Skip to main content

10 docs tagged with "privileged"

View All Tags

account

This component is responsible for provisioning the full account hierarchy along with Organizational Units (OUs)

account-map

This component is responsible for provisioning information only: it simply populates Terraform state with data (account ids, groups, and roles) that other root modules need via outputs

account-settings

This component is responsible for provisioning account level settings: IAM password policy, AWS Account Alias, EBS encryption, and Service Quotas

aws-saml

This component is responsible for provisioning SAML metadata into AWS IAM as new SAML providers

aws-team-roles

This component is responsible for provisioning user and system IAM roles outside the `identity` account

aws-teams

This component is responsible for provisioning all primary user and system roles into the centralized identity account

github-oidc-provider

This component is responsible for authorizing the GitHub OIDC provider as an Identity provider for an AWS account

github-oidc-role

This component is responsible for creating IAM roles for GitHub Actions to assume

identity-center

This component is responsible for creating [AWS SSO Permission Sets][1] and creating AWS SSO Account Assignments, that is, assigning IdP (Okta) groups and/or users to AWS SSO permission sets in specific AWS Accounts

tfstate-backend

This component is responsible for provisioning an S3 Bucket and DynamoDB table that follow security best practices for usage as a Terraform backend