Bring Your Own Storage (BYOS) with Google Cloud Platform

Camio provides the option to read and write video, images, and metadata using the Google Cloud Storage (GCS) and BigQuery datasets associated with your own Google Billing Account.

Even though Camio itself uses Google Cloud Storage and BigQuery by default (so the underlying storage system is exactly the same), Camio BYOS enables your team to control the storage policies, retention, permissions, backups, capacity, and billing directly from your own Google Cloud Platform account. 

This article describes:

How BYOS works

BYOS with Google Cloud Storage

Google Cloud Storage supports signed URLs. These enable the Camio Box gateway to write directly to your bucket(s) using URLs that the server provides for specific write requests. Signed URLs also enable Camio to serve video, images, and metadata from your own buckets directly from GCS from their Web Browsers (without passing through Camio servers). One big benefit of signed URLs is that the credentials to access your encrypted content are never stored on client devices.

BYOS with BigQuery

Google BigQuery organizes tables and views in datasets. So the Service Accounts you create for Camio to read and write to your BigQuery dataset are used for the event streaming, access logs, and reporting in Camio.

Creating credentials to access your storage

In order for Camio to access the specific Google Cloud Storage bucket(s) and BigQuery dataset you've chosen to use with Camio, you need to create and supply two separate credentials that allow Camio to read and write to your storage. 

Read and Write Service Accounts

  1. Create two IAM Service Accounts for Camio to use when accessing the buckets and BigQuery dataset:
    • one for reading (e.g. camio-storage-read@myproject.iam.gserviceaccount.com)
    • one for writing (e.g. camio-storage-write@myproject.iam.gserviceaccount.com)
  2. Create the key for each Service Account. You'll upload these keys to your Camio Account in the section below.

No Roles or permissions are provided at the point of Service Account creation, since each bucket and dataset will specify the permissions granted to the Service Accounts above.

Granting permission to the Service Accounts

Now that you have the two Service Accounts, you grant them permission to your chosen GCS buckets and BigQuery datasets.

Google Cloud Storage Permissions

  1. Create a bucket in GCP's Cloud Storage if you do not already have bucket(s) to use with Camio.
  2. Add the IAM Service Accounts to the bucket-level policy, granting them their respective read/write access. For each bucket you would like Camio to use, give

BigQuery Dataset Permissions

  1. Create the BigQuery dataset to be used by Camio.
  2. Add the Service Accounts to the BigQuery dataset using predefined BigQuery Roles giving:
    • the reading Service Account the BigQuery Data Viewer, and BigQuery Job User Roles, and
    • the writing Service Account the BigQuery Data Editor, and BigQuery Job User Roles.

Providing the access credentials to Camio

Paste or upload the keys of the read and write Service Accounts you created above, and press Save at https://camio.com/settings/storage

  1. read Service Account Key
  2. write Service Account Key
  3. video bucket name (e.g. "acmeproject1_camio_video")
  4. images and metadata bucket name (e.g. "acmeproject1_camio_metadata")
  5. dataset ID in BigQuery (e.g. "acmeproject1.camio_data")

When you press Save, Camio begins storing and serving your video, images, and metadata in your own bucket(s) and using your own BigQuery dataset for all reporting.

 

 

Have more questions? Submit a request

Comments