How do you automate IAM Role Creation in Customers AWS account?

0

I have a use case to automate the creation of IAM role and attaching a Permission policy to it for a Customers( internal ) AWS account( to which we may not have access to ). Any idea on how such automation can be done?

2개 답변
0

If you have no initial access to the AWS Account, the usual approach is for you to generate an AWS CloudFormation template which will create the Role with suitable Policies attached, and pass that to the customer for them to deploy. I'd suggest using tools such as cfn-nag and CloudFormation Guard to ensure your templates are following best practices and your own requirements for least privilege access.

It's a best practice to require an External ID as part of the trust policy.

profile pictureAWS
전문가
James_S
답변함 2년 전
0

Check out this github repo where I have tried to build a solution to help you automate user group assignment to permission sets in AWS IAM Identity Center for accessing any or all AWS accounts in your organization via federated access following principles of least privilege- Automated Role Entitlements in AWS IAM Identity Center

profile pictureAWS
답변함 5달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠