Skip to content

Commit

Permalink
[IT-3987] Configure SSO access for personal aws account
Browse files Browse the repository at this point in the history
Setup SSO access for personal AWS account.

depends on Sage-Bionetworks-IT#1285
  • Loading branch information
zaro0508 committed Nov 14, 2024
1 parent 0b278ce commit aca29c9
Showing 1 changed file with 21 additions and 0 deletions.
21 changes: 21 additions & 0 deletions org-formation/700-aws-sso/_tasks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -343,6 +343,10 @@ Parameters:
Type: String
Default: '143894c8-1031-70c4-b98a-9d2a9aec59bd'

MkPreYnAdminGroup: #JC aws-MkPreYn-admins
Type: String
Default: 'TBD'

#----------------------------------------------------------------------------------------------

SsoAdministrator:
Expand Down Expand Up @@ -1704,6 +1708,23 @@ SsoBWmErzkAdmin:
principalId: !Ref BWmErzkAdminGroup
permissionSetArn: !CopyValue [ !Sub '${resourcePrefix}-${appName}-admin-permission-set-arn' ]

SsoMkPreYnAdmin:
Type: update-stacks
DependsOn: SsoAdministrator
Template: https://raw.githubusercontent.com/Sage-Bionetworks/aws-infra/v0.2.11/templates/SSO/aws-sso.yaml
StackName: !Sub '${resourcePrefix}-${appName}-MkPreYn-admin'
StackDescription: 'SSO: admin role used by MkPreYn admin group'
DefaultOrganizationBindingRegion: !Ref primaryRegion
DefaultOrganizationBinding:
IncludeMasterAccount: true
OrganizationBindings:
TargetBinding:
Account: !Ref MkPreYnAccount
Parameters:
instanceArn: !Ref instanceArn
principalId: !Ref MkPreYnAdminGroup
permissionSetArn: !CopyValue [ !Sub '${resourcePrefix}-${appName}-admin-permission-set-arn' ]

SsoRecoverDevAdmin:
Type: update-stacks
DependsOn: SsoAdministrator
Expand Down

0 comments on commit aca29c9

Please sign in to comment.