Skip to content

Add CloudFormation template for Federated Identity (AWS) - #7422

Draft
seanrathier wants to merge 5 commits into
mainfrom
seanrathier/federated-identity-aws-cft
Draft

Add CloudFormation template for Federated Identity (AWS)#7422
seanrathier wants to merge 5 commits into
mainfrom
seanrathier/federated-identity-aws-cft

Conversation

@seanrathier

@seanrathier seanrathier commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Summary

closes https://github.com/elastic/ingest-dev/issues/8803

  • Adds deploy/cloudformation/federated-identity-aws.yml — a single CloudFormation template that creates one read-only IAM role for Elastic Federated Identity (Cloud Connectors) across AWS integrations.
  • The template grows incrementally: it carries only the permissions of integrations that are actually federated, one block per integration, mirroring the provider_permissions declared in that integration's package manifest in elastic/integrations. Grants are never added ahead of a declaration.
  • This baseline covers GuardDuty only — the single integration federated in production today. Its AmazonGuardDutyReadOnlyAccess grant is carried over verbatim from the shipped cloud-connectors-guardduty template (it pre-dates provider_permissions; it converts to a mirrored block when the aws package gains declarations under elastic/ingest-dev#8800).
  • The only required quick-create parameter is ElasticResourceId (used to derive the composite ExternalId).
  • Registers the template in scripts/publish_cft.sh so it is uploaded to s3://elastic-cspm-cft/ as cloudformation-federated-identity-aws-{version}.yml on release.

Background

Part of https://github.com/elastic/ingest-dev/issues/8812

This template supports the Federated Identity auth path for Cloud Connectors. In Kibana's flow it is the fallback: the IaC Provider renders role templates dynamically from provider_permissions at onboard time, and Kibana opens this static template's quick-create URL (via the package's iac_template_url) only when that render fails.

Two earlier revisions of this PR took different approaches — one Enable* boolean parameter per integration with CloudFormation Conditions, then a single unconditional grant covering every agentless-enabled AWS integration upfront. Both are superseded by the incremental model: per-integration additions land as separate PRs stacked on this one, each paired with the elastic/integrations PR that declares the permissions it mirrors (first up: aws_securityhub, paired with elastic/integrations#20436).

Test plan

  • Validate YAML with cfn-lint deploy/cloudformation/federated-identity-aws.yml (passes in pre-commit, along with the rain formatter)
  • Deploy a stack in a test AWS account and verify the role is created with the GuardDuty managed policy
  • Confirm stack outputs contain RoleArn and ExternalId, and that assuming the role with the composite ExternalId succeeds
  • Run publish_cft.sh against a test S3 bucket to verify the upload entry works

🤖 Generated with Claude Code

Introduces federated-identity-aws.yml — a single CFT with one Enable*
boolean parameter per AWS integration. CloudFormation Conditions attach
only the IAM policies needed for the selected data streams, keeping the
role minimal. Transport-layer policies (S3/SQS, CloudWatch Logs, Metrics)
are auto-derived so users never need to think about them.

Adds the template to publish_cft.sh so it is uploaded to S3 alongside
the existing cloud-connectors templates.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@seanrathier
seanrathier requested a review from a team as a code owner July 21, 2026 20:13
@mergify

mergify Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

This pull request does not have a backport label. Could you fix it @seanrathier? 🙏
To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • backport-v./d./d./d is the label to automatically backport to the 8./d branch. /d is the digit
  • backport-active-all is the label that automatically backports to all active branches.
  • backport-active-8 is the label that automatically backports to all active minor branches for the 8 major.
  • backport-active-9 is the label that automatically backports to all active minor branches for the 9 major.

@seanrathier
seanrathier marked this pull request as draft July 21, 2026 20:18
…nally

Drops the 24 Enable* parameters and all CloudFormation Conditions in
favor of a single static read-only role. Every IAM policy needed by the
agentless-enabled AWS policy templates is always attached, so Kibana
only needs to pass ElasticResourceId in the quick-create URL and users
never have to update the stack when they add integrations later.

Policies are grouped into four inline policy resources (transport,
metrics, security findings, service inventory) plus the GuardDuty
managed policy. Trust policy, ExternalId derivation, and outputs are
unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@seanrathier seanrathier changed the title Add parameterized CloudFormation template for Federated Identity (AWS) Add CloudFormation template for Federated Identity (AWS) Jul 22, 2026
@seanrathier seanrathier added backport-skip aws Team:Security-Cloud Services Security Data Experience - Cloud Services team. labels Jul 22, 2026
seanrathier and others added 2 commits July 23, 2026 09:45
Extends the federated identity role to cover CSPM, Cloud Asset
Inventory, and KSPM-EKS: attaches the SecurityAudit managed policy and
adds an ElasticSecurityPosture inline policy with the supplemental
config, organizations, access-analyzer, account, cross-account
sts:AssumeRole, and EKS read permissions declared in the per-package
IaC patches of elastic/integrations#20240.

CNVM is deliberately excluded: its scan operations (snapshot
create/delete, RunInstances/TerminateInstances, iam:PassRole) require
write access, and this role stays read-only. CNVM keeps its dedicated
template.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Cross-checked every inline action against the provider_permissions
declarations in elastic/integrations#19405 (the AWS package's
per-datastream permission manifest) and added the missing actions the
agentless data streams require at runtime:

- ec2:DescribeInstanceStatus (ec2_metrics)
- ecs:DescribeClusters (ecs_metrics)
- elasticloadbalancing:DescribeTargetHealth (elb_metrics)
- lambda:GetFunction (lambda)
- rds:DescribeDBClusters (rds)
- health:DescribeAffectedEntities (awshealth)
- securityhub:BatchGetSecurityControls, GetInsightResults
  (securityhub_findings_full_posture, securityhub_insights)

securityhub:ListInsights, declared by #19405, is NOT added: cfn-lint
confirms no such IAM action exists — listing insights is
securityhub:GetInsights, which was already granted.

Also corrects the Config grant: the aws.config data stream polls rule
compliance (DescribeConfigRules, DescribeComplianceByConfigRule,
GetComplianceDetailsByConfigRule), not resource inventory; the
inventory-style Config reads moved to the SecurityPosturePolicy with
the rest of the Asset Inventory permission set.

Actions not declared by #19405 are retained when another primary source
documents them (e.g. iam:ListAccountAliases in the package README);
services whose policy templates are not agentless-enabled (apigateway,
natgateway, vpn, emr, kafka, kinesis, redshift, s3_storage_lens) stay
out of scope.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
seanrathier added a commit to seanrathier/integrations that referenced this pull request Jul 31, 2026
Kibana renders the template via the IaC Provider first and falls back
to opening this quick-create URL when the render fails (422/502). Same
S3 bucket and URL shape as the aws package's existing URL, but pointing
at the incremental federated-identity-aws template, version pinned to
the package's Kibana floor minor. The fallback only functions once
elastic/cloudbeat#7422 merges and publishes the template to S3.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replace the all-at-once grant (five inline policies + SecurityAudit
covering every agentless-enabled AWS integration upfront) with an
incremental model: the template carries only the permissions of
integrations that are actually federated, one block per integration,
mirroring the provider_permissions declared in that integration's
package manifest in elastic/integrations. Never grant ahead of a
declaration.

The baseline is GuardDuty only — the single integration federated in
production today. Its AmazonGuardDutyReadOnlyAccess grant is carried
over verbatim from the shipped cloud-connectors-guardduty template,
pre-dating provider_permissions; it converts to a mirrored block when
the aws package gains declarations.

Per-integration additions land as separate PRs stacked on this one,
each paired with the elastic/integrations PR that declares the
permissions it mirrors.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aws backport-skip Team:Security-Cloud Services Security Data Experience - Cloud Services team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant