Review the following requirements before you configure protection for Google Cloud instances.
Commvault packages
Access Nodes for Google Cloud instances must have the Virtual Server package installed.
Access Node requirements
You must have at least one Commvault Access Node on a Google Cloud Compute Engine instance to back up resources from one or more Google Cloud projects.
Access Nodes must meet the following requirements:
-
Access Nodes must be hosted in Google Cloud.
-
An Access Node can protect instances in multiple projects when the service accounts have the required access to those projects.
-
The Access Node can reside in a project in the same or a different organization from the protected project.
-
To protect disks encrypted with customer-managed encryption keys (CMEKs), the Access Node must reside in the same organization as the protected resources.
-
For faster backup and restore operations, use at least one Access Node for each Google Cloud region.
Service account impersonation prerequisites
To use instance-attached authentication with service account impersonation, attach a service account to the Access Node instance.
The Access Node service account must have permission to impersonate the backup, restore, and storage service accounts that are configured for the target projects.
For the required permissions and service account bindings, see Service account permissions for Google Cloud.
Google Cloud APIs and services
For service account impersonation, enable the IAM Credentials API (iamcredentials.googleapis.com).
Commvault uses the IAM Credentials API to generate short-lived access tokens for the service accounts that the Access Node impersonates.
The following APIs and services are required to protect Google Cloud resources:
You can enable the required APIs from an authorized gcloud shell. For example:
gcloud services enable [service-name]
The service names include:
iam.googleapis.com
compute.googleapis.com
cloudresourcemanager.googleapis.com
cloudkms.googleapis.com
kmsinventory.googleapis.com
storage.googleapis.com
For service account impersonation, enable the IAM Credentials API:
iamcredentials.googleapis.com
Commvault uses the IAM Credentials API to generate short-lived access tokens for the service accounts that the Access Node impersonates.
You must enable the Cloud Resource Manager API. Backup jobs fail if this API isn't enabled.
Requirements for protecting resources across projects
An Access Node can protect resources in multiple Google Cloud projects when the required access is configured.
With service account impersonation, the Access Node service account must be able to impersonate the backup, restore, and storage service accounts configured for each target project. Each target service account must have the permissions required for its operation in that project.
Some operations require access to resources in another project, such as creating a disk from a snapshot or accessing resources that use customer-managed encryption keys. For these operations, the applicable backup or restore service account must have access to the required cross-project resources.
For the required permissions and cross-project service account bindings, see Service account permissions for Google Cloud.
Operating system support
Access Nodes for Google Cloud instances must run a supported operating system.
Linux
You can use an Access Node that runs one of the following operating systems:
-
Rocky Linux 9.x or 8.x
-
Red Hat Enterprise Linux 9.x or 8.x
-
Oracle Linux 9.x or 8.x
Rocky Linux is recommended.
Red Hat Enterprise Linux 7.x and Oracle Linux 7.x have reached end of life and receive best-effort support.
Windows
You can use the following Microsoft Windows Server editions:
-
Microsoft Windows Server 2025 x64
-
Microsoft Windows Server 2022 x64
-
Microsoft Windows Server 2019 x64
-
Microsoft Windows Server 2016 x64
Standard, Datacenter, and Server Core editions are supported.
Firewall requirements
Configure the network so that the Access Node can communicate with the Google Cloud services required for backup and restore operations.
Allow access to the following endpoints:
https://compute.googleapis.com/compute/v1/projects
https://content-cloudkms.googleapis.com/v1
https://cloudresourcemanager.googleapis.com/v1
https://storage.googleapis.com
https://storage.googleapis.com/storage/v1/b
https://storage.googleapis.com/upload/storage/v1/b
For service account impersonation, allow the Access Node to connect to the following endpoint:
https://iamcredentials.googleapis.com
Commvault uses the IAM Credentials endpoint to request short-lived access tokens for the target service accounts.
Tunnel ports, such as 8400 and 8403, must be open for communication between the Access Node and the CommServe computer when required by your network topology.
If the CommServe computer and Access Node are separated by a firewall, configure the required network route between them.
Hardware requirements
For Access Node hardware requirements, see Hardware Specifications for Virtual Server Agent.