Skip to main content

AWS

Connection

Setup

1

Create an IAM user

Create an IAM user for Klef and give it an access key.
2

Allow the actions

Attach a policy allowing the actions under Permissions.
3

Reach the organization

Only needed for accounts the key was not issued in. Let the user assume a role in each account, and name that role on the connection.

Settings

Permissions

Minimum permissions the connection requires.

aws.iam_user

Fields

Default Account Matching Rules

When Klef adopts an account that already exists in AWS, it works out whose it is by trying these in order. A connection can override them.

Examples

Contractor access

Unlicensed Microsoft, Slack and AWS access for contractors that expires on their end date, with a warning to their manager first.