Skip to content

Commit 3a12620

Browse files
authored
IT-4237 Create SSO access for a JC aws-dca-prod-admins group (#1326)
IT-4237: add dca-prod-admin group
1 parent b58d30a commit 3a12620

File tree

1 file changed

+21
-0
lines changed

1 file changed

+21
-0
lines changed

org-formation/700-aws-sso/_tasks.yaml

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -245,6 +245,10 @@ Parameters:
245245
Type: String
246246
Default: '540864c8-1021-7048-7142-4563c3f12645'
247247

248+
dcaProdAdminGroup: # JC aws-dca-prod-admins
249+
Type: String
250+
Default: 'e4d814e8-c071-70fb-2b1e-931d3aed6a46'
251+
248252
genieProdViewerGroup: #JC aws-genie-prod-viewers
249253
Type: String
250254
Default: '9478a4f8-3001-707d-dadb-0c9fffb968be'
@@ -1916,6 +1920,23 @@ SsoDCAProdApplicationManager:
19161920
principalId: !Ref dcaProdApplicationManagerGroup
19171921
permissionSetArn: !CopyValue [ !Sub '${resourcePrefix}-${appName}-application-manager-permission-set-arn' ]
19181922

1923+
SsoDCAProdAdmin:
1924+
Type: update-stacks
1925+
DependsOn: SsoAdministrator
1926+
Template: https://raw.githubusercontent.com/Sage-Bionetworks/aws-infra/v0.5.1/templates/SSO/aws-sso.njk
1927+
StackName: !Sub '${resourcePrefix}-${appName}-dca-prod-admin'
1928+
StackDescription: 'SSO: Administrator role used by DCA admin group'
1929+
DefaultOrganizationBindingRegion: !Ref primaryRegion
1930+
DefaultOrganizationBinding:
1931+
IncludeMasterAccount: true
1932+
OrganizationBindings:
1933+
TargetBinding:
1934+
Account: !Ref DCAProdAccount
1935+
Parameters:
1936+
instanceArn: !Ref instanceArn
1937+
principalId: !Ref dcaProdAdminGroup
1938+
permissionSetArn: !CopyValue [ !Sub '${resourcePrefix}-${appName}-admin-permission-set-arn' ]
1939+
19191940
SsoGenieProdViewer:
19201941
Type: update-stacks
19211942
DependsOn: SsoViewer

0 commit comments

Comments
 (0)