Orkestia
Blog
AWS Connections

Security Best Practices

AWS connection security features and least privilege recommendations.

Learn about AWS connection security features and how to follow the principle of least privilege.

How We Ensure Security

Orkestia uses industry best practices to secure AWS connections.

Cross-Account IAM Roles

Instead of storing AWS access keys, Orkestia uses cross-account IAM roles:

No Credentials Stored

We never store your AWS access keys.

Temporary Access

Each session uses short-lived STS credentials.

You Control Access

Delete the IAM role to immediately revoke access.

Full Audit Trail

All actions appear in AWS CloudTrail.

External ID Protection

The External ID in your trust policy prevents "confused deputy" attacks:

  • Unique to your organization
  • Required for all AssumeRole calls
  • Ensures only Orkestia (acting on your behalf) can use the role
trust-policy.json
{
  "Condition": {
    "StringEquals": {
      "sts:ExternalId": "lt_42_a1b2c3d4e5f6789012345678901234567"
    }
  }
}

Periodic Validation

Orkestia periodically validates connections to ensure:

  • The IAM role still exists
  • Required permissions are present
  • No unauthorized changes were made

Understanding Least Privilege

The principle of least privilege means granting only the minimum permissions necessary for a task.

Why It Matters

Overly permissive IAM policies:

  • Increase blast radius if credentials are compromised
  • Violate compliance requirements (SOC 2, ISO 27001, etc.)
  • Can lead to accidental resource modification or deletion

Least Privilege Analysis

When you validate a connection, Orkestia analyzes the IAM role for security issues and displays them in the Security Recommendations panel.


Issue Types

Orkestia detects four types of least privilege issues:

Overly Permissive Managed Policy

Severity: HighAWS managed policies like AdministratorAccess or PowerUserAccess grant far more permissions than Orkestia needs.

Example:

Policy: AdministratorAccess
Issue: Grants full access to all AWS services

Recommendation: Replace with a custom policy containing only required permissions.

Overly Permissive Action

Severity: MediumThe policy grants more specific actions than necessary.

Example:

Action: s3:*
Issue: Grants all S3 operations when only specific ones are needed

Recommendation: Replace with specific actions like s3:GetObject, s3:PutObject.

Wildcard Action

Severity: HighUsing * in actions grants access to ALL operations for a service.

Example:

Action: ec2:*
Issue: Grants all EC2 operations

Recommendation: Specify only the exact actions required.

Wildcard Resource

Severity: Medium to HighUsing * for resources grants access to ALL resources in your account.

Example:

Resource: *
Issue: Applies to all resources instead of specific buckets/distributions

Recommendation: Scope to specific resources using ARN patterns like arn:aws:s3:::ltinteg-*.


Severity Levels

SeverityColorDescription
HighRedCritical security issue, should be fixed immediately
MediumAmberImportant issue, fix when possible
LowBlueMinor improvement, optional

Viewing Security Issues

From the Connection Card

If a connection has security issues, you'll see a Security Recommendations banner:

  1. Click the banner to open the panel
  2. Review issues grouped by policy
  3. Follow recommendations to fix

From Connection Details

  1. Open the connection details panel
  2. Click Security Recommendations at the bottom
  3. Review and address issues

Fixing Least Privilege Issues

Open AWS IAM Console

Click the Open in AWS Console button in the panel, or:

  1. Go to AWS IAM Console
  2. Navigate to Roles
  3. Find your Orkestia role (shown at the top of the panel)

Review Attached Policies

  1. Click the role name
  2. View the Permissions tab
  3. Identify the policies with issues

Fix the Issues

For managed policies (like AdministratorAccess):

  1. Click Remove next to the policy
  2. Create a new inline policy with only required permissions
  3. Use the policy from the Orkestia setup wizard

For custom/inline policies:

  1. Click the policy name
  2. Click Edit
  3. Replace overly permissive actions with specific ones
  4. Scope resources to specific ARN patterns

Re-validate

  1. Return to Orkestia
  2. Click Validate on the connection
  3. Verify issues are resolved

Use this policy template for minimum required permissions:

minimum-policy.json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "S3Management",
      "Effect": "Allow",
      "Action": [
        "s3:CreateBucket",
        "s3:DeleteBucket",
        "s3:ListBucket",
        "s3:GetObject",
        "s3:PutObject",
        "s3:DeleteObject",
        "s3:GetBucketPolicy",
        "s3:PutBucketPolicy",
        "s3:GetBucketWebsite",
        "s3:PutBucketWebsite"
      ],
      "Resource": [
        "arn:aws:s3:::ltinteg-*",
        "arn:aws:s3:::ltinteg-*/*"
      ]
    },
    {
      "Sid": "CloudFrontManagement",
      "Effect": "Allow",
      "Action": [
        "cloudfront:CreateDistribution",
        "cloudfront:GetDistribution",
        "cloudfront:UpdateDistribution",
        "cloudfront:DeleteDistribution",
        "cloudfront:CreateInvalidation"
      ],
      "Resource": "*"
    }
  ]
}
Always use the policy from the Orkestia wizard for the most up-to-date permissions.

Important Notes

Security Issues Don't Break Functionality

Connections with least privilege issues will still work. These are recommendations to improve your security posture.

Regular Reviews

We recommend reviewing your IAM policies:

  • After initial setup
  • When adding new features
  • Quarterly as part of security audits

Next Steps

Troubleshooting

Fix common connection issues.

Managing Connections

View and validate connections.

Audit & Security

Platform-wide audit trail and security posture.