---
title: RDS Backups Solution brief
description: Automated Daily RDS Backups Saved in a Backup Account
image: https://lp.cloudride.co.il/hubfs/AWS%20Backup%20Centrally-Managed%20Backup%20for%20the%20Amazon%20Cloud%20-%20Blog%20(1)-1.png
---

[![cloudride-final-logo-3](https://lp.cloudride.co.il/hs-fs/hubfs/cloudride-final-logo-3.png?width=152&height=60&name=cloudride-final-logo-3.png "cloudride-final-logo-3")](http://www.cloudride.co.il)

![logo-website-white](https://lp.cloudride.co.il/hs-fs/hubfs/logo-website-white.png?width=340&height=135&name=logo-website-white.png "logo-website-white")

- [Company](http://www.cloudride.co.il) 
    - [About Us](http://www.cloudride.co.il/about-cloudride)
    - [Careers](http://www.cloudride.co.il/career)
    - [Contact Us](http://www.cloudride.co.il/contact-us)
    - [News & Event](http://www.cloudride.co.il/news-events)
- [Services](http://www.cloudride.co.il/services) 
    - Cloud Vendors 
          - [AWS Cloud Services](https://lp.cloudride.co.il/aws-cloud-expert) 
                  - [AWS for SMBs](https://lp.cloudride.co.il/aws_for_smbs)
                  - [AWS for the Public Sector](https://lp.cloudride.co.il/aws-for-the-public-sector)
          - [Azure Cloud Services](https://lp.cloudride.co.il/azure-landing-page)
    - Simplified 
          - [Cloud Migration](https://lp.cloudride.co.il/cloud-migration-services)
          - [Cloud Computing](https://lp.cloudride.co.il/cloud-computing-services)
          - [Kubernetes Experts](https://lp.cloudride.co.il/kubernetes-experts)
          - [Lambda as a Service](https://lp.cloudride.co.il/lambda-as-a-services)
    - Agile 
          - [Cloud Security](https://lp.cloudride.co.il/advanced-cloud-security-services)
          - [DevOps as a Service](https://lp.cloudride.co.il/devops-as-a-service)
    - Cost Effective 
          - [Cost Optimization & FinOps](https://lp.cloudride.co.il/finops-as-a-service)
          - [Windows Workloads](https://lp.cloudride.co.il/aws_for_windows_workloads)
- [Industries](http://www.cloudride.co.il/industries) 
    - [Financial Services](https://lp.cloudride.co.il/financial_services)
    - [Education](https://lp.cloudride.co.il/cloud-solutions-for-education)
    - [HealthCare](https://lp.cloudride.co.il/cloud-services-for-healthcare)
    - [High-Tech](https://lp.cloudride.co.il/cloud-services-for-high-tech)
    - [Media & Internet](https://lp.cloudride.co.il/cloud-services-for-internet-media)
- [Partners](http://www.cloudride.co.il/cloudride-partners)
- [Resources](http://www.cloudride.co.il/resource)
- [Blog](http://www.cloudride.co.il/blog)

[![Book A Meeting](https://no-cache.hubspot.com/cta/default/6762594/4b6a9933-e9dc-44a9-b43f-63aaeb2d2eb1.png)](https://cta-redirect.hubspot.com/cta/redirect/6762594/4b6a9933-e9dc-44a9-b43f-63aaeb2d2eb1)

# Automated Daily RDS Backups Saved in a Backup Account

Today, data is more important than ever to companies. Using the right tools and skills, the data can help companies make a lot of money by knowing their customers better and making their products fit exactly to them. Saving the data is important and can be mission-critical for companies as well. Some data is stored in an objective manner in Storage like S3 Buckets, and other data is stored in Databases.

 

**The Challenge**

The challenge had to do with Backups for our Database. According to a security concern, backups of our data needed to be saved in a private, different location than the main account resources and be kept safely. These backups need to be automated using a cron expression so that no human action is needed, and the backups need to remain highly available for the entire retention time.

 

Prerequisites for this Solution

Have a different account for storing the backups with the trust relationship between the accounts (using AWS Organizations or any other way you'll like).

 

The Solution

Using AWS Backup, we defined a vault and a backup plan to back up the RDS daily to the Vault. The backups are encrypted using an AWS KMS key and stored for 7 days. When a backup is completed, a CloudWatch Event is triggered, and it calls a Lambda function that triggers an Export to S3 operation for that snapshot. The S3 Bucket is encrypted at rest and has a replication rule to replicate the data to a second AWS Account's S3 Bucket using the same Encryption Key.

 

AWS Backup Rule:  
Backup rule name  
daily-backup  
Frequency  
Daily  
At 05:00 AM UTC  
Start within  
8 hours  
Complete within  
7 days  
Lifecycle  
Never transition to cold storage  
Expire after 1 week  
Backup vault  
pdq-backup-vault  
Tags added to recovery points  
–

Event Configuration:  
{  
"source": \[  
"aws.backup"  
\],  
"detail-type": \[  
"Backup Job State Change"  
\],  
"detail": {  
"backupVaultName": \[  
"pdq-backup-vault"  
\],  
"state": \[  
"COMPLETED"  
\]  
}  
}

Lambda  
Lambda Configuration  
{  
"Configuration": {  
"FunctionName": "copyBackupSnapshot",  
"FunctionArn": "arn:aws:lambda:us-east-2:123456789:function:copyBackupSnapshot",  
"Runtime": "python3.8",  
"Role": "arn:aws:iam::123456789:role/service-role/copyBackupSnapshot-role-{hash}",  
"Handler": "lambda\_function.lambda\_handler",  
"CodeSize": 557,  
"Description": "Used to copy snapshots from AWS backup to an S3 cross account replication bucket",  
"Timeout": 3,  
"MemorySize": 128,  
"LastModified": "2021-08-16T12:25:26.595+0000",  
"CodeSha256": "hash,  
"Version": "$LATEST",  
"TracingConfig": {  
"Mode": "PassThrough"  
},  
"RevisionId": "id",  
"State": "Active",  
"LastUpdateStatus": "Successful",  
"PackageType": "Zip"  
}  
}

Lamda Code  
import json  
import boto3  
import time  
from datetime import datetime  
CMK\_ARN = "kms-arn"  
now = datetime.now()  
currentTime = now.strftime("%d-%m-%Y-%H-%M-%S")

def lambda\_handler(event, context):  
client = boto3.client('rds')  
snapshotArn = event\["resources"\]\[0\]  
response = client.start\_export\_task(  
ExportTaskIdentifier="backup" + currentTime,  
SourceArn=snapshotArn,  
S3BucketName='rds-cross-account-snapshots-backup',  
IamRoleArn='role-that-allows-lambda-to-write-to-s3,  
KmsKeyId=CMK\_ARN,  
)

return {  
'statusCode': 200,  
'body': response\["Status"\]  
}

Lambda Role  
The lambda Role must have the following policy to use the KMS Key:  
{  
"Version": "2012-10-17",  
"Statement": \[  
{  
"Sid": "AllowUseOfCMKInAccount111122223333",  
"Effect": "Allow",  
"Action": \[  
"kms:Encrypt",  
"kms:Decrypt",  
"kms:ReEncrypt\*",  
"kms:GenerateDataKey\*",  
"kms:DescribeKey"  
\],  
"Resource": \[  
"arn:aws:kms:us-east-2:123456789:key/key\_Id"  
\]  
}  
\]  
}  
Write-to-S3-Role  
The role the lambda will invoke when dumping the backup to S3 will need this policy:  
{  
"Version": "2012-10-17",  
"Statement": \[  
{  
"Sid": "VisualEditor0",  
"Effect": "Allow",  
"Action": \[  
"s3:ListStorageLensConfigurations",  
"s3:ListAccessPointsForObjectLambda",  
"s3:GetAccessPoint",  
"s3:PutAccountPublicAccessBlock",  
"s3:GetAccountPublicAccessBlock",  
"s3:ListAllMyBuckets",  
"s3:ListAccessPoints",  
"s3:ListJobs",  
"s3:PutStorageLensConfiguration",  
"s3:CreateJob"  
\],  
"Resource": "\*"  
},  
{  
"Sid": "VisualEditor1",  
"Effect": "Allow",  
"Action": "s3:\*",  
"Resource": \[  
"arn:aws:s3:::\*/\*",  
"arn:aws:s3:::rds-cross-account-snapshots-backup"  
\]  
}  
\]  
}

Shared Account KMS Key Conf:  
{  
"Id": "key-consolepolicy-3",  
"Version": "2012-10-17",  
"Statement": \[  
{  
"Sid": "Enable IAM User Permissions",  
"Effect": "Allow",  
"Principal": {  
"AWS": "arn:aws:iam::123456789:root"  
},  
"Action": "kms:\*",  
"Resource": "\*"  
},  
{  
"Sid": "Allow access for Key Administrators",  
"Effect": "Allow",  
"Principal": {  
"AWS": \[  
"arn:aws:iam::123456789:user/name"  
\]  
},  
"Action": \[  
"kms:Create\*",  
"kms:Describe\*",  
"kms:Enable\*",  
"kms:List\*",  
"kms:Put\*",  
"kms:Update\*",  
"kms:Revoke\*",  
"kms:Disable\*",  
"kms:Get\*",  
"kms:Delete\*",  
"kms:TagResource",  
"kms:UntagResource",  
"kms:ScheduleKeyDeletion",  
"kms:CancelKeyDeletion"  
\],  
"Resource": "\*"  
},  
{  
"Sid": "Allow use of the key",  
"Effect": "Allow",  
"Principal": {  
"AWS": \[  
"arn:aws:iam::123456789:user/tomere",  
"arn:aws:iam::123456789:role/service-role/copyBackupSnapshot-role-{hash}",  
"arn:aws:iam::123456789:role/service-role/s3crr\_role\_for\_rds-cross-account-snapshots-backup",  
"arn:aws:iam::123456789:role/service-role/AWSBackupDefaultServiceRole",  
"arn:aws:iam::123456789:role/Admin\_\_SSO",  
"arn:aws:iam::987654321:root"  
\]  
},  
"Action": \[  
"kms:Encrypt",  
"kms:Decrypt",  
"kms:ReEncrypt\*",  
"kms:GenerateDataKey\*",  
"kms:DescribeKey"  
\],  
"Resource": "\*"  
},  
{  
"Sid": "Allow attachment of persistent resources",  
"Effect": "Allow",  
"Principal": {  
"AWS": \[  
"arn:aws:iam::123456789:role/service-role/copyBackupSnapshot-role-{hash}",  
"arn:aws:iam::123456789:role/service-role/s3crr\_role\_for\_rds-cross-account-snapshots-backup",  
"arn:aws:iam::123456789:role/service-role/AWSBackupDefaultServiceRole",  
"arn:aws:iam::123456789:role/Admin\_\_SSO",  
"arn:aws:iam::987654321:root"  
\]  
},  
"Action": \[  
"kms:CreateGrant",  
"kms:ListGrants",  
"kms:RevokeGrant"  
\],  
"Resource": "\*",  
"Condition": {  
"Bool": {  
"kms:GrantIsForAWSResource": "true"  
}  
}  
}  
\]  
}

S3 Configuration

![Screen Shot 2021-08-31 at 16.03.28](https://lp.cloudride.co.il/hs-fs/hubfs/Screen%20Shot%202021-08-31%20at%2016.03.28.png?width=1668&height=857&name=Screen%20Shot%202021-08-31%20at%2016.03.28.png "Screen Shot 2021-08-31 at 16.03.28")

##### Share the story:

<https://www.facebook.com/sharer/sharer.php?u=https://lp.cloudride.co.il/rds-backups-solution-brief> <https://www.linkedin.com/sharing/share-offsite/?url=https://lp.cloudride.co.il/rds-backups-solution-brief> <https://twitter.com/intent/tweet?original_referer=https://lp.cloudride.co.il/rds-backups-solution-brief&url=https://lp.cloudride.co.il/rds-backups-solution-brief> <https://pinterest.com/pin/create/button/?url=https://lp.cloudride.co.il/rds-backups-solution-brief> <https://www.xing/spi/shares/new?url=https://lp.cloudride.co.il/rds-backups-solution-brief>

#### AWS KMS:

*AWS Key Management System allows you to create, change and manage encryption keys inside your AWS account.*  
*I used CMK (customer-managed key) in order to encrypt the daily snapshots and shared this key with both accounts using a combination of key policy and IAM policy.*  
*In that way, you can manage and validate your encryption and also make sure that both accounts can use this custom key.*

#### S3 lifecycle rules

*Lifecycle rules in S3 are a feature that allows you to determine what will happen to objects that are inserted into an S3 bucket after pre-configured time.*  
*Objects can be moved to a different storage class or to be deleted.*  
*This feature allowed me to configure retention of 7 days to the snapshot that is being exported to S3 so we wouldn't have too many snapshots and we can reduce the cost of this backup bucket.*

## We'll Get You There

**Address**: 24 Raoul Wallenberg St., Tel Aviv 

**Email**: [info@cloudride.co.il](mailto:info@cloudride.co.il)

**Phone**: +972-79-300-1490

 

#### Latest Post

- [Cloud Security 101 for SMBs: Autonomous Purple Team and Real-Time Detection](http://www.cloudride.co.il/blog/cloud-security-101-skyhawk-security)
  
  29 Oct, 2025
- [Revolutionizing Efficiency with AI: My Experience Using Anthropic's Claude Code, Amazon Q for Developers, and Amazon Kiro](http://www.cloudride.co.il/blog/amazon-ai-tools-for-developers)
  
  04 Sep, 2025

#### Fast Links

- [Privacy Policy](https://lp.cloudride.co.il/privacy-policy)

![last badge 22.09.2024](https://lp.cloudride.co.il/hubfs/last%20badge%2022.09.2024.png "last badge 22.09.2024")

![azure badge black bg-1](https://lp.cloudride.co.il/hubfs/azure%20badge%20black%20bg-1.png "azure badge black bg-1")

Copyright © Cloudride

<https://www.facebook.com/cloudride2/> <https://www.linkedin.com/company/cloudride/>