Configure access using temporary credentials based on trusted AWS accounts without AWS credentials
Set up a trusted credential-less account that other AWS accounts can rely on for access.
始める前に
- Familiarize yourself with the Amazon documentation on Creating a role to delegate permissions to an IAM user.
- Decide which AWS account is going to be the trusted account. You use the trusted account to configure temporary credentials for Cloud Discovery using IAM roles. The trusted account that you use to access other accounts using IAM roles is referred to as an accessor account.
- If you're setting up a trust chain where a member account trusts a management account, and the management account trusts an accessor account, verify that you've configured the member account to trust the management account. For more information, see Configure access using temporary credentials for trusting AWS member accounts in management-accessor trust chain.
- Confirm that Discovery Admin Workspace is using at least version 1.10.0. The navigation module isn't available with earlier versions. To access Cloud Service Accounts with an earlier version, enter in the navigation filter: cmdb_ci_cloud_service_account.list.
Role required:
- For Cloud Discovery: discovery_admin
- For Cloud Provisioning and Governance: admin or sn_cmp.cloud_admin
このタスクについて
To use an account without AWS credentials, you must first configure that account with an IAM role and permissions to access the trusting service account. Then, you set up the IAM role of the trusting account to grant access to the IAM role of the trusted account.
手順
次のタスク
Verify that ServiceNow applications can access the trusting service account using the IAM role:
- Navigate to .
- Select the trusting AWS service account.
- Under Related Links, select Create Discovery Schedule.
- In the Discovery Manager Cloud Discovery page, select Test Account.
- If the connection is successful, a message displays indicating the account validation is successful.
- If the connection isn't successful, an error message displays indicating the cause of failure.