Aller au contenu

IAM roles#

Usage with keycloak#

Connection to AWS Web Console with Keycloak.

According to their Keycloak group membership, they can assume or not some AWS roles.

trust

  • cscd-administrator is attached to the AdministratorAccess managed policy
  • cscd-read-only is attached to the ReadOnlyAccess managed policy
  • cscd-power-user is attached to several policies:
    • ReadOnlyAccess managed policy
    • PowerUserAccess managed policy
    • Custom policy to create IAM user with a 'caascad-automation' tag set to 'true'