If your company uses AWS Organizations, you will need to deploy a stack set in each sub-account to build the Red Canary Resource Discovery Role.
- Navigate to CloudFormation.
- Click StackSets in the left navigation menu.
- Click Create StackSet.
- Select Service Managed Permissions.
- Select Template is Ready.
- Select Upload a template file.
- Select Choose file.
- Select the red-canary-resource-discovery-user.yaml you downloaded.
- Select Next.
- Enter a StackSet name.
- Enter the RedCanaryResourceDiscoveryRoleName ﹣ we suggest leaving it the default red-canary-resource-discovery-role.
Note: If you changed it in the Setup Discovery Role in Master Account step you must use the same name. - Enter the RedCanaryResourceDiscoveryUserARN which is the ARN of the user created in the Setup Discovery User section.
- Click Next.
- In the Configure StackSet Options leave the defaults.
- Click Next.
- In the set deployment options select Deploy new stacks.
- Select Deploy to organization.
- Under Specify regions, select US East (N. Virginia). Since roles are global, only one region is required.
- Click Next.
- Scroll to the bottom of the Review page.
- Click the agreement.
- Click Submit.
Note: Once this process is completed, continue on with creating credentials for a user.
Comments
0 comments
Please sign in to leave a comment.