Veeam Backup for AWS leverages worker instances to carry out various data protection and disaster recovery operations, including the creation and removal of EC2 image-level backups, data restoration, and EFS indexing. These worker instances are launched in a specific AWS Region during the backup, restore, and retention process. For more information regarding the AWS Regions in which Veeam Backup for AWS launches worker instances to execute operations, refer to the Architecture Overview documentation.
By default, Veeam Backup for AWS uses the permissions of the Default Backup Restore role to launch worker instances — the role is preconfigured and has all the required permissions. However, you can specify another IAM role to change the backup account (see Adding IAM Role for more information).
We are going to use the default role for this workshop.
For each Availability Zone in which worker instances will be launched, you can configure specific network settings:
At the Network step of the wizard, select an Amazon VPC and a subnet to which you want to connect worker instances, and specify a security group that must be associated with the instances.