1.0 Fortanix Key Insight - AWS Permissions
This section describes the read permissions required to onboard an Amazon Web Services (AWS) connection in Fortanix Key Insight. It provides a detailed list of permissions that must be granted to enable secure and successful integration with AWS keys and services.
1.1 AWS Permissions (Services)
This section describes the permissions required to integrate AWS services with Fortanix Key Insight.
AWS Service | Permission | Description |
---|---|---|
Key Management Service (KMS) |
| Lists all KMS keys in the account. |
| Retrieves tags for AWS resources, including KMS keys. | |
| Checks if automatic key rotation is enabled. | |
| Retrieves the access control policy for a key. | |
| Describes metadata about the key. | |
| Lists all grants for the specified key. | |
| Lists all tags attached to a KMS key. | |
| Returns information about all completed key material rotations for the specified KMS key. | |
Relational Database Service (RDS) |
| Provides metadata about RDS DB instances. |
Elastic Block Store (EBS) |
| Lists information about EBS volumes and configurations. |
Simple Storage Service (S3) |
| Lists all buckets owned by the authenticated sender. |
| Retrieves the default encryption configuration of an S3 bucket. | |
| Gets the region where the bucket resides. | |
DynamoDB |
| Lists all DynamoDB tables. |
| Provides metadata about a specific DynamoDB table. | |
| Lists all available DynamoDB Streams. | |
| Provides details about a specified stream, such as shards and records. | |
Elastic Kubernetes Service (EKS) |
| Describes an Amazon EKS cluster. |
| Lists all Amazon EKS clusters in the account. | |
Elastic File System (EFS) |
| Lists all Amazon EFS file systems and metadata. |
Redshift |
| Lists Amazon Redshift clusters and their configurations. |
1.2 AWS Permissions (Others)
This section describes the additional AWS permissions required to access identity roles, retrieve regional configurations, and enable onboarding of multiple AWS accounts using AWS Organization.
AWS Category | Permission | Description |
---|---|---|
Identity and Access Management (IAM) Security Token Service (STS) |
| Allows Fortanix Key Insight to assume the IAM role using the provided AWS user credentials. |
Account (Global) |
| Allows Fortanix Key Insight to identify the list of regions enabled in the AWS account. |
AWS Organization |
| Retrieves details about the organization (For example, master account, feature set). |
| Lists all accounts in the AWS Organization. | |
| Lists accounts under a specific organizational unit (OU). | |
| Lists all child OUs or accounts under a parent root or OU. | |
| Lists the organizational units under a parent root or OU. |