Control AWS access and permissions using policies
Configure policies with the necessary level of permissions to provide access to the AWS resources for Cloud Discovery and Cloud Provisioning and Governance.
Before you begin
Familiarize yourself with creating IAM users and user policies. Refer to the AWS documentation.
Identify the level of permissions required for discovering the resources using Cloud Discovery and managing the resources with Cloud Provisioning and Governance. For example:
- Additional S3 permissions are needed as AWS uses an S3 bucket to store and run the cloud formation templates to deploy stacks using CloudFormation. These permissions are needed even if you run the same CloudFormation template from the AWS console.
- Read-only access is required to do pattern discovery with the custom policy.
Download the Cloud Discovery patterns spreadsheet so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available quarterly, so check periodically to be sure you have the latest version of the spreadsheet.
Roles required:
- AWS Management Console administrator
- For Cloud Discovery: discovery_admin
- For Cloud Provisioning and Governance: admin or sn_cmp.cloud_admin