Skip to content

Repository files navigation

CCE AWS Organization Add Account Onboarding Module

This Terraform module onboards AWS member accounts to Connect Cloud Environments (CCE) with CyberArk SaaS services. CCE helps customers easily adopt CyberArk services and establish secure trust relationships with their AWS environments.

Overview

This module is designed to be run on AWS member accounts after the CCE organization module has been deployed to the AWS management account. It automatically provisions the necessary IAM roles and policies for services based on the organization configuration.

Features

  • Conditional Resource Provisioning: Only creates resources for services enabled in the organization
  • Multiple Service Support:
    • SCA (Secure Cloud Access): Just-in-time privileged access management with optional SSO integration
    • SIA (Secure Infrastructure Access): EC2 instance discovery and secure access
    • Secrets Hub: Centralized secrets management and synchronization with AWS Secrets Manager
  • Idempotent Operations: Safe to run multiple times
  • Standardized Outputs: Provides ARNs and IDs for all created resources

Prerequisites

Before using this module, ensure that you have the following information and requirements:

  1. CyberArk Identity Security Platform Account

    • API credentials (client ID and secret)
    • Tenant URL
  2. AWS Requirements

    • An AWS organization
    • CCE organization module deployed on the management account
    • Organization onboarding ID from the organization module output
    • Appropriate AWS credentials with IAM permissions on the member account
  3. Terraform Requirements

    • Terraform >= 1.7.5
    • AWS Provider ~> 5.0
    • CyberArk idsec Provider ~> 0.1

Usage

Basic Example

terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.0"
    }
    idsec = {
      source  = "cyberark/idsec"
      version = "0.12.1"
    }
  }
}

provider "aws" {
  region = "us-east-1"
}

provider "idsec" {
  # Configure with your CyberArk tenant credentials
  # See: https://registry.terraform.io/providers/cyberark/idsec/latest/docs
}

module "cce_add_account" {
  source = "cyberark/cce-organization-add-account/aws"

  org_onboarding_id = "org-abc123"  # From organization module output
  # role_name = "MyPrefix"  # Optional SCA IAM name prefix; same as org module sca.role_name
}

Examples

A complete working example is available in the examples/multiple_services/ directory. This includes a terraform.tfvars.example file demonstrating the use of the optional role_name variable. The example shows how to onboard an AWS member account with all services enabled in your organization's configuration.

Inputs

Name Description Type Required
org_onboarding_id The organization onboarding ID from the CCE organization module output string Yes
services List of services to enable for this account (for example, ["sia", "sca"]). Must match services configured in the organization. list(string) No (defaults to organization services)

| role_name | The SCA IAM role name prefix (matches the organization module's sca.role_name). When sso_enable = false, determines the prefix for SCA IAM roles; if omitted, defaults to the organization SCA role from CCE. When sso_enable = true, no SCA IAM resources are created in the member account and this input has no effect. | string | No |

Outputs

Name Description
account_onboarding_id The unique identifier for this account onboarding
deployed_services List of services deployed for this account
sia_role_arn The SIA role ARN, if enabled (null otherwise)
sca_role_arn The SCA role ARN, if enabled (null otherwise)
secrets_hub_role_arn The Secrets Hub role ARN, if enabled (null otherwise)

Service Details

SCA (Secure Cloud Access)

Provides just-in-time privileged access to cloud resources with:

  • Dynamic privilege elevation
  • Session monitoring and recording
  • Role-based access control
  • Optional AWS IAM Identity Center (SSO) integration

Resources Created:

  • IAM role: SCARole-{account-id}-{tenant-id} (same name as the organization management account role)
  • IAM policy: SCAPolicy-{account-id}-{tenant-id}
  • IAM permissions policy: SCAPermissionsPolicy-{account-id}-{tenant-id}
  • Conditional SSO policy (if SSO is enabled)

SCA Role Configuration

  • If your organization has sso_enable = false, you can use the optional role_name input to set a custom prefix for the member-account IAM roles and policies. To keep things consistent, match this to the sca.role_name value used in your management account. If you leave it blank, the module defaults to the SCA role name from CCE.
  • If sso_enable = true (IAM Identity Center), this module doesn't create any SCA IAM roles or policies in the member account, so the role_name input is ignored.

IDC (IAM Identity Center) member accounts: When sso_enable = true, this module does not create SCA IAM resources in the member account unless add_permissions_to_manage_cluster = true. In that k8 case it creates only the SCA cross-account role and the EKS cluster permissions policy—not the cross-account, IAM account-permissions, or SSO policies used on the management account or IAM member accounts.

EKS cluster permissions: Set add_permissions_to_manage_cluster = true on the management-account organization module (sca block); it is stored as addPermissionsToManageCluster in org parameters. When that value is true, this module attaches EKS cluster management permissions to the member-account SCA role (full SCA role for IAM members; role + EKS policy only for IDC members).

SIA (Secure Infrastructure Access)

Enables secure access to EC2 instances with:

  • Just-in-time access to EC2 instances
  • Automated discovery of EC2 resources
  • Session recording and monitoring

Resources Created:

  • IAM role: CyberArkSIA-{unique-suffix}
  • IAM policy: CyberarkJitAccountProvisioningPolicy-{tenant-id-prefix}-{unique-suffix}

Secrets Hub

Enables centralized secrets management with:

  • Synchronization of secrets from CyberArk vault to AWS Secrets Manager
  • Automated secret lifecycle management
  • Compliance and audit trail for secrets access
  • Support for secret rotation and updates

Resources Created:

  • IAM role: CyberArk-Secrets-Hub-AllowSecretsAccessRole-{unique-suffix}
  • IAM policy: CyberArk-Secrets-Hub-AllowSecretsAccessPolicy

Configuration:

  • The service uses the regions configured in the organization module
  • Secrets can only be created/managed in the specified AWS regions
  • All managed secrets are tagged with Sourced by CyberArk
  • Extended access (including read) can be enabled per secret by tagging with CyberArk Extended Access: true

How It Works

  1. Query Organization Data: The module queries the CCE organization configuration using the provided org_onboarding_id
  2. Validate Services: Validates that the services you provide match those configured in the organization
  3. Provision Resources: Conditionally creates IAM roles and policies for each specified service
  4. Register Account: Registers the account with CCE, providing the ARNs of created resources
  5. Output Information: Returns resource ARNs and configuration details

Service Versions and Organization Upgrades

Member accounts do not have their own service versions; each account inherits the version configured on its parent organization. This module reads those versions from the organization and passes them through, so you never set a service version here.

After you upgrade services on the management account with the CCE organization module, every member account moves to a Waiting for deployment state and must be re-applied to pick up the new version. Re-running this module on each member account is what performs that upgrade: the next terraform plan shows the inherited version changing, and applying it deploys the new version. No variable needs to change and no new version of this module is required.

Module Deletion

⚠️ Understanding Module Deletion

When you delete this module, it's important to understand what gets removed:

What Gets Deleted from AWS:

  • IAM roles and policies created by this module
  • The account resources from your AWS environment

What remains in CCE: The account registration remains on the CCE platform. The account is NOT removed from CCE when you delete this module. The account will only be fully removed from CCE when the entire organization is deleted using the terraform-aws-cce-organization module on the management account.

How to delete this module:

Remove this module from your main.tf file or run terraform destroy to remove AWS resources. The account remains registered on CCE until the organization is deleted.

Important: You must first delete all the accounts in the organization before you delete the organization's management account using the terraform-aws-cce-organization module. This ensures a clean and complete removal of all resources from both AWS and CCE.

Important Notes

  • Service Selection: You must provide the services variable with the list of services to enable (for example, ["sia", "sca"]). These services must match those configured in the organization on the management account.
  • Management Account: This module should NOT be run on the AWS management account. Use the CCE organization module on the management account instead.
  • Idempotency: The module is safe to run multiple times and will update resources as needed.
  • Regional Deployment: Deploy this module in the same region as your primary AWS operations.

Documentation

For more information:

Licensing

This repository is subject to the following licenses:

  • CyberArk Privileged Access Manager: Licensed under the CyberArk Software EULA
  • Terraform templates: Licensed under the Apache License, Version 2.0 (LICENSE)

Contributing

We welcome contributions! Please see our Contributing Guidelines for more details.

About

CyberArk is a global leader in Identity Security, providing powerful solutions for managing privileged access. Learn more at www.cyberark.com.

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages