User Guide

How to create an AWS segment

Preview

Create an AWS segment to discover resources in your AWS account and audit the ones you want to track in Inventory. By default, scans and audits for the segment run on AlloyScan cloud workers, services hosted and managed by AlloyScan. You do not need to install or maintain any local components.

NOTE: With the default cloud worker, AWS credentials are encrypted and stored in the AlloyScan cloud. If you want to keep them within your local network, you can use a local Audit Service instead. This can be a service you already use for other segments.

Prerequisites

  • You are a Site Administrator.
  • You have an AWS access key ID and secret access key for a principal with the permissions listed below.
  • For local execution, an Audit Service is available with access to the provider API. The required cloud modules must be installed on its host, or an administrator must enable Allow module installation on audit service host under Admin Center > Settings > Audit settings > Audit Service.

AWS permissions

Grant the principal used by the segment the following permissions to discover and audit AWS resources. The policy applies to both cloud-worker and local execution. Make sure the principal can access the resources you intend to scan.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:DescribeInstances",
        "ec2:DescribeRegions",
        "ec2:DescribeVolumes",
        "rds:DescribeDBInstances",
        "ec2:DescribeAvailabilityZones",
        "elasticloadbalancing:DescribeLoadBalancers",
        "elasticloadbalancing:DescribeLoadBalancerAttributes",
        "ec2:DescribeSecurityGroups",
        "ec2:DescribeImages",
        "ec2:DescribeVpcs",
        "ec2:DescribeSubnets",
        "ec2:DescribeNetworkInterfaces",
        "ec2:DescribeKeyPairs",
        "s3:ListBucket",
        "s3:ListBucketVersions",
        "s3:ListAllMyBuckets",
        "s3:GetBucketLocation",
        "compute-optimizer:GetEnrollmentStatus",
        "rds:DescribeCertificates"
      ],
      "Resource": "*"
    }
  ]
}

Create the segment

  1. Open Network > Segments and select + New segment.
  2. Select AWS and select Next.
  3. Under Execution placement, keep AlloyScan cloud worker, which is selected by default. To run scans and audits in your environment, select Local Audit service and choose an Audit Service.
  4. Review the segment name and change it if needed. Select the AWS resources and regions you want to scan.
  5. Select or add credentials for the provider. Cloud execution uses cloud credentials stored in AlloyScan; local execution uses credentials from the selected Audit Service.
  6. Create a scan schedule, or continue without a schedule. For cloud execution, Cloud start window (minutes) specifies how long after the scheduled time the scan may start.
  7. Review the settings and create the segment.

Use a cloud worker for an existing segment

Open the segment's settings, select AlloyScan cloud worker under Execution placement, select or add compatible cloud credentials, and save. Existing Audit Service credentials are not transferred to cloud storage. You can continue using local execution without changing the segment's credentials.

Verify

  1. Open the segment and select Scan.
  2. Review the scan results and audit the resources you want to inventory.
  3. Open Inventory > AWS and review the audited resources.