Repository navigation
Research - Terraform plan via Identity center #139
Description
Activity
- addedcomplexity: missingThis label means the issue is missing a complexity labelThis label means the issue is missing a complexity label
on Jan 22, 2026 - moved this to New Issue Review in CoP: DevOps: Project Board
on Apr 16, 2026 - added and removedcomplexity: missingThis label means the issue is missing a complexity labelThis label means the issue is missing a complexity label
on Aug 9, 2026 - addedrole: DevOps EngineerEngineer who maintains and deploys softwareEngineer who maintains and deploys softwareand removed
on Aug 9, 2026 - addedsize: 3ptCan be done in 13-18 hoursCan be done in 13-18 hoursand removed
on Aug 9, 2026 - moved this from New Issue Review to Prioritized Backlog in CoP: DevOps: Project Board
on Aug 9, 2026 Taking for action:
To-do:
- Confirm via AWS Mgmt Console if IAM Identity Center is enabled (I know already that the basic IAM is, from the IAM review)
- familiarize with Pin Terraform to 1.16 in CI #182 to follow its conventions, since it suggests its pattern relevant here.
- construct local-only Apply options; leaning toward an AWS CLI script procession.
- speak with leadership to revisit IAM expiry & options to request reinstatement
- moved this from Prioritized Backlog to In progress (actively working) in CoP: DevOps: Project Board
on Sep 24, 2026 Result
Test has been run and confirms that AWS Identity center can be used to authenticate and run Terraform Plan without secret keys. Setup was minimal(otherwise negligible for an already-present account), and login was straightforward.
The one foreseeable obstacle is that AWS Identity Center requires itself to be established as an AWS Organization resource (trivial config, just enablement of AWS IdC after AWS Orgs is also enabled). To this end, I'd imagine that @ExperimentsInHonesty is the one with the AWS Orgs-administrative account, so if AWS IdC isn't already enabled (it wasn't when I did the IAM review, and I believe my Incubator AWS account is locked/expired now), she may have to be the one to do it, unless she's assigned those privileges to a lead already.
Note: Confirming the objective is to alleviate the need for an access key/IAM user key to deploy Terraform Plan, and not the need for passwords altogether.
Test
The test was run in a personal AWS tenant, where a mock of the suggested Incubator setup was established, a tester user account was made, a Terraform AWS IAM group was made, SSO was enabled and distributed for the tester account, and I successfully logged in and ran a tester Terraform deployment to AWS via the command line.
What Was Used
- AWS CLI
- Terraform
- HashiCorp AWS provider
- AWS IAM Identity Center enabled
- AWS Organizations enabled
- A user created, and authenticated with password and MFA
- A group-assigned, one-hour permission duration
Local Steps:
The process for a local developer, via Bash, AWS CLI and Terraform CLI:
aws configure sso --profile hfl-incubator-plan aws sso login --profile hfl-incubator-plan export AWS_PROFILE=hfl-incubator-plan aws sts get-caller-identity terraform init -reconfigure terraform planPowerShell & AWS CLI option:
$env:AWS_PROFILE = "hfl-incubator-plan" aws sso login --profile hfl-incubator-plan aws sts get-caller-identity terraform init -reconfigure terraform planNote: This avoids hard-coding profile names into the Terraform provider & backend by creating an environment variable. This way, the contributor can choose whatever profile name they want, so they don't collide with GitHub Actions or other executions.
AWS-Side Configuration
- Enable AWS Organizations (free)
- Enable IAM Identity Center (free)
- Establish desired permission set for Terraform Plan privileges
- AWS IAM: Create the user group with the Step 3 Terraform permissions, and session duration
- Assign the group to the Incubator user account (if using an Organization-level HfLA account), requiring MFA
- Add desired users/developers to that group
AWS Scoped Privilege Set
ReadOnlyAccessprobably won't be enough, as this was a topic I personally ran into with Issue 146, PR 147, and PR 142, which touched on these very topics. The suggestions below follow the findings there.The step 3 permissions should cover authentication for:
- Terraform AWS Provider
read/list/describerequired to refresh resources
- Terraform state backend resources (depends on what's used)
- S3 read
- State-lock in DynamoDB/S3
- AWS Key Management System permissions, if that's used
What can be used::
{ "Version": "2012-10-17", "Statement": [ { "Sid": "ReadRequiredSecretValues", "Effect": "Allow", "Action": "secretsmanager:GetSecretValue", "Resource": [ "arn:aws:secretsmanager:us-west-2:035866691871:secret:home-unite-us-cognito-client*", "arn:aws:secretsmanager:us-west-2:035866691871:secret:home-unite-us-google-clientid*", "arn:aws:secretsmanager:us-west-2:035866691871:secret:home-unite-us-google-secret*" ] }, { "Sid": "ListTerraformStatePrefix", "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::hfla-incubator-terraform-state", "Condition": { "StringLike": { "s3:prefix": "incubator/*" } } }, { "Sid": "ReadWriteTerraformState", "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject" ], "Resource": "arn:aws:s3:::hfla-incubator-terraform-state/incubator/terraform.tfstate" }, { "Sid": "ManageTerraformStateLock", "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject", "s3:DeleteObject" ], "Resource": "arn:aws:s3:::hfla-incubator-terraform-state/incubator/terraform.tfstate.tflock" } ] }Plus
ReadOnlyAccess, of course.
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsQuestions/Review
Overview
Currently, for devops people to run
terraform plan, they need to provide an AWS IAM access key and secret. What we would like to do is have users use AWS Identity Center instead of having to maintain a key.One note on this - this has to be self-contained in incubator, it can't be attached to the org