kfrajer / kfrajer.github.src

Hugo src code for kfrajer.github.io site
0 stars 0 forks source link

Docs: Instructions to switch role in AWS Console #39

Open kfrajer opened 3 years ago

kfrajer commented 3 years ago

REFERENCE: [GOLD] https://aws.amazon.com/blogs/security/how-to-enable-cross-account-access-to-the-aws-management-console/

OVERVIEW

==================================== Roles in 924300192870 alias cfire(MASTER)

USERS ROLES cm-ui AdministratorAccess, assumeRoleBillingRO NOTE: cm-ui can create roles but assumeRole can only be attached by root or user with proper IAM role management

ROLES Assigned to Account NOTE cfire-ro-billing-role 924300192870 View only: RO cfire-rw-billing-role 824370033741 Full access: RW assumeRoleBillingRO

POLICIES BillingViewAccess Effect: allow, actions: [Custom RO] Resource: BillingFullAccess Effect: allow, actions: [Custom RW] Resource: assumeRoleBillingRO Effect: allow, actions: sts::AssumeRole Resource: "arn:aws:iam::924300192870:role/cfire-ro-billing-role"

Switch role info in dialog prompt Acc: 924300192870 Role name: cfire-ro-billing-role Cross-account session name: viewBilling

==================================== Account 824370033741 alias luchofire(SLAVE)

USERS ROLES cm-dev-main-ui assumeRoleBillingRW-cfire, AdministratorAccess, AmazonS3FullAccess, AmazonSESFullAccess, IAMReadOnlyAccess, AWSElementalMediaStoreFullAccess

ROLES None relevant

POLICIES assumeRoleBillingRW-cfire Effect: allow, actions: sts::AssumeRole Resource: "arn:aws:iam::924300192870:role/cfire-rw-billing-role"

Switch role info in dialog prompt Acc: 924300192870 Role name: cfire-rw-billing-role Cross-account session name: meBilling99