Help
Back to home
English
English
  • Overview
    • Our Features
    • AWS Discount Catalog
    • Money back guarantee
  • Getting Started
    • Step 1 - Estimate Savings Preview
    • Step 2 - Know your Business
    • Step 3 - Join Dotted
    • Team Invitation
    • Additional AWS accounts
    • Post onboarding
  • Multi-account architecture
    • via 'Join Account(s)'
    • Leave an AWS Organization
    • via 'Join With A Pre-Existing Org(s)'
  • Dotted Platform
    • Dashboard
    • Estimate View
    • Effective Savings Rate
    • Finops Teams Time Spent
    • Past Savings
    • Volume Tier Discounts
    • Invoices from AWS & Dotted
    • Payments
    • Sales or Value added tax (VAT)
  • Security & Access
    • Cross Account Role
    • IAM Role Breakdown
    • Role Deployment
    • Other Housekeeping
    • Access Management
  • General FAQ
  • Legal
    • Privacy Policy
    • Terms of Use
    • Mutual Non-Disclosure Agreement
  • Understanding AWS
    • Reserved Instances
    • Savings Plans
    • Commitments
      • What are commitments in AWS?
Fornecido por GitBook
Nesta página

Isto foi útil?

  1. Security & Access

Role Deployment

AnteriorIAM Role BreakdownPróximoOther Housekeeping

Atualizado há 1 ano

Isto foi útil?

Dotted automates cross-account role deployment using (CFN) and, more specifically, "" These links enable Dotted to pass a CFN template along with user-specific parameters, such as the cross-account role, external ID, Dotted ID, and more.

Dotted automates cross-account role deployment using AWS CloudFormation (CFN) and, more specifically, "quick-create links." These links enable Dotted to pass a CFN template along with user-specific parameters, such as the cross-account role, external ID, Dotted ID, and more.

Users only need to click the quick-create link and then click "deploy" to have the role deployed to their AWS account. The CFN templates are stored publicly, allowing users to review them before agreeing to the deployment:

(you can read more about these roles in the previous article, )

During deployment, after role creation, a list of properties is sent to Dotted's management account:

  • Dotted ID

  • Cross-account role ARN

  • Dotted external ID

  • User's account ID

  • Role type (read-only)

These properties are stored in Dotted's database. If the deployment occurs during the last step, Dotted will also invite the user's AWS account to join Dotted's AWS Organization. If the user already belongs to an organization, this step will fail. We support existing organizations joining Dotted on a case-by-case basis. Please contact our support team if this applies to you!

Lastly, we offer manual role deployment for customers who cannot work with CloudFormation.

Please contact our support team for more information. .

AWS CloudFormation
quick-create links.
Read-only role
here
support@usedotted.com