AWS S3 Policies and Permissions Reference
Objective
Configure AWS AssumeRole Authentication
To help facilitate secure data delivery, you can add permissions to allow a specific IAM user in the F5 Distributed Cloud AWS account to assume a role in your AWS account.
To configure AWS AssumeRole Authentication, you must create a role and attach a trust policy in the IAM section of the AWS Console and then delegate it to the F5 Distributed Cloud AWS account.
-
Obtain the following service account and keys required for the Assume Role:
-
F5 Distributed Cloud AWS account number (GLR Account Number:
<GLR-ACCOUNT-NUMBER>) -
Your F5 Distributed Cloud tenant ID
Note: To request the F5 AWS account number, contact F5 Support.
-
-
Create AWS AssumeRole with the custom trust policy.
-
In the AWS Console, select IAM > Roles.
-
Select Create Role.
-
Select Custom trust policy and paste the following JSON:
{"Version": "2012-10-17","Statement": [{"Effect": "Allow","Principal": {"AWS": "arn:aws:iam::<account-number>:user/svc-acct-f5xc-bot-and-risk-management"},"Action": "sts:AssumeRole"},{"Effect": "Allow","Principal": {"AWS": "arn:aws:iam::<account-number>:user/svc-acct-f5xc-bot-and-risk-management"},"Action": "sts:TagSession"}]}Note: Replace
<account-number>with the GLR AWS account number. -
Attach an inline permissions policy to allow pushing data to your AWS S3 bucket:
{"Version": "2012-10-17","Statement": [{"Sid": "Statement1","Effect": "Allow","Action": ["s3:ListBucket","s3:PutObject"],"Resource": ["arn:aws:s3:::<<bucket name>>","arn:aws:s3:::<<bucket name>>/*"]}]} -
Finish creating the role in the AWS Console and record the ARN value (role_arn) that you created. You need the role_arn when you add the AssumeRole credential in the Distributed Cloud Console.
-
-
Log in to the Distributed Cloud Console and add an AssumeRole credential.
- When you add a AWS S3 data receiver, from the AWS Cloud Credentials drop-down menu, select Add Item.
- From the Select Cloud Credential Type drop-down menu, select AWS Assume Role.
- In the IAM Role ARN field, enter the same ARN value that you created in the AWS Console.
- In the Role Session Name field, enter a name for the role.
- Select Add Cloud Credentials to save the credential.