Skip to content

AWS Permission Matrix

In order to understand the groups and permission sets we have implemented across AWS, CloudOps have created the following matrix that will be updated each time an amendment or a new group gets generated.

The Matrix

| | | |
---|---|---|---|---
Groups| Scope| Permission Sets| AWS Policy| Description
role_AWS_ROOT_Administrator| IT SupportLyniate Admins| ROOT_Administrator| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess.This roleonlyprovides access to the root account.
role_AWS_LYNIATE_Administrator| IT SupportLyniate Admins| LYNIATE_Administrator| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess.This roleprovides access to non productlyniate.comaccounts and some remainingrhapsody.globalaccounts.
role_AWS_LYNIATE_Developer| Lyniate Developers| LYNIATE_Developer| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess.This roleonlyprovides access to the rapid accounts. "721641150516", #rapid-test-management "810181829066", #rapid-test-runtime "842873269711", #rapid-test-data "126964540875" #rapid-development
role_AWS_RAAS_Administrator| RAAS Admins| RAAS_Administrator| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess.This roleonlyprovides access to theraasaccounts.
role_AWS_RHAPSODY_Developer| RHAPSODY Developer| RHAPSODY_Developer| arn:aws:iam::aws:policy/PowerUserAccess| Permission set contains PowerUserAccess.This roleonlyprovides access to therhapsody developeraccount(s). "058587540471", # Developer
role_AWS_ENVOY_Administrator| ENVOY Admins| ENVOY_Administrator| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess.This roleonlyprovides access to theenvoyaccounts.
role_AWS_CAAS_Administrator| CAAS Admins| CAAS_Administrator| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess.This roleonlyprovides access to thecaas/CPaccounts.
role_AWS_CAAS_Developer| CAAS Development| CAAS_Developer| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess to some accounts and ReadOnlyAccess to others.This roleprovides AdministratorAccess to thecaas_developer_listaccount(s) "778843825177", # CaaS Infrastructure Dev "305708351346", # CaaS Services Dev "302409530443", # CaaS Services Staging "033557743667" # Corepoint Development This role provides ReadOnlyAccess to the caas_services_list account(s) "126452270709" # CaaS Services Prod
role_AWS_CAAS_Support| CAAS Support| CAAS_Support| arn:aws:iam::aws:policy/job-function/ViewOnlyAccess``arn:aws:iam::aws:policy/job-function/SupportUser| This role only provides access to the caas/CP accounts.
role_AWS_CAAS_Platform| CAAS Platform| CAAS_Platform| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess.This roleonlyprovides access to theCaaS UAT accountsaccount(s) "498435430432", # caas-customer-acme "804518368323", # caas-betahealthsystems "537263504876" # CP-PS-Conversion-WestVirginiaUniv
role_AWS_LYNIATE_Security| Lyniate Security| LYNIATE_Security| arn:aws:iam::aws:policy/SecurityAudit| Permission set contains SecurityAudit access. This role only provides access to the security accounts.
role_AWS_CCL_Administrator| Co Creation Lab Admins| Co_Creation_Lab_Administrator| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the co creation lab account(s). "957268370994", # Lyniate - Co Creation Lab
role_AWS_FHIR_Administrator| FHIR Admins| FHIR_Administrator| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the fhir account(s). "126964540875", # Lyniate - fhir-gw-dev
role_AWS_ROOT_Reader| Lyniate ReadOnlyIT Support| ROOT_Reader| arn:aws:iam::aws:policy/job-function/ViewOnlyAccess| Permission set contains ViewOnlyAccess.This roleonlyprovides access to the root account.
role_AWS_MARKETING_Admin| Marketing Team| MKT_Reader| arn:aws:iam::aws:policy/job-function/ViewOnlyAccess| Permission set contains ViewOnlyAccess access. This role only provides access to the Marketing account(s). "482091521175", # Marketplace
role_AWS_MARKETING_Reader| Marketing Team| MKT_Admin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the Marketing account(s). "482091521175", # Marketplace
role_AWS_ATLAS_Administrator| RCP Team| ATLAS_Admin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the RCP account(s). "729825624878", # atlas-global-devops "745193994333", # Envoy Development "514344987565", # rcp-stage-us-east-2-core "863681870127", # rcp-dev-us-west-1-core "745961794808", # atlas-dev-us-west-2-core "976898467737", # atlas-dev-eu-west-1-core "624737326462", # atlas-test-us-east-2-core "490107952907", # atlas-prod-us-east-2-core
role_AWS_ATLAS_Developer| RCP Team| ATLAS_Developer| arn:aws:iam::aws:policy/job-function/ViewOnlyAccess| Permission set contains ViewOnlyAccess access. This role only provides access to the RCP account(s). "729825624878", # atlas-global-devops "745193994333", # Envoy Development "514344987565", # rcp-stage-us-east-2-core "863681870127", # rcp-dev-us-west-1-core "745961794808", # atlas-dev-us-west-2-core "976898467737", # atlas-dev-eu-west-1-core "624737326462", # atlas-test-us-east-2-core "490107952907", # atlas-prod-us-east-2-core
role_AWS_ATLAS_Developer_Admin| RCP Team| ATLAS_Developer_Admin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the; dev, stage and test RCP account(s). "729825624878", # atlas-global-devops "745193994333", # Envoy Development "514344987565", # rcp-stage-us-east-2-core "863681870127", # rcp-dev-us-west-1-core "745961794808", # atlas-dev-us-west-2-core "976898467737", # atlas-dev-eu-west-1-core "624737326462", # atlas-test-us-east-2-core
role_AWS_ROOT_BillingReader| Lyniate ReadOnlyIT Support| ROOT_Billing_Reader| arn:aws:iam::aws:policy/AWSBillingReadOnlyAccess| Permission set contains AWSBillingReadOnlyAccess.This roleonlyprovides access to the root account.
role_AWS_EDUCATION_Reader| Lyniate Education Team| EDUCATION_Reader| arn:aws:iam::aws:policy/job-function/ViewOnlyAccess| Permission set contains ViewOnlyAccess access. This role only provides access to the Education account(s). "388180106501", # Education Account
role_AWS_EDUCATION_Administrator| Lyniate Education Team| EDUCATION_Admin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the LCP account(s). "388180106501", # Education Account
role_AWS_CMI_Admin| CMI Team| CMI_Admin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the CMI account(s) and CMI master account.
role_AWS_SEMANTIC_Admin| Semantic Admin| SEMANTIC_Admin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the SEMANTIC account(s) and SEMANTIC account.
role_AWS_ROOT_MarketPlace| Finance and Marketing| ROOT_MarketPlace| arn:aws:iam::aws:policy/AWSMarketplaceFullAccess| Permission set contains AWSMarketplaceFullAccess access. This role only provides access to the root account.
role_AWS_ROOT_OrganizationAdmin| Cloud Ops| ROOT_OrganizationAdmin| arn:aws:iam::aws:policy/AWSOrganizationsFullAccess``arn:aws:iam::aws:policy/AWSSupportAccess``arn:aws:iam::aws:policy/AWSTrustedAdvisorPriorityFullAccess| Permission set contains full access to AWS Organizations, Support, and Trusted Advisor. This role only provides access to the root account.
role_AWS_SEMANTIC_Upgrades| RAAS Team| SEMANTIC_Upgrades| arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore json{ "Statement": [ { "Action": "s3:GetObject", "Effect": "Allow", "Resource": "arn:aws:s3:::distribution.carecom.dk/healthterm/", "Sid": "" } ], "Version": "2012-10-17" }| Permission set contains AmazonSSMManagedInstanceCore access and S3 upgrade bucket access. This role only provides access to the SEMANTIC account(s) and SEMANTIC account.
role_AWS_ATLAS_Developer_Admin| LCP Team| ATLAS_Developer_Admin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the Education account(s). "729825624878", # atlas-dev-global-devops "859809131801", # atlas-dev-global-network "745961794808" # atlas-dev-uswest2-core
role_AWS_CORP_DNS| ITRAASCAAS| CORP_DNS| arn:aws:iam::aws:policy/AmazonRoute53FullAccess| Permission set contains AmazonRoute53FullAccess access. This role only provides access to the Coporate account(s). "236982743259", # Corporate Account
role_AWS_CORP_S3| Product Management| CORP_s3| arn:aws:iam::aws:policy/AmazonS3FullAccess| Permission set contains AmazonS3FullAccess access. This role only provides access to the Coporate account(s). "236982743259", # Corporate Account
role_AWS_TG_Administrator| ENVOY TeamRAAS Team*| TG_Admin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role only provides access to the TrustGrid account(s). "995305582632", # TrustGrid Account
role_AWS_NOC_Engineer| SRE Team| NOC_Engineer| arn:aws:iam::aws:policy/job-function/NetworkAdministrator``arn:aws:iam::aws:policy/job-function/SystemAdministrator| Permission set contains SystemAdministrator and NetworkAdminstrator access. This role only provides access to the Rhapsody CNA account(s). "314526787001", # Rhapsody CNA
role_AWS_RAAS_TempAdmin| GOT Team| RAAS_TempAdmin| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. This role provides time based access to all raasand envoy accounts.
role_AWS_RAAS_SRE| SRE Team| RAAS_SRE| arn:aws:iam::aws:policy/AdministratorAccess| Permission set contains AdministratorAccess access. Controlled by boundary policy, but will be deprecated in favour of SCP This role provides time based access to all raasand envoy accounts.
role_AWS_GL_RO| GL ReadOnly| GL_Engineer| arn:aws:iam::aws:policy/ReadOnlyAccess| Permission set contains readonly permissions to access the security Account for IPAM and 2 Corp and US Prod accounts to view all Rout53 entries "207728102958", # Rhapsody CNA (centralised network account) "236982743259", # Corporate Account "319328043080" # Envoy US Account
role_AWS_RAAS_PatchManager| GOT Team*SRE Team| RAAS_PatchManager| { "Statement": [ { "Action": "ssm:", "Effect": "Allow", "Resource": "", "Sid": "" }, { "Action": "cloudformation:", "Effect": "Allow", "Resource": "", "Sid": "" }, { "Action": [ "iam:PassRole", "events:UpdateSchedule", "events:PutRule", "events:ListRules", "events:EnableRule", "events:DisableRule", "events:DescribeRule" ], "Effect": "Allow", "Resource": "", "Sid": "" }, { "Action": [ "lambda:UpdateFunctionConfiguration", "lambda:ListFunctions", "lambda:GetFunction" ], "Effect": "Allow", "Resource": "", "Sid": "" }, { "Action": "sts:AssumeRole", "Effect": "Allow", "Resource": "arn:aws:iam:::role/AWS-SystemsManager-AutomationExecutionRole", "Sid": "" } ], "Version": "2012-10-17" }| Permission set contains Custom Permissions for SSM/CloudFormation/EventBridge and Lambda access. This role provides time based access to Lyniate Security account. "207728102958", # Lyniate Security
role_AWS_RHAPSODY_SecurityReader| N/A| N/A| |
role_AWS_RHAPSODY_CVEReader| SoC Team| RHAPSODY_CVEReader| { "Statement": [ { "Action": [ "organizations:ListAccounts", "inspector:Preview", "inspector:List", "inspector:Get", "inspector:Describe", "inspector2:ListUsageTotals", "inspector2:ListTagsForResource", "inspector2:ListFindings", "inspector2:ListFindingAggregations", "inspector2:ListFilters", "inspector2:ListDelegatedAdminAccounts", "inspector2:ListCoverageStatistics", "inspector2:ListCoverage", "inspector2:ListAccountPermissions", "inspector2:GetMember", "inspector2:GetFindingsReportStatus", "inspector2:GetDelegatedAdminAccount", "inspector2:GetConfiguration", "inspector2:DescribeOrganizationConfiguration", "inspector2:BatchGetMemberEc2DeepInspectionStatus", "inspector2:BatchGetFreeTrialInfo", "inspector2:BatchGetAccountStatus" ], "Effect": "Allow", "Resource": "", "Sid": "" } ], "Version": "2012-10-17" }| Permission set contains Custom PermissionsAmazonInspectorReadOnlyAccess**and for the followingThis roleprovides time based access to*Lyniate Securityaccount. "207728102958", # Lyniate Security
role_AWS_SC_Admin| Solutions Consulting Team| SC_Admin| { "Statement": [ { "Action": "ec2:RunInstances", "Condition": { "Null": { "aws:RequestTag/Team": "true", "ec2:ImageType": "false" } }, "Effect": "Deny", "NotResource": [ "arn:aws:ec2:us-west-2::image/ami-02262cd3ca5171944", "arn:aws:ec2:us-west-2::image/ami-01143488e74271126", "arn:aws:ec2:us-west-1::image/ami-08823d0c2726fb4e1", "arn:aws:ec2:us-west-1::image/ami-01082a6704e60c078", "arn:aws:ec2:us-east-2::image/ami-0363fe5c70d06eafb", "arn:aws:ec2:us-east-2::image/ami-00b130a303f46b4c8", "arn:aws:ec2:us-east-1::image/ami-076654a98ef7adb14", "arn:aws:ec2:us-east-1::image/ami-06c17e52b3d0d705d", "arn:aws:ec2:eu-west-2::image/ami-03bd65a4cd500a3db", "arn:aws:ec2:eu-west-2::image/ami-012243a0a89d6bd54", "arn:aws:ec2:eu-north-1::image/ami-0ce5dda73b46f75d2", "arn:aws:ec2:eu-north-1::image/ami-0bcd1a1b7d5642ec6", "arn:aws:ec2:eu-central-1::image/ami-08281e0c326a2c55f", "arn:aws:ec2:eu-central-1::image/ami-0014fad080072a914", "arn:aws:ec2:ca-central-1::image/ami-0d8d49d96e1baabc2", "arn:aws:ec2:ca-central-1::image/ami-028799dbc7c6c9ecb" ], "Sid": "" } ], "Version": "2012-10-17" }| Permission set contains Custom permissionsPowerUserAccessand for the following*This roleprovides time based access toCloud Masteraccount. "821542835567", # Cloud Master
role_aws_s3_customer_files| Product and Dev teams| customer_files_s3_prod| { #To give access to lyniate-customer-facing-files S3 bucket in lyniate-prod account # Console login permissions statement { effect = "Allow" actions = [ "iam:GetUser", "iam:GetRole", "iam:ListRoles", "iam:ListUsers", "sts:GetCallerIdentity" ] resources = [""] } # List all S3 buckets statement { effect = "Allow" actions = [ "s3:ListAllMyBuckets", "s3:GetBucketLocation" ] resources = [""] } # Full CRUD access to specific S3 bucket statement { effect = "Allow" actions = [ "s3:ListBucket", "s3:GetBucketLocation", "s3:GetBucketVersioning" ] resources = ["arn:aws:s3:::lyniate-customer-facing-files"] } statement { effect = "Allow" actions = [ "s3:GetObject", "s3:GetObjectVersion", "s3:PutObject", "s3:PutObjectAcl", "s3:DeleteObject", "s3:DeleteObjectVersion" ] resources = ["arn:aws:s3:::lyniate-customer-facing-files/"] } }| Permission set contains Custom permissions to allow Product and Development teams to access S3 bucket to manage customer facing files. This is primarily linked to Salesforce Knowledge base articles which will help customers download release artifacts "260259092184" # Lyniate Prod
role_AWS_StratusGrid_Reader| StratusGrid| StratusGrid_Reader| arn:aws:iam::aws:policy/ReadOnlyAccess + Inline restrictions| Permission set contains ReadOnlyAccess with an inline policy that denies access to secrets, credentials, and raw data retrieval.This role provides access toall AWS accountsincluding the master account(926239352039). CloudShell and EKS visibility are explicitly allowed. This role was created to allow StratusGrid engineers to perform cost analysis and optimization across the Rhapsody AWS environment.

Automation and CLI

In order to maintain privileges and permission sets Terraform is used to automate any changes to permissions. The module for this is located here: https://gitlab.com/rhapsody.global/raas/terraform-module-sso - a pipeline is triggered when a new account gets added, this is currently a WIP and as of now, all triggered changes need to be applied from the pipeline directly.

If AWS CLI is required an example config below shows the easiest implementation, or if you wish to download the example config you can below.

The above config samples one customer account across different products and is intended as a guide only.
When using SSO, it is a good practice to authenticate to an endpoint rather than an account, then swap between accounts using AWS environment variables to change the profile.