aquasecurity / aquasecurity/cloudsploit

Is it possible to audit all sub-accounts from master account?

Open
#204 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
3.8k
Forks
751
Avg merge
11d 9h
Merged PRs (30d)
3

Description

Hi!
Thanks for the tool, we found it really useful for our cloud env.

I wonder if it's possible to audit all sub-accounts from master (payer) account by assuming role in them instead of having to create an IAM user in every single subaccount and assigning security audit policy to it.
This approach would be much easier to manage and will also cover new subaccounts everytime they are created.

Thank you!

Contributor guide

Open the contributing guide

Research direction

Review the current AWS account-auditing and authentication flow, then determine how a master payer account could assume roles in its sub-accounts instead of requiring an IAM user in each one. Done would mean auditing existing and newly created sub-accounts through the proposed role-based approach.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.