Expose attached cloud integration or AWS(/GCP/Azure) identifier to policies

It would be great for policies to know where specific resources are being deployed. For example:

  • what cloud integration is attached to the stack

  • what aws account id / role is attached to the aws providers (and similar for GCP / Azure)

This information can be very useful if actions need to be taken on specific AWS accounts / GCP projects, etc …

Workaround
Run identity check in hooks to add external data to policy data (https://docs.spacelift.io/concepts/policy/terraform-plan-policy#example-passing-custom-tool-output-to-the-plan-policy)
Problem
We're looking into solutions to add specific tags to all resources on specific accounts.

Please authenticate to join the conversation.

Upvoters
Status

⬆️ Gathering votes

Board

💡 Feature Requests

Tags

Policies

Date

About 1 year ago

Subscribe to post

Get notified by email when there are changes.