Automatically managing access policies for archived objects
An archival storage of data backed up from a repository storage of a primary storage is maintained. Access to data stored in archival storage is limited by one or more access policies based on whether a corresponding data restore has been authorized. A request for specific data stored in the archival storage is received. The one or more access policies are automatically managed based on status and timing of one or more data restore authorizations for the specific data stored in the archival storage.
1 . A method, comprising:
receiving a request to perform a restore operation to restore data stored in an archival storage, wherein the data is not associated with an access policy that limits access to the data;
determining that the request to perform the restore operation is an authorized request;
determining an expected duration for performing the restore operation;
automatically generating, based on the authorized request, a temporary access policy associated with the data and usable to access the data for performing the restore operation, wherein the temporary access policy is valid for the expected duration for performing the restore operation;
performing, based on the temporary access policy, the restore operation; and
terminating, based on the expected duration elapsing, access to the data provided by the temporary access policy.
2 . The method of claim 1 , wherein the request to perform the restore operation to restore data is for one or more objects associated with one or more archived backup snapshots.
3 . The method of claim 1 , wherein the request to perform the restore operation to restore the data includes a particular prefix associated with a storage location for the data.
4 . The method of claim 1 , further comprising: providing the temporary access policy to a cloud storage provider that uses the temporary access policy to determine whether to permit or deny access to the data.
5 . The method of claim 1 , further comprising: providing, to a user device associated with the request to perform the restore operation to restore the data, a notification that the request has been approved.
6 . The method of claim 1 , further comprising receiving a request for credentials to access the data stored in the archival storage.
7 . The method of claim 6 , further comprising validating a storage system from which the request for the credentials to access the data stored in the archival storage is received.
8 . The method of claim 7 , further comprising denying the request for the credentials to access the data stored in the archival storage in response to a determination that the storage system is not validated.
9 . The method of claim 7 , further comprising creating credentials to access the data stored in the archival storage in response to a determination that the storage system is validated.
10 . The method of claim 9 , wherein the credentials are valid for a limited period of time.
11 . The method of claim 9 , further comprising providing, to the storage system, the credentials to access the data stored in the archival storage to the storage system.
12 . The method of claim 11 , wherein the storage system utilizes the provided credentials to access the data stored in the archival storage.
13 . The method of claim 7 , wherein the storage system manages the archival storage.
14 . The method of claim 7 , wherein the storage system is a different storage system than the storage system that manages the archival storage.
15 . The method of claim 1 , wherein determining that the request to perform the restore operation is an authorized request comprises performing a quorum approval process.
16 . The method of claim 1 , wherein determining that the request to perform the restore operation is an authorized request is based on status and timing of one or more authorizations.
17 . Computer-readable storage media comprising instructions that, when executed by processing circuitry, cause the processing circuitry to:
receive a request to perform a restore operation to restore data stored in an archival storage, wherein the data is not associated with an access policy that limits access to the data;
determine that the request to perform the restore operation is an authorized request;
determine an expected duration for performing the restore operation;
automatically generate, based on authorized request, a temporary access policy associated with the data and usable to access the data for performing the restore operation, wherein the temporary access policy is valid for the expected duration for performing the restore operation;
perform, based on the temporary access policy, the restore operation; and
terminate, based on the expected duration elapsing, access to the data provided by the temporary access policy.
18 . A management system, comprising:
one or more processors coupled to memory, the one or more processors and memory configured to:
receive a request to perform a restore operation to restore data stored in an archival storage, wherein the data is not associated with an access policy that limits access to the data;
determine that the request to perform the restore operation is an authorized request;
determine an expected duration for performing the restore operation;
automatically generate, based on the authorized request, a temporary access policy associated with the data and usable to access the data for performing the restore operation, wherein the temporary access policy is valid for the expected duration for performing the restore operation;
perform, based on the temporary access policy, the restore operation; and
terminate, based on the expected duration elapsing, access to the data provided by the temporary access policy.