Skip to content

data-engineer (tenant accounts): Identify required resources and access #263

Description

@jordanpadams

Summary

Identify and document the IAM permissions the Tenant Data Engineer role needs within each tenant (node) production account, including cross-account access to PDS-CDS-PROD.

Tasks

  • Identify required AWS services and actions scoped to the node account
  • Confirm trust policy for cross-account assume-role to prod-core-cloudops-engineer in PDS-CDS-PROD
  • Determine per-node permission variations (e.g., OpenSearch index scoping per node)
  • Review with SA team and get sign-off

Parent Theme

Part of #235

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    Status
    ToDo
    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions