Using the Copy DBR Feature

Copy_DBR

The Copy DBR functionality will allow you to create a subset of charges from the Detailed Billing Report (DBR) for a specific payee, and then copy that file into an S3 bucket inside that payee account. The following are the steps to get Copy DBR working correctly:

  1. Create an S3 Bucket inside the payee to use as a destination for the payee DBR file. You can also use an existing S3 bucket. The S3 bucket must be part of the specific payee account or the payer account
  2. Under “Bucket Name”, enter the name of the S3 bucket from step 1.
  3. Under “Cost Type”, select “Amazon” to get the unblended cost or “Custom” to get the List cost.
  4. If the S3 Bucket exists in the current Payer account you are using, check the box for “Use current CloudCheckr credentials”.
    1. Note: You must update your IAM policy that is used by the credentials (IAM user or Role) you have added to CloudCheckr to include the following policy in order for Copy DBR to work correctly:
      {
          "Version": "2012-10-17",
          "Statement": [
              {
                  "Sid": "Stmt1443712554000",
                  "Effect": "Allow",
                  "Action": [
                      "s3:DeleteObject",
                      "s3:GetBucketLocation",
                      "s3:ListObject",
                      "s3:PutObject"
                  ],
                  "Resource": [
                      "arn:aws:s3:::your-target-S3-bucket-name-here*"
                  ]
              }
          ]
      }
  5. If the S3 Bucket exists in a different account or the payee account, in the box “Add new credentials” you must provide the IAM Access Key and Secret Key for that account.
    1. Note: You must update your IAM policy that is used by the credentials (IAM user or Role) you have added to CloudCheckr to include the following policy in order for Copy DBR to work correctly:
      {
          "Version": "2012-10-17",
          "Statement": [
              {
                  "Sid": "Stmt1443712554000",
                  "Effect": "Allow",
                  "Action": [
                      "s3:DeleteObject",
                      "s3:GetBucketLocation",
                      "s3:ListObject",
                      "s3:PutObject"
                  ],
                  "Resource": [
                      "arn:aws:s3:::your-target-S3-bucket-name-here*"
                  ]
              }
          ]
      }
  6. When adding the policy with the additional permissions it is paramount that a “*” is added at the end of the bucket name. This is necessary to allow the DBR to be added to the S3 bucket. In the sample permissions a “*” is added at the end of the bucket name (arn:aws:s3:::your-target-S3-bucket-name-here*).

For tips on updating your IAM policy within AWS console, see:
https://support.cloudcheckr.com/getting-started-with-cloudcheckr/permissions-page/