Spotter Documentation

AWS Access Management

Decide a name for an AWS role to use — Spotter will ask for this name when you create an integration setup. Use the same role name in every account: Spotter uses that one name everywhere.

The examples below are IAM policy documents. Attach the matching one to the role in each account.

Configure Master Account

Create a role named YOUR_ROLE_NAME in your master account with the following permissions:

JSON
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "Action": [
        "ce:GetCostAndUsage",
        "ce:GetCostForecast",
        "ce:GetReservationPurchaseRecommendation",
        "ce:GetRightsizingRecommendation",
        "ce:GetSavingsPlansPurchaseRecommendation",
        "ce:GetTags",
        "ce:ListCostAllocationTags",
        "config:ListAggregateDiscoveredResources",
        "cost-optimization-hub:GetRecommendation",
        "cost-optimization-hub:ListEnrollmentStatuses",
        "cost-optimization-hub:ListRecommendations",
        "iam:ListAccountAliases",
        "organizations:ListAccounts",
        "trustedadvisor:GetRecommendation",
        "trustedadvisor:ListChecks",
        "trustedadvisor:ListRecommendationResources",
        "trustedadvisor:ListRecommendations"
      ],
      "Resource": "*"
    }
  ]
}

Configure Config Account

Create a role named YOUR_ROLE_NAME in your config account with the following permissions:

JSON
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "Action": [
        "config:ListAggregateDiscoveredResources",
        "iam:ListAccountAliases",
        "trustedadvisor:GetRecommendation",
        "trustedadvisor:ListChecks",
        "trustedadvisor:ListRecommendationResources",
        "trustedadvisor:ListRecommendations"
      ],
      "Resource": "*"
    }
  ]
}

Configure Security Account

Create a role named YOUR_ROLE_NAME in your security account with the following permissions:

JSON
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "Action": [
        "iam:ListAccountAliases",
        "securityhub:GetFindings",
        "trustedadvisor:GetRecommendation",
        "trustedadvisor:ListChecks",
        "trustedadvisor:ListRecommendationResources",
        "trustedadvisor:ListRecommendations"
      ],
      "Resource": "*"
    }
  ]
}

The permissions above read findings from Security Hub CSPM, the original Security Hub.

If the security account also has the newer AWS Security Hub enabled, grant the two actions below. They let Spotter detect that it's in use and keep finding statuses — for example suppressed or resolved — in sync with what you see in its console. Accounts using only Security Hub CSPM don't need them.

JSON
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "Action": ["securityhub:DescribeSecurityHubV2", "securityhub:GetFindingsV2"],
      "Resource": "*"
    }
  ]
}

Configure Other Accounts

Create a role named YOUR_ROLE_NAME in all other accounts with the following permissions:

JSON
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "Action": [
        "iam:ListAccountAliases",
        "trustedadvisor:GetRecommendation",
        "trustedadvisor:ListChecks",
        "trustedadvisor:ListRecommendationResources",
        "trustedadvisor:ListRecommendations"
      ],
      "Resource": "*"
    }
  ]
}

Configure Trust Relationship

Create a trust relationship for the role from the AWS account of Spotter:

JSON
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "Principal": {
        "AWS": ["arn:aws:iam::730660357973:root"]
      },
      "Action": "sts:AssumeRole",
      "Condition": {
        "StringEquals": {
          "sts:ExternalId": "YOUR_EXTERNAL_ID"
        }
      }
    }
  ]
}

You'll find the YOUR_EXTERNAL_ID value in Spotter: go to Admin → Integrations → AWS and see the integration details.