官术网_书友最值得收藏!

Accessing the member account

Once you've created your member account, it's time to put it to work!

An IAM role will be present in the new account, with a default name of OrganizationAccountAccessRole. This is so you can assume the role (from your master account) and administer the member account. While this name is as good as any, it can be configured by passing the --role-name argument when creating the account.

In order to assume the role, you need to know its Amazon Resource Name (ARN). Working out the ARN is a multi-step process:

  1. List your member accounts by running the following command in your master account:
        aws organizations list-accounts
  1. Find the account you created (by its name) and note the ID value in the record. Using that ID, generate the role's ARN by following this pattern:
        arn:aws:iam::<your-member-account-
id>:role/OrganizationAccountAccessRole
  1. If you have changed the created role's name, update the last part of the ARN accordingly.

See the recipes in Chapter 8Security and Identity for information on how to best manage multiple accounts.

主站蜘蛛池模板: 景东| 玉溪市| 青龙| 辰溪县| 饶阳县| 肥东县| 泸溪县| 永年县| 盐城市| 连州市| 毕节市| 盘锦市| 辉南县| 长岭县| 阳曲县| 杭州市| 南乐县| 隆子县| 甘肃省| 屯昌县| 乳山市| 凤阳县| 务川| 道孚县| 东平县| 托克托县| 大石桥市| 酉阳| 肇庆市| 宁安市| 红桥区| 炉霍县| 三亚市| 巢湖市| 轮台县| 远安县| 清水河县| 元谋县| 克什克腾旗| 子洲县| 和龙市|