aquasecurity / aquasecurity/cloudsploit
Is it possible to audit all sub-accounts from master account?
- Dominant language
- JavaScript
- Stars
- 3.8k
- Forks
- 751
- Avg merge
- 11d 9h
- Merged PRs (30d)
- 3
Description
Hi!
Thanks for the tool, we found it really useful for our cloud env.
I wonder if it's possible to audit all sub-accounts from master (payer) account by assuming role in them instead of having to create an IAM user in every single subaccount and assigning security audit policy to it.
This approach would be much easier to manage and will also cover new subaccounts everytime they are created.
Thank you!
Contributor guide
Research direction
Review the current AWS account-auditing and authentication flow, then determine how a master payer account could assume roles in its sub-accounts instead of requiring an IAM user in each one. Done would mean auditing existing and newly created sub-accounts through the proposed role-based approach.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100