*** This version of Confluence is for testing only and contains a copy of content from June 29th 2026. No changes will be preserved. ***
...
- The IAM principal cost allocation tags listed below are enabled, but are not passed to the Cornell AWS billing system. However, they may provide functionality to Cornell AWS customers who need to re-bill AWS charges internally.
- Customer-managed roles integrated with Cornell Shibboleth (e.g., shib-my-role) can be tagged. But Shibboleth roles managed centrally (e.g., shib-admin, shib-cs, shib-itsg) cannot be tagged directly.
- IAM roles created by AWS Identity Center (aka AWS SSO), like sso-admin, cannot be tagged.
- To get tags applied to spend by IAM principals that cannot be tagged (e.g., shib-admin), you must use session tagging. See Passing session tags in AWS STS.
- However, you cannot use session tags with AWS Identity Center roles (e.g., sso-admin) because AWS creates manages sessions for those roles internally.
- AWS Bedrock is the only service that supports IAM principal cost allocation tags. I.e., only charges for Bedrock are labeled with the tags of the IAM principal or session that triggered the spend.
...