Skip to content
Discussion options

You must be logged in to vote

Following up on this now, since we have completely eliminated aws team/role usage!

Atmos auth doesnt eliminate team/role usage on its own, but it enables us to select a specific identity for each stack. That we can specify a different role or permission set in each, and no longer need to use account-map to assume a Terraform role in the target account during Terraform execution. Atmos now assumes the role before running Terraform. That way we can simply execute Terraform with a predefined Permission Set in each account (or IAM role for machine users)

  1. High level explanation of the architecture: https://docs.cloudposse.com/layers/identity/
  2. Long explanation of the evolution from our identit…

Replies: 2 comments 2 replies

Comment options

milldr
Oct 20, 2025
Maintainer Sponsor

You must be logged in to vote
2 replies
@petabook
Comment options

@milldr
Comment options

milldr Dec 30, 2025
Maintainer Sponsor

Answer selected by milldr
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
4 participants