Help
Back to home
English
English
  • Overview
    • Our Features
    • AWS Discount Catalog
    • Money back guarantee
  • Getting Started
    • Step 1 - Estimate Savings Preview
    • Step 2 - Know your Business
    • Step 3 - Join Dotted
    • Team Invitation
    • Additional AWS accounts
    • Post onboarding
  • Multi-account architecture
    • via 'Join Account(s)'
    • Leave an AWS Organization
    • via 'Join With A Pre-Existing Org(s)'
  • Dotted Platform
    • Dashboard
    • Estimate View
    • Effective Savings Rate
    • Finops Teams Time Spent
    • Past Savings
    • Volume Tier Discounts
    • Invoices from AWS & Dotted
    • Payments
    • Sales or Value added tax (VAT)
  • Security & Access
    • Cross Account Role
    • IAM Role Breakdown
    • Role Deployment
    • Other Housekeeping
    • Access Management
  • General FAQ
  • Legal
    • Privacy Policy
    • Terms of Use
    • Mutual Non-Disclosure Agreement
  • Understanding AWS
    • Reserved Instances
    • Savings Plans
    • Commitments
      • What are commitments in AWS?
Fornecido por GitBook
Nesta página

Isto foi útil?

  1. Security & Access

Cross Account Role

AnteriorSecurity & AccessPróximoIAM Role Breakdown

Atualizado há 1 ano

Isto foi útil?

Dotted accesses your AWS account via a cross-account role. In line with AWS IAM policy best practices, Dotted requests only the . This means we limit the actions we can take and the resources to which those actions can be applied.

We further enhance security by using read-only permissions: .

Read-only role

This role is used during the initial . It requires read-only permissions (see the IAM roles breakdown ) to access up to one year of historical billing data (via Cost Explorer) and your AWS infrastructure metadata (such as the Redshift cluster you are using and whether it is already covered by reserved instances). After ingesting this data, Dotted's billing engine calculates optimal savings. Once a user is fully onboarded, the read-only role is used again to display cost and savings on the Dotted dashboard, helping users monitor their current spending and the savings achieved by Dotted.

[
  {
    "PolicyName": "DottedBillingReadOnly",
    "PolicyDocument": {
      "Statement": [
        {
          "Action": [
            "budgets:Describe*",
            "budgets:View*",
            "ce:Get*",
            "ce:Describe*",
            "ce:List*",
            "cur:Describe*",
            "cur:Get*",
            "cur:Validate*",
            "pricing:DescribeServices"
            "pricing:GetAttributeValues",
            "pricing:GetProducts",
            "organizations:Describe*",
            "organizations:List*",
            "savingsplans:Describe*",
            "rds:Describe*",
            "rds:List*",
            "elasticache:List*",
            "elasticache:Describe*",
            "redshift:Describe*",
            "es:Describe*",
            "es:List*",
            "billing:Get*",
            "payments:List*",
            "payments:Get*",
            "tax:List*",
            "tax:Get*",
            "consolidatedbilling:Get*",
            "consolidatedbilling:List*",
            "account:GetContactInformation",
            "invoicing:List*",
            "invoicing:Get*",
            "freetier:Get*",
            "ec2:Describe*",
            "lambda:List*",
            "lambda:Get*",
            "ecs:Describe*"
          ],
          "Resource": "*",
          "Effect": "Allow"
        }
      ]
    }
  }
]

Please contact our support team for more information. .

least-privilege permissions
the read-only role
onboarding step (Step 1)
here
support@usedotted.com