This Terraform module onboards AWS member accounts to Connect Cloud Environments (CCE) with CyberArk SaaS services. CCE helps customers easily adopt CyberArk services and establish secure trust relationships with their AWS environments.
This module automates the creation of the required AWS IAM resources and establishes trust relationships with services, enabling seamless integration in a single deployment.
The module supports multiple services that can be enabled independently or together:
- SIA (Secure Infrastructure Access) - Provides just-in-time privileged access to EC2 instances
- SCA (Secure Cloud Access) - Enables secure cloud entitlements management
- Automated IAM Setup: Creates and configures IAM roles and policies
- Multi-Service Support: Enable SIA and/or SCA based on your needs
- Security Best Practices: Implements least-privilege access with external ID validation
- Idempotent: Safe to run multiple times
- Production Ready: Includes validation, error handling, and comprehensive outputs
This module creates the following resources in your AWS account:
- IAM role:
CyberArkSIA-{unique-suffix} - IAM policy:
CyberarkJitAccountProvisioningPolicy-{tenant-id}-{unique-suffix} - Permissions: EC2 instance and region discovery
- IAM role:
SCARole-{account-id}-{tenant-id} - IAM policy:
SCAPolicy-{account-id}-{tenant-id} - IAM permissions policy:
SCAPermissionsPolicy-{account-id}-{tenant-id} - Permissions: IAM role management, SAML provider management
Before using this module, ensure that you have the following information and requirements:
-
Identity Security Platform Account
- API credentials (client ID and secret)
- Tenant URL
-
AWS Requirements
- AWS credentials configured with the appropriate permissions
- Permissions to create IAM roles and policies
- AWS account ID that you want to onboard
-
Terraform Requirements
- Terraform >= 1.8.5
- AWS Provider ~> 5.0
- CyberArk idsec Provider ~> 1.0
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
idsec = {
source = "cyberark/idsec"
version = "~> 0.2.1"
}
}
}
provider "aws" {
region = "us-east-1"
}
provider "idsec" {
# Configure with your CyberArk tenant credentials
# See: https://registry.terraform.io/providers/cyberark/idsec/latest/docs
}
module "cce_onboarding" {
source = "path/to/terraform-aws-cce-account"
account_id = "123456789012"
account_display_name = "Production AWS account"
# Enable only SCA
sca = {
enable = true
}
}module "cce_onboarding" {
source = "path/to/terraform-aws-cce-account"
account_id = "123456789012"
account_display_name = "Production AWS account"
# Enable SIA
sia = {
enable = true
}
sca = {
enable = true
}
}SIA provides just-in-time privileged access to your EC2 instances. To enable:
sia = {
enable = true
}Note: Internally, SIA uses the name "dpa" (Dynamic Privileged Access) for backward compatibility with existing deployments.
SCA enables secure cloud entitlements management. Configuration options:
# Basic SCA
sca = {
enable = true
}
# Optional: EKS cluster management permissions on the SCA cross-account role
sca = {
enable = true
add_permissions_to_manage_cluster = true
}| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| account_id | The AWS account ID that you want to onboard. Must be a valid 12-digit AWS account ID. | string |
n/a | yes |
| account_display_name | The display name for the AWS account | string |
"AWS Account" |
no |
| sia | Configuration for SIA (Secure Infrastructure Access). Note: Uses DPA internally for backward compatibility. | object({ enable = optional(bool, true) }) |
null |
no |
| sca | Configuration for SCA (Secure Cloud Access). add_permissions_to_manage_cluster (default false) attaches optional EKS cluster management permissions. |
object({ enable = optional(bool, true), role_name = optional(string), add_permissions_to_manage_cluster = optional(bool, false) }) |
{ enable = false } |
no |
| Name | Description |
|---|---|
| account_id | The AWS account ID that was onboarded |
| account_display_name | The display name of the AWS account |
| deployment_region | The AWS region where resources were deployed |
| sia_role_arn | The IAM role ARN created for SIA. Returns null if SIA is not enabled. |
| sca_role_arn | The IAM role ARN created for SCA. Returns null if SCA is not enabled. |
| enabled_services | List of services that were enabled for this account |
See the examples directory for complete, working examples:
The AWS credentials used to run this module require the following permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"iam:CreateRole",
"iam:DeleteRole",
"iam:GetRole",
"iam:CreatePolicy",
"iam:DeletePolicy",
"iam:GetPolicy",
"iam:AttachRolePolicy",
"iam:DetachRolePolicy",
"iam:ListAttachedRolePolicies",
"iam:TagRole",
"iam:UntagRole"
],
"Resource": "*"
}
]
}- External ID Validation: All cross-account role assumptions use external ID validation to prevent confused deputy attacks
- Least Privilege: IAM policies grant only the minimum permissions required for each service
- Trust Policies: Roles can only be assumed by verified service accounts with proper conditions
- Regional Deployment: Resources are deployed in the region specified by your AWS provider configuration
Solution: Ensure your account_id variable contains exactly 12 digits without any spaces or special characters.
Solution: Ensure your idsec provider is correctly configured with valid CyberArk credentials. See provider documentation for more information.
This module follows Semantic Versioning. Current version: 0.1.0
This repository is subject to the following licenses:
- CyberArk Privileged Access Manager: Licensed under the CyberArk Software EULA
- Terraform templates: Licensed under the Apache License, Version 2.0 (LICENSE)
We welcome contributions! Please see our Contributing Guidelines for more details.
For issues related to this Terraform module, please open an issue in this repository.
For CCE platform support, please contact CyberArk support.
CyberArk is a global leader in Identity Security, providing powerful solutions for managing privileged access and securing cloud environments. Learn more at www.cyberark.com.