Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Warning

Note that this policy and IAM role are provided as "guard rails" onlyserve only as first-order safeguards. A savvy AWS user can fairly easily contrive to bypass the this policy and role created here.

Deployment

  1. In the target AWS account, create a new CloudFormation stack using the template.yaml file.
  2. Create an Active Directory group that contains the people you wish to have access to the shib-limited_admin role in your AWS account.
  3. Make a request to cloud-support@cornell.edu asking that the shib-limited_admin role be configured for use by your AWS account. Optionally, request that a similar AWS SSO role be created as well. Be sure to provide the name of the AD group you created above.
  4. Once the Cloud Team confirms that the shib-limited_admin group and/or the AWS SSO role is enabled, ask your team to begin using the new role(s) when using your AWS account.

...