encryption for new volumes is enabled for an AWS region, backups and full instance restores that use resources from a service account might fail.

Symptoms

When Amazon EBS encryption for new volumes is enabled for an AWS region, backups and full instance restores that use resources from a service account might fail.

Causes

If Amazon EBS encryption for new volumes is enabled for an AWS region in your AWS account, all new EBS volumes created in your account for that region are encrypted, including volumes that are created during backups. As a result, those volumes cannot be modified by the backup process, and the backup fails. Volume encryption also prevents snapshots from being shared across accounts. As a result, full VM restores that are performed using resources from a separate service account fail.

Resolution

Applicable to: Feature Release 11.21 and below

To enable backups to complete successfully, on the access node (VSA proxy) that is used to perform the backup, you can configure the bAllowAWSModifyBackupVolume additional setting and set the value to 0.  This setting enables backups to complete without attempting to modify the volumes that are created as part of the backup. To prevent the errors for backups and restores that are caused by default encryption settings, you can disable the Amazon setting in your account:

  1. In your AWS account, open the EC2 Dashboard for the region where the EC2 instances are hosted.
  2. On the right-hand side, under Account Attributes, click Settings.
  3. Clear the Always encrypt new EBS volumes check box.

Applicable to: Feature Release 11.22 and later

Backups:

Full VM Restores:
Verify that the KMS key from the admin account is shared with the tenant account.

1 Commvault Way, Tinton Falls, NJ 07724 Sitemap | Legal Notices | Trademarks | Privacy Policy
Copyright © Commvault | All Rights Reserved.