Skip to content

Commit e7de064

Browse files
Merge pull request #4370 from ovh/HB-RACI-Object-storage
Hb raci object storage
2 parents ea40a12 + dfb03b7 commit e7de064

File tree

6 files changed

+285
-0
lines changed

6 files changed

+285
-0
lines changed

pages/account/responsibility-sharing/product.en-gb.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ order: 6
1414
>
1515
> - [RACI Public Cloud Instances](https://docs.ovh.com/gb/en/public-cloud/raci-instances-public-cloud/)
1616
>
17+
> - [RACI Public Cloud Object Storage](https://docs.ovh.com/gb/en/storage/object-storage/s3/raci-object-storage-public-cloud/)
18+
>
1719
> - [RACI Block Storage](https://docs.ovh.com/gb/en/public-cloud/raci-block-storage-public-cloud/)
1820
>
1921
> - [RACI Log Data Platform](https://docs.ovh.com/gb/en/logs-data-platform/responsibility-model/)

pages/account/responsibility-sharing/product.fr-fr.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ order: 6
1414
>
1515
> - [RACI Public Cloud Instances](https://docs.ovh.com/fr/public-cloud/raci-instances-public-cloud/)
1616
>
17+
> - [RACI Public Cloud Object Storage](https://docs.ovh.com/fr/storage/object-storage/s3/raci-object-storage-public-cloud/)
18+
>
1719
> - [RACI Block Storage](https://docs.ovh.com/fr/public-cloud/raci-block-storage-public-cloud/)
1820
>
1921
> - [RACI Log Data Platform](https://docs.ovh.com/fr/logs-data-platform/responsibility-model/)
Lines changed: 139 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,139 @@
1+
---
2+
title: "Object Storage - Shared Responsibility RACI"
3+
slug: s3/raci-object-storage-public-cloud
4+
section: General information
5+
excerpt: "Shared responsibilities between OVHcloud and the customer for Public Cloud Object Storage"
6+
order: 030
7+
updated: 2023-03-20
8+
---
9+
10+
**Last update 20th March 2023**
11+
12+
## Objectif
13+
14+
The RACI below details shared responsibilities between OVHcloud and the customer for the Public Cloud Object Storage service. This shared model can help relieve the customer’s operational burden for the following service ranges :
15+
16+
- Standard Object Storage-S3 API
17+
- High Performance Object Storage-S3 API
18+
- Standard Object Storage-Swift API
19+
20+
| Roles |
21+
| --- |
22+
|R : Is in charge of carrying out the process|
23+
|A : Accountable for the successful completion of the process|
24+
|C : Is consulted during the process|
25+
|I : Is informed of the results of the process|
26+
27+
### 1. Before subscription
28+
29+
#### 1.1. Specify service as needed
30+
31+
| **Activity** | **Customer** | **OVHcloud** |
32+
| --- | --- | --- |
33+
| Choose the Object Storage container service range following business needs (SWIFT, S3 High Speed, S3 Standard, ...) | RA | I |
34+
| Provide personal data needed for service subscription | RA | I |
35+
| Choose service location| RA | I |
36+
37+
### 2. Service availability
38+
39+
#### 2.1. Install the service
40+
41+
| **Activity** | **Customer** | **OVHcloud** |
42+
| --- | --- | --- |
43+
| Produce, route, deliver and maintain physical Instances and hosting buldings | I | RA |
44+
45+
#### 2.2. Customer Information System setup
46+
47+
| **Activity** | **Customer** | **OVHcloud** |
48+
| --- | --- | --- |
49+
| Create S3 credentials for an OpenStack user | RA | |
50+
51+
### 3. Service usage
52+
53+
#### 3.1. Operations
54+
55+
##### **3.1.1. Daily operations**
56+
57+
| **Activity** | **Customer** | **OVHcloud** |
58+
| --- | --- | --- |
59+
| Provide and manage Containers and objects' accessibility | | RA |
60+
| Manage Containers and objects' security created (object lock, SSE-C, etc ... | RA | |
61+
| Administrate service storage | I | RA |
62+
| Administrate data | RA | |
63+
| Manage backups | RA | |
64+
65+
##### **3.1.2. Access management**
66+
67+
| **Activity** | **Customer** | **OVHcloud** |
68+
| --- | --- | --- |
69+
| Manage access rights to the OVHcloud Control Panel | RA | I |
70+
| Manage physical and logical access to infrastructures for OVHcloud teams | | RA |
71+
| Manage S3 security policy of containers and object created | RA | |
72+
73+
##### **3.1.3. Monitoring**
74+
75+
| **Activity** | **Customer** | **OVHcloud** |
76+
| --- | --- | --- |
77+
| Manage and monitor physical servers in support of the Object Storage service | | RA |
78+
| Retain logs of the Object Storage service | | RA |
79+
| Monitor the proper functioning of physical devices (utilities) in support of the service | I | RA |
80+
| Create, modify, control, restore, delete backups | RA | |
81+
| Maintain storage devices used for the service | | RA |
82+
83+
##### **3.1.4. Storage**
84+
85+
| **Activity** | **Customer** | **OVHcloud** |
86+
| --- | --- | --- |
87+
| Manage data encryption before importing in the Object Storage | RA | |
88+
| Manage data encryption on the allowed storage space using SSE-C and with encryption keys provided by the Client | A | R |
89+
90+
##### **3.1.5. Management**
91+
92+
| **Activity** | **Customer** | **OVHcloud** |
93+
| --- | --- | --- |
94+
| Provide inventory of containers and objects used | I | RA |
95+
| Manage the security of management infrastructure (API, control plane) | | RA |
96+
| Manage physical security of equipments and hosted infrastructures | I | RA |
97+
98+
##### **3.1.6. Business continuity**
99+
100+
| **Activity** | **Customer** | **OVHcloud** |
101+
| --- | --- | --- |
102+
| Perform periodic restoration tests | RA | |
103+
| Maintain a business continuity and disaster recovery plan for the hosted IS | RA | |
104+
| Manage automatic management systems for the infrastructure provided | I | RA |
105+
106+
#### 3.2. Event management
107+
108+
##### **3.2.1. Incidents**
109+
110+
| **Activity** | **Customer** | **OVHcloud** |
111+
| --- | --- | --- |
112+
| Process incidents on the service (tickets and contacts) | AI | RA |
113+
| Replace faulty hardware on physical servers of Object Storage clusters | | RA |
114+
115+
### 4. Reversibility
116+
117+
#### 4.1. Reversibility Model
118+
119+
| **Activity** | **Customer** | **OVHcloud** |
120+
| --- | --- | --- |
121+
| Plan reversibility operations | RA | |
122+
| Choose fallback infrastructures | RA | CI |
123+
| Choose data format to export | RA | |
124+
125+
#### 4.2. Data recovery
126+
127+
| **Activity** | **Customer** | **OVHcloud** |
128+
| --- | --- | --- |
129+
| Manage reversibility operations | RA | |
130+
| Migrate/transfer data | RA | |
131+
132+
### 5. End of service
133+
134+
#### 5.1. Data destruction
135+
136+
| **Activity** | **Customer** | **OVHcloud** |
137+
| --- | --- | --- |
138+
| Destroy data from the Object Storage Containers Service via API S3 | RA | |
139+
| Destroy end-of-life storage devices | | RA |
Lines changed: 139 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,139 @@
1+
---
2+
title: "Object Storage - Partage des responsabilités (RACI)"
3+
slug: s3/raci-object-storage-public-cloud
4+
section: Informations générales
5+
excerpt: "RACI entre OVHcloud et le client pour l'utilisation du Object Storage Public Cloud"
6+
order: 030
7+
updated: 2023-03-20
8+
---
9+
10+
**Dernière mise à jour le 20/03/2023**
11+
12+
## Objectif
13+
14+
Le RACI ci-dessous détaille le partage des responsabilités entre OVHcloud et le client pour le service Object Storage Public Cloud. Ce modèle peut aider le client à utiliser au mieux les gammes de services suivantes :
15+
16+
- Standard Object Storage-S3 API
17+
- High Performance Object Storage-S3 API
18+
- Standard Object Storage-Swift API
19+
20+
| Rôles |
21+
| --- |
22+
|R : Est en charge de la **R**éalisation du processus|
23+
|A : Est **A**pprobateur de la réalisation du processus|
24+
|C : Est **C**onsulté pendant le processus|
25+
|I : Est **I**nformé des résultats du processus|
26+
27+
### 1. Avant la souscription
28+
29+
#### 1.1. Spécifier le service en fonction des besoins
30+
31+
| **Activité** | **Client** | **OVHcloud** |
32+
| --- | --- | --- |
33+
| Choisir la gamme de Conteneur Object Storage en fonction des besoins (SWIFT, S3 High Speed, S3 Standard, ...)| RA | I |
34+
| Renseigner les données à caractère personnel nécessaires pour la souscription au service | RA | I |
35+
| Choisir la localisation du service| RA | I |
36+
37+
### 2. Mise à disposition du service
38+
39+
#### 2.1. Installer le service
40+
41+
| **Activité** | **Client** | **OVHcloud** |
42+
| --- | --- | --- |
43+
| Produire, acheminer, livrer et maintenir les instances physiques et les bâtiments d’hébergement | I | RA |
44+
45+
#### 2.2. Installation du SI client
46+
47+
| **Activité** | **Client** | **OVHcloud** |
48+
| --- | --- | --- |
49+
| Créer les identifiants de connexion S3 pour un utilisateur OpenStack | RA | |
50+
51+
### 3. Utilisation du service
52+
53+
#### 3.1. Opérations
54+
55+
##### **3.1.1. Opérations quotidiennes**
56+
57+
| **Activité** | **Client** | **OVHcloud** |
58+
| --- | --- | --- |
59+
| Fournir, gérer l'accessibilité des conteneurs et objets | | RA |
60+
| Gérer la sécurité des conteneurs et objets créés (object lock, SSE-C, etc) | RA | |
61+
| Administrer le service de stockage | I | RA |
62+
| Administrer les données | RA | |
63+
| Réaliser les backups | RA | |
64+
65+
##### **3.1.2. Gestion des accès**
66+
67+
| **Activité** | **Client** | **OVHcloud** |
68+
| --- | --- | --- |
69+
| Gérer l’accès à l'interface de gestion (espace client OVHcloud) | RA | I |
70+
| Gérer les accès physiques et logiques des équipes OVHcloud aux infrastructures | | RA |
71+
| Gérer la sécurité logique (politique de sécurité S3) des conteneurs et objets créés | RA | |
72+
73+
##### **3.1.3. Monitoring**
74+
75+
| **Activité** | **Client** | **OVHcloud** |
76+
| --- | --- | --- |
77+
| Gérer et monitorer la capacité des serveurs physiques utilisés pour le Service Object Storage | | RA |
78+
| Conserver les logs du Service Object Storage| | RA |
79+
| Monitorer le bon fonctionnement des dispositifs physiques en support du stockage| I | RA |
80+
| Créer, modifier, contrôler, restaurer, supprimer les backups | RA | |
81+
| Réaliser la maintenance des dispositifs de stockage fournis | | RA |
82+
83+
##### **3.1.4. Stockage**
84+
85+
| **Activité** | **Client** | **OVHcloud** |
86+
| --- | --- | --- |
87+
| Gérer le chiffrement des données avant le dépôt sur l'Object Storage | RA | |
88+
| Gérer le chiffrement des données sur l'espace de stockage alloué en utilisant SSE-C et avec les clés fournies par le Client | A | R |
89+
90+
##### **3.1.5. Gestion**
91+
92+
| **Activité** | **Client** | **OVHcloud** |
93+
| --- | --- | --- |
94+
| Fournir l'inventaire sur les conteneurs et objets créés | I | RA |
95+
| Gérer la sécurité de l'infrastructure de gestion (API, control plane) | | RA |
96+
| Gérer la sécurité physique des équipements et infrastructures hébergés | I | RA |
97+
98+
##### **3.1.6. Continuité d'activité**
99+
100+
| **Activité** | **Client** | **OVHcloud** |
101+
| --- | --- | --- |
102+
| Réaliser des tests périodiques de restauration de données | RA | |
103+
| Maintenir un plan de continuité d’activité et de reprise d’activité pour le SI hébergé | RA | |
104+
| Gérer les systèmes de gestion automatiques de l’infrastructure mise à disposition | I | RA |
105+
106+
#### 3.2. Gestion des évènements
107+
108+
##### **3.2.1. Incidents**
109+
110+
| **Activité** | **Client** | **OVHcloud** |
111+
| --- | --- | --- |
112+
| Traiter les incidents sur le service (tickets et contacts téléphoniques) | AI | RA |
113+
| Remplacer les éléments matériels défectueux sur les clusters Object Storage | | RA |
114+
115+
### 4. Réversibilité
116+
117+
#### 4.1. Modèle de réversibilité
118+
119+
| **Activité** | **Client** | **OVHcloud** |
120+
| --- | --- | --- |
121+
| Planifier les opérations de réversibilité | RA | |
122+
| Choisir les infrastructures de repli | RA | CI |
123+
| Choisir le format des données à exporter | RA | |
124+
125+
#### 4.2. Récupération des données
126+
127+
| **Activité** | **Client** | **OVHcloud** |
128+
| --- | --- | --- |
129+
| Gérer les opérations de réversibilité | RA | |
130+
| Migrer / transférer les données | RA | |
131+
132+
### 5. Fin de service
133+
134+
#### 5.1. Destruction des données
135+
136+
| **Activité** | **Client** | **OVHcloud** |
137+
| --- | --- | --- |
138+
| Supprimer les données du Service Conteneurs Object Storage via les API S3 | RA | |
139+
| Détruire les supports de stockage arrivés en fin de vie ou sur lesquels le processus de destruction sécurisé génère des erreurs | | RA |
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
id: 6db98c2f-6c86-4877-b3ac-60450763544d
2+
full_slug: public-cloud-storage-shared-responsibility

pages/index.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1458,6 +1458,7 @@
14581458
+ [Object Storage - S3 Compliancy](cloud/storage/object_storage/s3_s3_compliancy)
14591459
+ [Object Storage - Technical Limitations](cloud/storage/object_storage/s3_limitations)
14601460
+ [Object Storage - Endpoints and Object Storage geoavailability](cloud/storage/object_storage/s3_location)
1461+
+ [Object Storage - Shared Responsibility RACI](cloud/storage/object_storage/s3_object_storage_responsibility_model)
14611462
+ [General guides to start](storage-object-storage-general-guides-to-start)
14621463
+ [Object Storage - Getting started with Object Storage](cloud/storage/object_storage/s3_getting_started_with_object_storage)
14631464
+ [Object Storage - Identity and access management](cloud/storage/object_storage/s3_identity_and_access_management)

0 commit comments

Comments
 (0)