Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

The Department Cloud Tools are designed to simplify the association of UT staff with IAM roles in AWS. The tools consist of a web portal and a series of dedicated groups and organizational units created in the Austin Active Directory.

The following roles are defined in the Department Cloud Tools: 

RoleFunctionsMembers
Cloud Tools OwnersCreate a "cloud account" associated with a department OUITS Staff
OU OwnersAssign EIDs as "cloud account admins" for a cloud accountExisting owners for Active Directory departments
Cloud Account AdminsCreate and populate role groupsEIDs assigned by OU Owners to a cloud account

The process for associating a user account with an IAM role is as follows:

  1. An existing department owner requests a new cloud account by providing an AWS account number to ITS
  2. ITS staff create a cloud account for the department with the provided AWS account number
  3. Department owners assign EIDs as cloud account admins for the new cloud account
  4. A cloud account admin creates role groups for AWS IAM roles
  5. A cloud account admin populates the role groups with EIDs, native Active Directory department accounts, or Active Directory groups
  • No labels