To add a cloud service:
- On the Admin page, select the Service management tab.
- Select Add service on the task bar.
- Select the cloud provider you want to use, enter the required information, and
select Add.
Refer to the tabs below for details on each specific cloud provider.
Enter the information required to connect to Akamai Edge DNS:
Obtaining access credentials: For information about how to create API Access Credentials for DDI orchestrator, refer to the Akamai documentation on creating EdgeGrid authentication credentials.
- Enter the information required to connect to Amazon Web Services
(AWS):
- Use the Agent dropdown to select the appropriate device to manage the cloud service.
- Enter a Name for the service.
- Select whether the service will Manage DNS, Manage IPAM, or both.
- Check the Authenticate with instance roles to use an EC2 instance's IAM role to access AWS services. This requires both the DNS and DHCP Agents to be running inside an AWS instance.
- If you do not authenticate with instance roles, you must enter an Access key ID and Secret access key to use for authentication. For information about how to create API access credentials for DDI orchestrator to use, refer to AWS security credentials.
- Check the Use organization discovery checkbox to enable DDI orchestrator to automatically discover and manage AWS resources in accounts belonging to the AWS Organization that DDI orchestrator has access to.
- Check the Exclude regions checkbox to skip discovery and management of resources in specific regions. If selected, you will be prompted in a subsequent step to select regions from which to exclude resources during discovery.
- Select Next.
- If you selected to use organization discovery, complete the following
fields in the Organization discovery settings
step:
- Account management role name: The name of the role that DDI orchestrator will assume to manage accounts belonging to your AWS organization.
- Organization management role ARN: The role ARN that DDI orchestrator will assume to discover accounts belonging to your AWS organization.
- (Optional) Ignore list: A list of
organizational units or account IDs to ignore during
organizational discovery, separated by newlines or commas.Note: If you add an account that is currently managed by DDI orchestrator to the ignore list, it will be removed from DDI orchestrator.
- Select Next.
- If you selected to exclude regions, select the AWS regions where
discovery should not be run in the AWS region
exclusions step. Account-specific exclusions become
available after the service has been added to DDI orchestrator and can be
added by editing
the service properties.
Enter the information required to connect to Azure:
- Use the Agent dropdown to select the appropriate device to manage the cloud service.
- Enter a Name for the service.
- Select whether the service will Manage DNS, Manage IPAM, or both.
- To use managed identities instead of secrets, certificates, or other
forms of authentication, select the Authenticate with managed
identities checkbox. To use managed identities, the
agent must be running on a virtual machine in Azure with managed
identities enabled. For more information about managed identities, refer
to What is managed
identities for Azure resources?.Note: DDI orchestrator supports authentication with both system-assigned and user-assigned managed identities. When using a user-assigned managed identity, you must also specify the Client ID of the user-assigned managed identity. This ensures that, if a virtual machine has multiple user-assigned managed identities, DDI orchestrator can determine which one to use for authentication. For instructions on how to set up managed identities in Azure, refer to Configure managed identities on Azure virtual machines (VMs).
- Enter the following access credentials to access Azure DNS: Tenant
ID, Subscription ID, Client ID and Client
secret. For instructions on how to retrieve this information,
refer to the Microsoft
documentation.
If you choose to use managed identities, you do not need to enter these access credentials.
- To use Azure government, check the Use Azure government checkbox.
To manage Meraki with DDI orchestrator, you must have an operational instance of the DHCP Agent.
In the Add service wizard, enter the following information:
- Use the Agent dropdown to select a DHCP agent to proxy requests through.
- Enter a Name for the service.
- Enter an API key to access the service.
- In the Ignore list field, enter the Meraki Organization or Network IDs that DDI orchestrator should exclude from synchronization. List one ID per line.
For information about how to create API Access Credentials for use by DDI orchestrator, refer to Cisco Meraki Dashboard API.
Synchronization parameters, such as network client synchronization interval, can be configured in the Advanced system settings.
Enter the information required to connect to NS1:
Obtaining access credentials: For information about how to create API Access Credentials for use by DDI orchestrator, refer to the IBM NS1 Connect documentation.
The service and any subnets defined will be displayed under DNS services or DHCP services, respectively.