Cloud-native data protection with AWS Backup
This reference architecture describes how AWS Backup is implemented in a single AWS account to protect multiple services in an automated way.
-
Use AWS CloudFormation to create the components that AWS Backup uses in this architecture.
-
The AWS Backup plan defines the frequency, retention period, lifecycle, backup copy destination, and resources to protect.
-
The AWS Backup vault is a logical container that stores and organizes your backups. A defined AWS KMS key enforces encryption.
-
A backup job runs within the backup window defined in the backup plan. After the job completes, a recovery point appears in the vault for restore.
-
Secure access to your resources through IAM by using AWS-managed policies as a starting point. At the vault level, access policies protect the vault and its contents.
-
AWS Backup actions record in CloudTrail as events.
-
Monitor AWS Backup service metrics through CloudWatch.
-
Use https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-what-is.html to monitor AWS Backup events, such as when a backup fails or gets deleted.
-
Audit backups and automate reports through AWS Backup Audit Manager. With this service, you can continuously monitor compliance of your backups.
Further reading
For additional information, refer to
Diagram history
To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Initial publication | Reference architecture diagram first published. | July 29, 2022 |
Reference architecture diagram first published. | July 29, 2022 | |
Reference architecture diagram first published. | July 29, 2022 | |
Reference architecture diagrams first published. | July 29, 2022 |
Note
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.