Setup Methods
This guide covers the three methods for creating an IAM role to connect your AWS account: Manual, CloudFormation, and Terraform.
Wizard Overview
The connection wizard has 5 steps:
| Step | Description |
|---|---|
| 1. Connection Scope | Choose organization-wide or site-specific |
| 2. Setup Method | Choose Manual, CloudFormation, or Terraform |
| 3. Route53 Option | Enable Route53 DNS management (optional) |
| 4. Setup Instructions | Follow the instructions for your chosen method |
| 5. Enter Role ARN | Provide the role ARN and connection name |
Step 1: Choose Connection Scope
Select how this AWS connection will be used:
Organization-wide (Recommended)
- Available to all sites in your organization
- Best when using one AWS account for all deployments
- Simplifies management with a single connection
Site-specific
Coming SoonSite-specific connections will allow you to connect different AWS accounts to individual sites for isolation or compliance requirements.
Step 2: Choose Setup Method
Select your preferred method for creating the IAM role:
| Method | Best For | Complexity |
|---|---|---|
| Manual | One-time setup, AWS Console users | Medium |
| CloudFormation | AWS-native IaC, repeatable deployments | Low |
| Terraform | Multi-cloud IaC, existing Terraform users | Low |
Step 3: Route53 Option
Choose whether you plan to use AWS Route53 for DNS management:
Yes, use Route53
Select this if you want Orkestia to:
- Automatically create DNS records for your domains
- Manage SSL certificate validation records
- Handle subdomain configuration
The IAM role will include additional Route53 permissions.
No, use external DNS
Select this if you:
- Use Cloudflare, GoDaddy, or another DNS provider
- Will manually configure DNS records
- Don't need automatic DNS management
Step 4: Setup Instructions
Follow the instructions for your chosen setup method below.
Create the IAM role manually in the AWS Console.
4.1 Copy Your External ID
The wizard displays your unique External ID. This is a security feature that prevents "confused deputy" attacks.
Example: lt_42_a1b2c3d4e5f6789012345678901234567
Click the copy button to copy your External ID.
4.2 Create IAM Role in AWS Console
Open the AWS IAM Console
Navigate to the AWS IAM Console and click Roles in the sidebar.
Create a new role
Click Create role and select AWS account as the trusted entity type.
Configure cross-account access
Choose Another AWS account and enter the Orkestia AWS Account ID:
856022192189
Add External ID requirement
Check Require external ID and enter your External ID from the wizard.
Continue to permissions
Click Next to proceed to the permissions step.
4.3 Trust Policy
The wizard provides the complete trust policy JSON. Here's the format:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::856022192189:root"
},
"Action": "sts:AssumeRole",
"Condition": {
"StringEquals": {
"sts:ExternalId": "YOUR_EXTERNAL_ID"
}
}
}
]
}
4.4 Permission Policy
The wizard provides the permission policy with all required permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "S3BucketManagement",
"Effect": "Allow",
"Action": [
"s3:CreateBucket",
"s3:DeleteBucket",
"s3:ListBucket",
"s3:GetBucketLocation",
"s3:GetBucketPolicy",
"s3:PutBucketPolicy",
"s3:DeleteBucketPolicy",
"s3:GetBucketWebsite",
"s3:PutBucketWebsite",
"s3:DeleteBucketWebsite",
"s3:PutBucketPublicAccessBlock",
"s3:GetBucketPublicAccessBlock"
],
"Resource": "arn:aws:s3:::ltinteg-*"
},
{
"Sid": "S3ObjectManagement",
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::ltinteg-*",
"arn:aws:s3:::ltinteg-*/*"
]
},
{
"Sid": "CloudFrontManagement",
"Effect": "Allow",
"Action": [
"cloudfront:CreateDistribution",
"cloudfront:GetDistribution",
"cloudfront:UpdateDistribution",
"cloudfront:DeleteDistribution",
"cloudfront:ListDistributions",
"cloudfront:CreateInvalidation",
"cloudfront:GetInvalidation",
"cloudfront:ListInvalidations"
],
"Resource": "*"
}
]
}
aws.* workflows it unlocks in the workflow reference.4.5 Attach the Permission Policy
Create a new policy
In the AWS Console, click Create policy and switch to the JSON tab.
Paste the policy
Paste the permission policy from the wizard.
Name and create
Click Next, name the policy (e.g., OrkestiaPolicy), and click Create policy.
Attach to role
Return to role creation and attach this policy. Complete the role creation.
4.6 Get the Role ARN
After creating the role:
- Open the role in IAM Console
- Copy the Role ARN from the summary section
Example: arn:aws:iam::123456789012:role/OrkestiaRole
Deploy a CloudFormation stack to automatically create the IAM role.
4.1 Clone the Repository
# The CloudFormation template is provided by your Orkestia contact.
# (The Manual method above is fully self-contained and needs no download.)
4.2 Deploy the Stack
Run the following command, replacing the parameter values from the wizard:
aws cloudformation deploy \
--template-file template.yaml \
--stack-name ltinteg-role \
--parameter-overrides \
ExternalId=YOUR_EXTERNAL_ID \
OrkestiaAccountId=856022192189 \
--capabilities CAPABILITY_NAMED_IAM
With Route53 enabled:
aws cloudformation deploy \
--template-file template.yaml \
--stack-name ltinteg-role \
--parameter-overrides \
ExternalId=YOUR_EXTERNAL_ID \
OrkestiaAccountId=856022192189 \
UseRoute53=true \
--capabilities CAPABILITY_NAMED_IAM
4.3 Get the Role ARN
After deployment completes, retrieve the Role ARN:
aws cloudformation describe-stacks \
--stack-name ltinteg-role \
--query "Stacks[0].Outputs[?OutputKey=='RoleArn'].OutputValue" \
--output text
Use Terraform to provision the IAM role as part of your infrastructure code.
4.1 Clone the Repository
# The Terraform module is provided by your Orkestia contact.
# (The Manual method above is fully self-contained and needs no download.)
4.2 Configure Variables
Create or update terraform.tfvars with your values:
external_id = "YOUR_EXTERNAL_ID"
ltinteg_account_id = "856022192189"
With Route53 enabled:
external_id = "YOUR_EXTERNAL_ID"
ltinteg_account_id = "856022192189"
use_route53 = true
4.3 Apply the Configuration
terraform init
terraform plan
terraform apply
4.4 Get the Role ARN
After applying, retrieve the Role ARN:
terraform output cross_account_role_arn
::
Step 5: Enter Connection Details
After creating the IAM role using any method:
5.1 Enter Connection Name
Give your connection a descriptive name:
Production AccountStaging EnvironmentUS-East Region
5.2 Enter Role ARN
Paste the IAM Role ARN you obtained:
arn:aws:iam::123456789012:role/OrkestiaRole
The wizard validates the ARN format in real-time:
- Green checkmark — Valid ARN format
- Red X — Invalid format, check for typos
5.3 Connect
Click Connect AWS to create the connection.
Orkestia will:
- Attempt to assume the role
- Validate required permissions
- Check for security issues
