Configure access using temporary credentials for trusting AWS member accounts in management-accessor trust chain
Configure access for AWS member accounts by using a trust chain from the accessor through the management account.
Before you begin
- Familiarize yourself with the Amazon documentation on Creating a role to delegate permissions to an IAM user.
- Ensure that you know which AWS member accounts are assigned to the same management account. You use the management account for configuring temporary credentials for cloud discovery using IAM roles.
- Confirm that Discovery Admin Workspace is using at least version 1.10.0. The navigation module isn't available with earlier versions. To access Cloud Service Accounts with an earlier version, enter in the navigation filter: cmdb_ci_cloud_service_account.list.
Role required:
- For Cloud Discovery: discovery_admin
- For Cloud Provisioning and Governance: admin or sn_cmp.cloud_admin
About this task
You can configure access for AWS member accounts by using a trust chain from the accessor through the management account. The accessor account either has AWS credentials or uses a credential-free method.
Procedure
What to do next
Configure the trusting management account and the trusted accessor account.
- For information on configuring accessor accounts with AWS credentials, see Configure access using temporary credentials based on trusted AWS accounts with AWS credentials.
- For information on configuring accessor accounts without AWS credentials, see Configure access using temporary credentials based on trusted AWS accounts without AWS credentials.