Transcript
And that you could typically do it in less time than it takes to make a cup of coffee? Let me show you how Clumio's Terraform provider makes this possible. Traditionally, you'd first need to connect your AWS accounts, then configure policies, create protection rules and groups, and apply protection. But with Terraform, here's all we need. Four simple files. Let me show you what's inside. First, we tell Terraform we want to use Clumio and AWS. Think of these as the apps we're connecting together. The API token is stored securely in a separate file. Next, we establish the connection between Clumio and AWS. Similar to CloudFormation, the Clumio module is designed to handle the complex IAM roles and permissions automatically. Notice we're enabling protection for EC2, EBS, RDS databases, DynamoDB tables, and S3 buckets. It can help protect your critical data, all in one go. Here's where we define our backup policy. Notice how we can set different RPOs and retention for different resource types. Moreover, for DynamoDB, we've defined multiple retention tiers, 3 days and 30 days, giving us flexibility for different recovery scenarios. This single policy will automatically apply to all resources of each type, based on a condition that we will shortly set up. Now here's where it gets really powerful. This protection rule is designed to automatically find and protect any supported resource tagged with the key createdBy and the value demoscript, whether it exists now or gets created tomorrow. The protection group specifically manages all our production S3 buckets as a single unit, designed to make it easy to adjust policies for hundreds of buckets at once. Now the deployment begins. First, we initialize Terraform. Then, we preview what Terraform will do. Resources from both the Clumio module and the provider are planned out. And finally, Terraform is applied. Terraform automatically instantiates all the previously planned resources from both the Clumio module and the provider. Dependencies are also respected, meaning that everything is created in the correct order. Once complete, Terraform confirms success. And there we have it. All resources across four different AWS services are now protected according to the defined backup policy. The protection rule is active and the S3 protection group is managing our buckets. But here's what's really great. This entire configuration is now in code. Tomorrow, when your team adds more S3 buckets or spins up new databases with the same tag, they're automatically protected. But look at this. Our entire protection strategy is reusable and easily describable, all in one place. It's designed so anyone can understand what's protected and how, just by reading this single file. No clicking through multiple screens. No documentation drift. No guesswork. From zero to protected in minutes. Clumio's Terraform provider is designed so that your AWS infrastructure can be protected by one simple Terraform configuration. Complete with automatic protection for future resources. Ready to see how this scales to your environment? Microsoft Mechanics www.microsoft-mechanics.com