Closed Sander3003 closed 1 year ago
We are currently using a personal root-account tight to a person; it would be nice to tight it to a organization (if possible).
Based on some reading, I would suggest LF (energy) manages the AWS-root account and the CoMPAS team space (organisation unit?) with a group of CoMPAS admin users to deploy and manage LF energy CoMPAS demo setup. @pascalwilbrink will this work?
Root user taks are not needed to just deploy the CoMPAS demo on AWS: https://docs.aws.amazon.com/accounts/latest/reference/root-user-tasks.html
@pascalwilbrink requested LF energy to go for option 2.
Done
Create AWS IAM user for LF energy. Activities with the root IAM users are barely needed. Their are 2 options:
Todo first: Check if this account cannot be hacked (e.g. by password reset).
Advantage: more control/power Downside: More responsibility
Advantage: clear owner and managed by a professional organisation Downside: dependency on LF energy and their availability
@jmertic What do you prefer? @pascalwilbrink can you check the security concerns of option 1?