Skip to content

Research - Terraform plan via Identity center #139

Description

@ale210

Overview

Currently, for devops people to run terraform plan, they need to provide an AWS IAM access key and secret. What we would like to do is have users use AWS Identity Center instead of having to maintain a key.

One note on this - this has to be self-contained in incubator, it can't be attached to the org

Activity

  1. added this to the 05 - Team Workflow milestone on Aug 9, 2026
  2. added and removed
    complexity: missingThis label means the issue is missing a complexity label
    on Aug 9, 2026
  3. removed this from the 05 - Team Workflow milestone on Aug 9, 2026
  4. added this to the 02 - Security milestone on Aug 9, 2026
  5. moved this from New Issue Review to Prioritized Backlog in CoP: DevOps: Project Boardon Aug 9, 2026
  6. self-assigned this
    on Sep 23, 2026
  7. Benettonkkb commented on Sep 23, 2026

    @Benettonkkb
    Member

    Taking for action:

    To-do:

    • Confirm via AWS Mgmt Console if IAM Identity Center is enabled (I know already that the basic IAM is, from the IAM review)
    • familiarize with Pin Terraform to 1.16 in CI #182 to follow its conventions, since it suggests its pattern relevant here.
    • construct local-only Apply options; leaning toward an AWS CLI script procession.
    • speak with leadership to revisit IAM expiry & options to request reinstatement
  8. moved this from Prioritized Backlog to In progress (actively working) in CoP: DevOps: Project Boardon Sep 24, 2026
  9. Benettonkkb commented on Oct 8, 2026

    @Benettonkkb
    Member

    Result

    Test has been run and confirms that AWS Identity center can be used to authenticate and run Terraform Plan without secret keys. Setup was minimal(otherwise negligible for an already-present account), and login was straightforward.

    The one foreseeable obstacle is that AWS Identity Center requires itself to be established as an AWS Organization resource (trivial config, just enablement of AWS IdC after AWS Orgs is also enabled). To this end, I'd imagine that @ExperimentsInHonesty is the one with the AWS Orgs-administrative account, so if AWS IdC isn't already enabled (it wasn't when I did the IAM review, and I believe my Incubator AWS account is locked/expired now), she may have to be the one to do it, unless she's assigned those privileges to a lead already.

    Note: Confirming the objective is to alleviate the need for an access key/IAM user key to deploy Terraform Plan, and not the need for passwords altogether.

    Test

    The test was run in a personal AWS tenant, where a mock of the suggested Incubator setup was established, a tester user account was made, a Terraform AWS IAM group was made, SSO was enabled and distributed for the tester account, and I successfully logged in and ran a tester Terraform deployment to AWS via the command line.

    What Was Used

    • AWS CLI
    • Terraform
    • HashiCorp AWS provider
    • AWS IAM Identity Center enabled
    • AWS Organizations enabled
    • A user created, and authenticated with password and MFA
    • A group-assigned, one-hour permission duration

    Local Steps:

    The process for a local developer, via Bash, AWS CLI and Terraform CLI:

    aws configure sso --profile hfl-incubator-plan
    aws sso login --profile hfl-incubator-plan
    
    export AWS_PROFILE=hfl-incubator-plan
    
    aws sts get-caller-identity
    terraform init -reconfigure
    terraform plan
    

    PowerShell & AWS CLI option:

    $env:AWS_PROFILE = "hfl-incubator-plan"
    
    aws sso login --profile hfl-incubator-plan
    aws sts get-caller-identity
    terraform init -reconfigure
    terraform plan
    

    Note: This avoids hard-coding profile names into the Terraform provider & backend by creating an environment variable. This way, the contributor can choose whatever profile name they want, so they don't collide with GitHub Actions or other executions.

    AWS-Side Configuration

    1. Enable AWS Organizations (free)
    2. Enable IAM Identity Center (free)
    3. Establish desired permission set for Terraform Plan privileges
    4. AWS IAM: Create the user group with the Step 3 Terraform permissions, and session duration
    5. Assign the group to the Incubator user account (if using an Organization-level HfLA account), requiring MFA
    6. Add desired users/developers to that group

    AWS Scoped Privilege Set

    ReadOnlyAccess probably won't be enough, as this was a topic I personally ran into with Issue 146, PR 147, and PR 142, which touched on these very topics. The suggestions below follow the findings there.

    The step 3 permissions should cover authentication for:

    • Terraform AWS Provider
      • read/list/describe required to refresh resources
    • Terraform state backend resources (depends on what's used)
      • S3 read
      • State-lock in DynamoDB/S3
      • AWS Key Management System permissions, if that's used

    What can be used::

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "ReadRequiredSecretValues",
          "Effect": "Allow",
          "Action": "secretsmanager:GetSecretValue",
          "Resource": [
            "arn:aws:secretsmanager:us-west-2:035866691871:secret:home-unite-us-cognito-client*",
            "arn:aws:secretsmanager:us-west-2:035866691871:secret:home-unite-us-google-clientid*",
            "arn:aws:secretsmanager:us-west-2:035866691871:secret:home-unite-us-google-secret*"
          ]
        },
        {
          "Sid": "ListTerraformStatePrefix",
          "Effect": "Allow",
          "Action": "s3:ListBucket",
          "Resource": "arn:aws:s3:::hfla-incubator-terraform-state",
          "Condition": {
            "StringLike": {
              "s3:prefix": "incubator/*"
            }
          }
        },
        {
          "Sid": "ReadWriteTerraformState",
          "Effect": "Allow",
          "Action": [
            "s3:GetObject",
            "s3:PutObject"
          ],
          "Resource": "arn:aws:s3:::hfla-incubator-terraform-state/incubator/terraform.tfstate"
        },
        {
          "Sid": "ManageTerraformStateLock",
          "Effect": "Allow",
          "Action": [
            "s3:GetObject",
            "s3:PutObject",
            "s3:DeleteObject"
          ],
          "Resource": "arn:aws:s3:::hfla-incubator-terraform-state/incubator/terraform.tfstate.tflock"
        }
      ]
    }
    

    Plus ReadOnlyAccess, of course.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions