ministryofjustice / analytical-platform

Analytical Platform • This repository is defined and managed in Terraform
https://docs.analytical-platform.service.justice.gov.uk
MIT License
11 stars 4 forks source link

🛡️ Investigate IAM Identity Center with Lake Formation + tags for access management #4006

Closed bagg3rs closed 5 months ago

bagg3rs commented 5 months ago

User Story

As a Analytical Platform user I want to use one identity to access data resources So that accessing and requesting access to data and using analytical applications is simplified

Value / Purpose

We need the availability of IAM Identity Centre being integrated with EntraID with groups to allow and test tagged based access

IAM Identity Center along with identity propagation and Lake Formation tags should give the Data Platform Service area a unified way to grant access to AWS services including S3, Athena, QuickSight and Glue Catalogue.

Useful Contacts

RichB, Julia

Hypothesis

If we use AWS IDAM Identity Centre and Lake Formation Then we can simplify access management for Data Platform services

Proposal

Can IAM Identity Center can be the centre of Data Platform services?

Additional Information

Definition of Done

michaeljcollinsuk commented 5 months ago

Slack thread of initial discussions with the team https://mojdt.slack.com/archives/C04M8224WCV/p1713364819258839

Summary of my initial thoughts:

michaeljcollinsuk commented 5 months ago

Some thoughts/discussion on Identity Centre with the team in https://mojdt.slack.com/archives/C04M8224WCV/p1713537790475079

jacobwoffenden commented 5 months ago

Closing as per https://mojdt.slack.com/archives/C04M8224WCV/p1714549958985199?thread_ts=1714549071.413819&cid=C04M8224WCV