Access Key ID: AKIAIOSFODNN7EXAMPLE Secret Access Key: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
Cloud Backup
title: Cloud Backup - How to Set Up Amazon S3 for Cloud Backup created_at: 2016.03.01 updated_at: 2021.06.21 category: Cloud Backup --- :toc: macro :toc-title:

Amazon S3 provides a low-cost, scalable cloud storage location for secure off-site data protection. It offers a free tier to its cloud services that includes 5GB of storage for a year. Retrospect 11 and higher for Windows and Retrospect 13 and higher for Mac are certified for Amazon S3. Follow these step-by-step instructions for setting up an Amazon S3 account, configuring a storage location (called a "bucket"), and creating a set of security credentials (an Access Key and a Secret Key, similar to a username and password).
See the following video or the steps below to quickly create an Amazon AWS account.
Visit Amazon AWS to start the account creation process and click "Create an AWS Account".

Fill in an email address and password.

Complete the contact information form.

Complete the payment information form.

Complete the identity verification.

Select an appropriate Support Plan.

The new account is created. You’re ready to set up the storage location.

Now we will create a bucket that Retrospect can use to store backups.
Log into AWS Console.

Search for S3 and select.

Click "Create Bucket".

Type in an appropriate name for the bucket. Note that these are globally-unique names.

Continue through the rest of the wizard with default options.



Your bucket is now ready. In Retrospect, the "Path" is s3.amazonaws.com/your_bucket_name. Next, you need a set of security credentials for Retrospect to use to access it.

Amazon S3 offers different storage classes to tailor its feature set and pricing model to different use cases. Retrospect supports "Standard", "Reduced Redundancy", "Infrequent Access", "One-Region", "S3 Glacier", and "S3 Glacier Deep Archive". The default storage class is "Standard". See below for how to use the other storage classes.
You can use Amazon’s guide to Lifecycle Management or follow the steps below.
Go to S3, select your Retrospect bucket, click on Properties, select Lifecycle, and click "Add Rule".

Choose the target for the rule. This must include your set.

Select "Transition to the Standard - Infrequent Access Storage Class". The minimum number of days is 30. Click "Review" and then "Create and Activate Rule"

You will see the rule listed in your bucket’s Properties under Lifecycle.

Amazon S3’s Glacier storage classes are very cost-effective but come with a performance trade-off. When you utilize either "S3 Glacier" or "S3 Glacier Deep Archive", objects (backups) are not immediately accessible and must be restored. Retrospect defaults to storing objects under the "Standard" tier, so you will need to make a lifecycle to transition objects to Glacier storage.
You can use Amazon’s guide to Lifecycle Management or follow the steps below.
Backup
Go to S3, select your Retrospect bucket, click on Management.

Click "Create Lifecycle Rule".

Fill out the name and prefix (what backup sets you want to transition). Retrospect only uses the current version of the object, so check "Transition current versions of objects between storage classes". You can transition directly from your current storage tier to "S3 Glacier Deep Archive". Click "Create Rule".
You will see the rule listed in your bucket’s Properties under Lifecycle.
Restore
Files stored on Glacier require a separate restore process before Retrospect can access them. You need to select the files in the set and click "Initiate Restore". You can also use a CLI to perform this in bulk.

Select the number of days you need to files temporarily available (for the restore) and the method (which affects cost).

The restore will start, and the set will be available for Retrospect. You can see verify what storage class the set is by looking at the file browser.
The "Reduced Redundancy" storage class is not available in Lifecycle. You must set this storage class periodically after a backup. You can use the AWS Console or a third-party tool like Cyberduck.
Go to S3, select your Retrospect bucket, navigate to your set, click on Properties, select "Reduced Redundancy, and click "Save".

Now we will create the security credentials it can use to access that bucket. To grant Retrospect more granular access to your S3 account, please see the Advanced Access Setup Guide.
Open the IAM console.
In the navigation pane, choose Users.
Choose your IAM user name (not the check box).
Choose the Security Credentials tab and then choose Create Access Key.
To see your access key, choose Show User Security Credentials. Your credentials will look something like this:
Access Key ID: AKIAIOSFODNN7EXAMPLE Secret Access Key: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
Choose Download Credentials, and store the keys in a secure location. Note that your secret key will no longer be available through the AWS Management Console; you will have the only copy. Keep it confidential in order to protect your account, and never email it. Do not share it outside your organization, even if an inquiry appears to come from AWS or Amazon.com. No one who legitimately represents Amazon will ever ask you for your secret key.
Go to IAM and click on "Users".

Click on "Create New Users".

Type in an appropriate username for Retrospect and click "Create". AWS will show you a set of credentials: an Access Key and a Secret Key. This is the only time AWS will show these, so download them to a safe place.

On the new user’s account, click "Inline Policy" and then "Create User Policy". We are going to restrict this user’s access to only the bucket we just created.

Choose "Custom Policy" and click "Select". Enter the following policy, replacing "your_bucket_name" with the name of the bucket you created.
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "s3:*"
            ],
            "Resource": [
                "arn:aws:s3:::your_bucket_name",
                "arn:aws:s3:::your_bucket_name/*"
            ]
        }
    ]
}
When you’re done, click "Validate Policy" then "Apply Policy". With this, Retrospect will have full access to that bucket but no access to anything else on S3 or other AWS services.
Retrospect needs three pieces of information to access Amazon S3:
Virtual-Host Path – your_bucket_name.s3.us-east-1.amazonaws.com
Access Key – Use the Access Key from above.
Secret Key – Use the Secret Key from above.
Note that for the new virtual-host path, the region is required. Otherwise, you will receive a "Host not found or network unavailable" error.
For the path, Amazon S3 supports different paths for its regions. Please see the following paths for the region you specified when creating the bucket:
Ireland – your_bucket_name.s3.eu-west-1.amazonaws.com
Sydney – your_bucket_name.s3.ap-southeast-2.amazonaws.com
Singapore – your_bucket_name.s3.ap-southeast-1.amazonaws.com
Tokyo – your_bucket_name.s3.ap-northeast-1.amazonaws.com
Sao Paulo – your_bucket_name.s3.sa-east-1.amazonaws.com
See Amazon S3 Regions/Endpoints for further details.
Note that if you use the default path of s3.amazonaws.com for a region outside of the United States, you may receive the following error: "These credentials are not valid". Please use the region-specific URL above to correct this.
Note that as of September 30, 2020, new buckets on S3 require virtual-host domains instead of path-style domains. Please see our KB article to learn more.
If you see error "Host not found or network unavailable", the issue could be that you are using a Retrospect version below 17.5 with a path-style domain. See screenshot.

Please upgrade to Retrospect 17.5 to use virtual-host domains.
Añadir el almacenamiento en la nube como destino es simple. Retrospect tiene un nuevo tipo de conjunto llamado "nube". Cree un nuevo conjunto de copia de seguridad/conjunto de medios y seleccione "nube" como tipo.
Interfaz de Windows

Interfaz de Mac

Next you’ll need to enter your cloud storage credentials. Retrospect allows customers to enable or disable SSL encryption (HTTP or HTTPS) and to set the maximum storage usage, up to 8TB per cloud member.
Interfaz de Windows

Interfaz de Mac

Usar el almacenamiento en la nube es simple. Después de haber creado un conjunto en la nube, cree una nueva secuencia de comandos o añádala a una ya existente y haga clic en "Ejecutar". La copia de seguridad se iniciará, siendo subido el contenido del conjunto a su lugar de almacenamiento en la nube. Puede hacer un seguimiento del progreso en la ejecución/actividad.
Interfaz de Windows

Interfaz de Mac

La limitación para la copia de seguridad en la nube y la restauración de la nube está disponible en Preferencias.
Interfaz de Windows

Interfaz de Mac

Below are a number of tips for using cloud storage in Retrospect:
Herramienta de medición de ancho de banda – Mida su ancho de banda de subida y bajada con esta herramienta gratuita: <a target="_blank" href="http://speedtest.net">Speedtest.net</a>.
Desactivar la verificación de copia de seguridad – La verificación descargará todos los datos que suba. Vea más detalles acerca de por qué debe desactivarla para las copias de seguridad en la nube en <a href="/la/support/kb/best_practices_for_cloud_storage#notes">Copia de seguridad en la nube: las mejores prácticas para la protección de datos con almacenamiento en la nube</a>.
Last Update: 21 de junio de 2021