Cloudformation: Investigate if cloudbeat-root
is needed in single account
#2433
Labels
Team:Cloud Security
Cloud Security team related
The role
cloudbeat-root
seems to be used only inAWSOrg
functionality and thus not needed in single account cloudformation script.Single account cloudformation deploys the role
ElasticAgentRole
(with a unique name) that contains the necessary policy (SecurityAudit
) that is then referenced intoElasticAgentInstanceProfile
which is used into the EC2 instance which seems to be enough for the single account.We should verify that
cloudbeat-root
is not actually used in single account cspm (aws - cloudformation) deployments and if it's not we should remove it from single account cloudformation yaml.The text was updated successfully, but these errors were encountered: