Orkestia
Blog
AWS Connections

Setup Methods

Three ways to create an IAM role for your AWS connection - Manual, CloudFormation, or Terraform.

This guide covers the three methods for creating an IAM role to connect your AWS account: Manual, CloudFormation, and Terraform.

Wizard Overview

The connection wizard has 5 steps:

StepDescription
1. Connection ScopeChoose organization-wide or site-specific
2. Setup MethodChoose Manual, CloudFormation, or Terraform
3. Route53 OptionEnable Route53 DNS management (optional)
4. Setup InstructionsFollow the instructions for your chosen method
5. Enter Role ARNProvide the role ARN and connection name

Step 1: Choose Connection Scope

Select how this AWS connection will be used:

  • Available to all sites in your organization
  • Best when using one AWS account for all deployments
  • Simplifies management with a single connection

Site-specific

Coming Soon

Site-specific connections will allow you to connect different AWS accounts to individual sites for isolation or compliance requirements.


Step 2: Choose Setup Method

Select your preferred method for creating the IAM role:

MethodBest ForComplexity
ManualOne-time setup, AWS Console usersMedium
CloudFormationAWS-native IaC, repeatable deploymentsLow
TerraformMulti-cloud IaC, existing Terraform usersLow

Step 3: Route53 Option

Choose whether you plan to use AWS Route53 for DNS management:

Yes, use Route53

Select this if you want Orkestia to:

  • Automatically create DNS records for your domains
  • Manage SSL certificate validation records
  • Handle subdomain configuration

The IAM role will include additional Route53 permissions.

No, use external DNS

Select this if you:

  • Use Cloudflare, GoDaddy, or another DNS provider
  • Will manually configure DNS records
  • Don't need automatic DNS management

Step 4: Setup Instructions

Follow the instructions for your chosen setup method below.

Create the IAM role manually in the AWS Console.

4.1 Copy Your External ID

The wizard displays your unique External ID. This is a security feature that prevents "confused deputy" attacks.

Example: lt_42_a1b2c3d4e5f6789012345678901234567

Click the copy button to copy your External ID.

Keep this External ID secure. You'll need it for the trust policy.

4.2 Create IAM Role in AWS Console

Open the AWS IAM Console

Navigate to the AWS IAM Console and click Roles in the sidebar.

Create a new role

Click Create role and select AWS account as the trusted entity type.

Configure cross-account access

Choose Another AWS account and enter the Orkestia AWS Account ID:

856022192189

Add External ID requirement

Check Require external ID and enter your External ID from the wizard.

Continue to permissions

Click Next to proceed to the permissions step.

4.3 Trust Policy

The wizard provides the complete trust policy JSON. Here's the format:

trust-policy.json
{
"Version": "2012-10-17",
"Statement": [
  {
    "Effect": "Allow",
    "Principal": {
      "AWS": "arn:aws:iam::856022192189:root"
    },
    "Action": "sts:AssumeRole",
    "Condition": {
      "StringEquals": {
        "sts:ExternalId": "YOUR_EXTERNAL_ID"
      }
    }
  }
]
}

4.4 Permission Policy

The wizard provides the permission policy with all required permissions:

permission-policy.json
{
"Version": "2012-10-17",
"Statement": [
  {
    "Sid": "S3BucketManagement",
    "Effect": "Allow",
    "Action": [
      "s3:CreateBucket",
      "s3:DeleteBucket",
      "s3:ListBucket",
      "s3:GetBucketLocation",
      "s3:GetBucketPolicy",
      "s3:PutBucketPolicy",
      "s3:DeleteBucketPolicy",
      "s3:GetBucketWebsite",
      "s3:PutBucketWebsite",
      "s3:DeleteBucketWebsite",
      "s3:PutBucketPublicAccessBlock",
      "s3:GetBucketPublicAccessBlock"
    ],
    "Resource": "arn:aws:s3:::ltinteg-*"
  },
  {
    "Sid": "S3ObjectManagement",
    "Effect": "Allow",
    "Action": [
      "s3:GetObject",
      "s3:PutObject",
      "s3:DeleteObject",
      "s3:ListBucket"
    ],
    "Resource": [
      "arn:aws:s3:::ltinteg-*",
      "arn:aws:s3:::ltinteg-*/*"
    ]
  },
  {
    "Sid": "CloudFrontManagement",
    "Effect": "Allow",
    "Action": [
      "cloudfront:CreateDistribution",
      "cloudfront:GetDistribution",
      "cloudfront:UpdateDistribution",
      "cloudfront:DeleteDistribution",
      "cloudfront:ListDistributions",
      "cloudfront:CreateInvalidation",
      "cloudfront:GetInvalidation",
      "cloudfront:ListInvalidations"
    ],
    "Resource": "*"
  }
]
}
Always copy the policy from the wizard to ensure you have the latest required permissions. The permission set is scoped to the AWS-backed capabilities your organization uses — browse the aws.* workflows it unlocks in the workflow reference.

4.5 Attach the Permission Policy

Create a new policy

In the AWS Console, click Create policy and switch to the JSON tab.

Paste the policy

Paste the permission policy from the wizard.

Name and create

Click Next, name the policy (e.g., OrkestiaPolicy), and click Create policy.

Attach to role

Return to role creation and attach this policy. Complete the role creation.

4.6 Get the Role ARN

After creating the role:

  1. Open the role in IAM Console
  2. Copy the Role ARN from the summary section
Example: arn:aws:iam::123456789012:role/OrkestiaRole

Deploy a CloudFormation stack to automatically create the IAM role.

4.1 Clone the Repository

Terminal
# The CloudFormation template is provided by your Orkestia contact.
# (The Manual method above is fully self-contained and needs no download.)

4.2 Deploy the Stack

Run the following command, replacing the parameter values from the wizard:

Terminal
aws cloudformation deploy \
  --template-file template.yaml \
  --stack-name ltinteg-role \
  --parameter-overrides \
    ExternalId=YOUR_EXTERNAL_ID \
    OrkestiaAccountId=856022192189 \
  --capabilities CAPABILITY_NAMED_IAM

With Route53 enabled:

Terminal
aws cloudformation deploy \
  --template-file template.yaml \
  --stack-name ltinteg-role \
  --parameter-overrides \
    ExternalId=YOUR_EXTERNAL_ID \
    OrkestiaAccountId=856022192189 \
    UseRoute53=true \
  --capabilities CAPABILITY_NAMED_IAM

4.3 Get the Role ARN

After deployment completes, retrieve the Role ARN:

Terminal
aws cloudformation describe-stacks \
  --stack-name ltinteg-role \
  --query "Stacks[0].Outputs[?OutputKey=='RoleArn'].OutputValue" \
  --output text

Use Terraform to provision the IAM role as part of your infrastructure code.

4.1 Clone the Repository

Terminal
# The Terraform module is provided by your Orkestia contact.
# (The Manual method above is fully self-contained and needs no download.)

4.2 Configure Variables

Create or update terraform.tfvars with your values:

terraform.tfvars
external_id         = "YOUR_EXTERNAL_ID"
ltinteg_account_id  = "856022192189"

With Route53 enabled:

terraform.tfvars
external_id         = "YOUR_EXTERNAL_ID"
ltinteg_account_id  = "856022192189"
use_route53         = true

4.3 Apply the Configuration

Terminal
terraform init
terraform plan
terraform apply

4.4 Get the Role ARN

After applying, retrieve the Role ARN:

Terminal
terraform output cross_account_role_arn

::


Step 5: Enter Connection Details

After creating the IAM role using any method:

5.1 Enter Connection Name

Give your connection a descriptive name:

  • Production Account
  • Staging Environment
  • US-East Region

5.2 Enter Role ARN

Paste the IAM Role ARN you obtained:

arn:aws:iam::123456789012:role/OrkestiaRole

The wizard validates the ARN format in real-time:

  • Green checkmark — Valid ARN format
  • Red X — Invalid format, check for typos

5.3 Connect

Click Connect AWS to create the connection.

Orkestia will:

  1. Attempt to assume the role
  2. Validate required permissions
  3. Check for security issues

Next Steps

Managing Connections

View and manage your connections.

Security Best Practices

Understand security recommendations.

Troubleshooting

Fix common connection issues.

Integrations

See how AWS fits the wider connection catalog.