Planning
Permissions
Platform roles and privileges Datamotive needs on VMware, AWS, GCP, and Azure to orchestrate replication, DR, and migration workflows.
- Product
- Easy Hybrid DR
- Version
- v2.0.3
- Last updated
- Updated
- Reading time
- 3 min read
Datamotive nodes integrate with platform managers (vCenter Server, AWS, GCP, Azure) through their APIs to orchestrate replication, DR, and migration workflows. Create a dedicated role or principal per platform with the privileges below — on both the protected and the recovery site.
Create a dedicated vCenter role with the following privilege groups and assign it to the Datamotive service user on both sites:
- Datastore — Allocate space · Low level file operations · Browse datastore
- Global — Enable methods · Disable methods
- Host › Local operations — Create virtual machine · Delete virtual machine · Reconfigure virtual machine
- Network — Assign network
- Resource — Assign virtual machine to resource pool · Migrate powered off virtual machine
- Virtual machine › Change Configuration — Add existing disk · Add new disk · Add or remove device · Advanced configuration · Change CPU count · Change Memory · Change Settings · Change Swapfile placement · Configure Host USB device · Configure Raw device · Extend virtual disk · Modify device settings · Remove disk · Rename · Toggle disk change tracking
- Virtual machine › Edit Inventory — Create from existing · Create new · Move · Register · Remove
- Virtual machine › Interaction — Connect devices · Create screenshot · Power off · Power on · Reset
- Virtual machine › Provisioning — Allow disk access · Allow file access · Allow read-only disk access · Allow virtual machine download · Clone template · Clone virtual machine · Customize guest · Modify customization specification · Read customization specifications
- Virtual machine › Snapshot management — Create snapshot · Remove snapshot · Rename snapshot · Revert to snapshot
- vSphere Replication — Configure replication · Manage replication
- vSphere Tagging — Select all
Toggle disk change tracking is required so Datamotive can enable Changed Block Tracking (CBT) on protected VMs.
Console users and roles
Platform permissions above are separate from Datamotive's own user management. Console users, roles, and SAML single sign-on are covered in RBAC.
Related docs
Was this page helpful?
