Ingestion Configuration
Perform the following setup for each AWS account for which Serval will ingest roles.AWS Account Ingestion Role configuration
AWS Account Ingestion Role configuration
- Follow the guide to add give Serval access to an AWS role in your account.
-
Once the role is created, navigate to permissions and select “Create inline policy”
.png?fit=max&auto=format&n=kEJkqsoMd8RKyAo5&q=85&s=e95443255f41e1b33a16821e43b09681)
Create an inline policy for the ingestion role
-
Add the following permission policy. These permissions are required to be able to properly ingest all the data we require:
Tagging roles for ingestion
Serval only ingests roles tagged with the keyserval (the value can be empty). Add this tag to each IAM role you want discovered during resource sync, and attach any AWS permission policies that define what the role can do.
