AWS datasync: Clarified DataSync agent requirements for Google Cloud Storage transfers
Summary
Updated agent deployment instructions and clarified when agents are required based on transfer mode (Basic/Enhanced).
Security assessment
The changes clarify operational requirements for agent deployment but contain no references to vulnerabilities, security features, or best practices. The modifications focus on task mode configurations without security implications.
Evidence
Most transfers require a DataSync agent.
Diff
diff --git a/datasync/latest/userguide/tutorial_transfer-google-cloud-storage.md b/datasync/latest/userguide/tutorial_transfer-google-cloud-storage.md index b4b566a3e..666863775 100644 --- a//datasync/latest/userguide/tutorial_transfer-google-cloud-storage.md +++ b//datasync/latest/userguide/tutorial_transfer-google-cloud-storage.md @@ -28 +28 @@ With AWS DataSync, you can transfer data between Google Cloud Storage and the fo -To begin the transfer setup, create a location for your Google Cloud Storage. This location can serve as either your transfer source or destination. A DataSync agent is required only when you transfer data between Google Cloud Storage and Amazon EFS or Amazon FSx, or when using **Basic mode** tasks. **Enhanced mode** data transfers between Google Cloud Storage and Amazon S3 don't require an agent. +To begin the transfer setup, create a location for your Google Cloud Storage. This location can serve as either your transfer source or destination. Most transfers require a DataSync agent. Transfers between Google Cloud Storage and Amazon S3 using **Enhanced mode** do not require an agent. Use the agent that corresponds to your task mode. @@ -32 +32 @@ To begin the transfer setup, create a location for your Google Cloud Storage. Th -For private cloud connectivity between Google Cloud Storage and AWS, use Basic mode with agents. +For private cloud connectivity between Google Cloud Storage and AWS, you need a DataSync agent. @@ -38 +38 @@ DataSync uses the [Google Cloud Storage XML API](https://cloud.google.com/storag -When you use Basic mode for transfers, you can deploy the agent in Google Cloud Storage or your Amazon VPC. +When you use an agent for transfers, you can deploy it in Google Cloud Storage or your Amazon VPC. @@ -148 +148 @@ To do this, modify the [security group](https://docs.aws.amazon.com/vpc/latest/u -A DataSync agent is only required when using **Basic** mode tasks. If you are using **Enhanced** mode to transfer between Google Cloud Storage (GCS) and Amazon S3, then no agent is required. If you want to use **Basic** mode, then you need a DataSync agent that can access your GCS bucket. +Most transfers require a DataSync agent. Transfers between Google Cloud Storage (GCS) and Amazon S3 using **Enhanced** mode do not require an agent. Use the agent that corresponds to your task mode. If you use an agent, it needs access to your GCS bucket. @@ -160 +160 @@ In this scenario, the DataSync agent runs in your Google Cloud environment. - 3. For **Hypervisor** , choose **VMware ESXi** , then choose **Download the image** to download a `.zip` file that contains the agent. + 3. For **Hypervisor** , choose **VMware ESXi** , then choose **Download the image**. @@ -162 +162,5 @@ In this scenario, the DataSync agent runs in your Google Cloud environment. - 4. Open a terminal. Unzip the image by running the following command: + * The Enhanced mode agent downloads as an `.ova` image file. + + * The Basic mode agent downloads in a `.zip` file that contains the `.ova` image file. + + 4. If you downloaded a Basic mode agent, open a terminal and unzip the image by running the following command: @@ -227 +231,3 @@ In this scenario, the agent runs as an Amazon EC2 instance in a VPC that's assoc - 2. Copy the following command. Replace ``vpc-region`` with the AWS Region where your VPC resides (for example, `us-east-1`). + 2. Copy one of the following commands, depending on your task mode. Replace ``vpc-region`` with the AWS Region where your VPC resides (for example, `us-east-1`). + +Basic mode agents @@ -230,0 +237,4 @@ In this scenario, the agent runs as an Amazon EC2 instance in a VPC that's assoc +Enhanced mode agents + + aws ssm get-parameter --name /aws/service/datasync/ami/v3 --region vpc-region +