aws cloudformation data.md

Cross-Account Access via CloudFormation

There are multiple ways to deploy AWS roles to provide Dropzone visibility into your environment. See the AWS documentation for more info.

Dropzone provides CloudFormation Templates (CFTs) that assist you in creating the IAM Role you need to integrate with Dropzone. The new role includes a custom trust policy, an AWS-managed ReadOnlyAccess policy, and an inline policy granting specific permissions for secure and streamlined Dropzone operations.

There are two CFTs available:

Name CFT Link Purpose
ReadOnly link This policy provides read-only access to all your AWS resources. Use this if you do not want to edit your role if more permissions are required in the future.
Minimum ReadOnly link This policy provides read-only access to only those AWS resources currently needed by Dropzone. Use this if you are prepared to edit your Policies in the future if Dropzone adds new functionality that requires more access.

Both create a Custom Trust Policy that ensures secure role assumption by Dropzone, using the provided External ID and User ARN.

The following integrations are available for Minimum ReadOnly access:

Service Integration Policy Required
CloudTrail AWSCloudTrail_ReadOnlyAccess Required
EC2 AmazonEC2ReadOnlyAccess Required
EKS eks:ListClusters, eks:DescribeCluster Optional
GuardDuty AmazonGuardDutyReadOnlyAccess Optional
IAM IAMReadOnlyAccess Optional
Route53 AmazonRoute53ReadOnlyAccess Optional
S3 AmazonS3ReadOnlyAccess Optional
S3 (Outposts) AmazonS3OutpostsReadOnlyAccess Optional
Systems Manager AmazonSSMReadOnlyAccess Optional

Find the Dropzone IAM Role Information

Running the CloudFormation Template

You will need to repeat these instructions for each account you want to be visible to Dropzone.

Once done, you may move onto configuring the Dropzone Data and Alert Sources described in the AWS documentation