Security Best Practices
Learn about AWS connection security features and how to follow the principle of least privilege.
How We Ensure Security
Orkestia uses industry best practices to secure AWS connections.
Cross-Account IAM Roles
Instead of storing AWS access keys, Orkestia uses cross-account IAM roles:
No Credentials Stored
We never store your AWS access keys.
Temporary Access
Each session uses short-lived STS credentials.
You Control Access
Delete the IAM role to immediately revoke access.
Full Audit Trail
All actions appear in AWS CloudTrail.
External ID Protection
The External ID in your trust policy prevents "confused deputy" attacks:
- Unique to your organization
- Required for all AssumeRole calls
- Ensures only Orkestia (acting on your behalf) can use the role
{
"Condition": {
"StringEquals": {
"sts:ExternalId": "lt_42_a1b2c3d4e5f6789012345678901234567"
}
}
}
Periodic Validation
Orkestia periodically validates connections to ensure:
- The IAM role still exists
- Required permissions are present
- No unauthorized changes were made
Understanding Least Privilege
The principle of least privilege means granting only the minimum permissions necessary for a task.
Why It Matters
Overly permissive IAM policies:
- Increase blast radius if credentials are compromised
- Violate compliance requirements (SOC 2, ISO 27001, etc.)
- Can lead to accidental resource modification or deletion
Least Privilege Analysis
When you validate a connection, Orkestia analyzes the IAM role for security issues and displays them in the Security Recommendations panel.
Issue Types
Orkestia detects four types of least privilege issues:
Overly Permissive Managed Policy
AdministratorAccess or PowerUserAccess grant far more permissions than Orkestia needs.Example:
Policy: AdministratorAccess
Issue: Grants full access to all AWS services
Recommendation: Replace with a custom policy containing only required permissions.
Overly Permissive Action
Example:
Action: s3:*
Issue: Grants all S3 operations when only specific ones are needed
Recommendation: Replace with specific actions like s3:GetObject, s3:PutObject.
Wildcard Action
* in actions grants access to ALL operations for a service.Example:
Action: ec2:*
Issue: Grants all EC2 operations
Recommendation: Specify only the exact actions required.
Wildcard Resource
* for resources grants access to ALL resources in your account.Example:
Resource: *
Issue: Applies to all resources instead of specific buckets/distributions
Recommendation: Scope to specific resources using ARN patterns like arn:aws:s3:::ltinteg-*.
Severity Levels
| Severity | Color | Description |
|---|---|---|
| High | Red | Critical security issue, should be fixed immediately |
| Medium | Amber | Important issue, fix when possible |
| Low | Blue | Minor improvement, optional |
Viewing Security Issues
From the Connection Card
If a connection has security issues, you'll see a Security Recommendations banner:
- Click the banner to open the panel
- Review issues grouped by policy
- Follow recommendations to fix
From Connection Details
- Open the connection details panel
- Click Security Recommendations at the bottom
- Review and address issues
Fixing Least Privilege Issues
Open AWS IAM Console
Click the Open in AWS Console button in the panel, or:
- Go to AWS IAM Console
- Navigate to Roles
- Find your Orkestia role (shown at the top of the panel)
Review Attached Policies
- Click the role name
- View the Permissions tab
- Identify the policies with issues
Fix the Issues
For managed policies (like AdministratorAccess):
- Click Remove next to the policy
- Create a new inline policy with only required permissions
- Use the policy from the Orkestia setup wizard
For custom/inline policies:
- Click the policy name
- Click Edit
- Replace overly permissive actions with specific ones
- Scope resources to specific ARN patterns
Re-validate
- Return to Orkestia
- Click Validate on the connection
- Verify issues are resolved
Recommended Policy
Use this policy template for minimum required permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "S3Management",
"Effect": "Allow",
"Action": [
"s3:CreateBucket",
"s3:DeleteBucket",
"s3:ListBucket",
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject",
"s3:GetBucketPolicy",
"s3:PutBucketPolicy",
"s3:GetBucketWebsite",
"s3:PutBucketWebsite"
],
"Resource": [
"arn:aws:s3:::ltinteg-*",
"arn:aws:s3:::ltinteg-*/*"
]
},
{
"Sid": "CloudFrontManagement",
"Effect": "Allow",
"Action": [
"cloudfront:CreateDistribution",
"cloudfront:GetDistribution",
"cloudfront:UpdateDistribution",
"cloudfront:DeleteDistribution",
"cloudfront:CreateInvalidation"
],
"Resource": "*"
}
]
}
Important Notes
Security Issues Don't Break Functionality
Regular Reviews
We recommend reviewing your IAM policies:
- After initial setup
- When adding new features
- Quarterly as part of security audits
