Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • The IAM principal cost allocation tags listed below are enabled, but are not passed to the Cornell AWS billing system. However, they may provide functionality to Cornell AWS customers who need to re-bill AWS charges internally.
  • Customer-managed roles integrated with Cornell Shibboleth (e.g., shib-my-role) can be tagged. But Shibboleth roles managed centrally (e.g., shib-admin, shib-cs, shib-itsg) cannot be tagged directly.
  • IAM roles created by AWS Identity Center (aka AWS SSO), like sso-admin, cannot be tagged.
  • To get tags applied to spend by IAM principals that cannot be tagged (e.g., shib-admin), you must use session tagging. See Passing session tags in AWS STS.
    • However, you cannot use session tags with AWS Identity Center roles (e.g., sso-admin) because AWS creates manages sessions for those roles internally.
  • AWS Bedrock is the only service that supports IAM principal cost allocation tags. I.e., only charges for Bedrock are labeled with the tags of the IAM principal or session that triggered the spend.

...