3 ms·
They are leveraging the Cross-Account access feature of the AWS Management console, which has been released early this year: https://aws.amazon.com/blogs/aws/ne
by athrun 11y ago
They are leveraging the Cross-Account access feature of the AWS Management console, which has been released early this year: https://aws.amazon.com/blogs/aws/new-cross-account-access-in-the-aws-management-console/ https://aws.amazon.com/blogs/aws/new-cross-account-access-in...
> If you switch to ops-admin @ stage for example, and then go to the S3 page in the console,
> will you get a listing of all buckets in the stage AWS account even though your login
> session as calvin "belongs" to an other AWS account (segment)?
It should work like that, yes.
Your privileges will be "scoped" to the role you are assuming in the "stage" account.
> I can see how having separate AWS accounts for dev/stage/prod makes things easier.
It's also a good way of maintaining agility when you have multiple teams working in parallel on different projects (ex: 1 team = 1 AWS account).
Zalando has recently published a bunch of tools leveraging IAM to help manage multiple AWS accounts (ex: federated SSH access) : https://stups.io/ https://stups.io/
- simonpantzare 11y agoI missed the announcement of cross-account access. This seems great, thanks! STUPS looks interesting. What scares me a bit about these suites that provide many abstractions on top of AWS is how they work in mixed environments where some resources have been set up and are managed out-of-band. I understand that the purpose of STUPS for example is to provide a higher-level interface to AWS, and that having many AWS accounts avoids these mixed environments. Perhaps it's just me suffering from analysis paralysis. I kind of want there to be one or two leading suites of AWS PaaS tools to choose from, whereas the market today seems fragmented with new tools popping up all the time. For the moment I'm betting on HashiCorp. :)