Skip to main content

AWS Discovery in a Single Account

Report an Issue

This page lists the configuration fields in a usage example of the teleport-discovery-aws Terraform module: single-account-legacy.

Teleport AWS Account Discovery Example​

Configuration in this directory creates AWS and Teleport resources necessary for Teleport to discover resources in a single AWS account.

In addition, the example uses a custom AWS IAM policy to narrow the scope of permissions for Teleport Discovery Service instances.

Requirements​

NameVersion
terraform>= 1.0
aws>= 5.0
teleport>= 18.5.1
tls>= 4.0

Providers​

NameVersion
aws>= 5.0

Modules​

NameSourceVersion
aws_discovery../..n/a

Resources​

NameType
aws_iam_policy_document.teleport_discovery_service_single_accountdata source

Inputs​

No inputs.

Outputs​

NameDescription
aws_discoveryn/a

Source Code​

View the single-account-legacy example source code for the teleport-discovery-aws module on GitHub.

################################################################################
# teleport/discovery/aws/examples/single-account-legacy/main.tf
################################################################################

module "aws_discovery" {
  source  = "terraform.releases.teleport.dev/teleport/discovery/aws"
  version = "~> 18.0"

  teleport_proxy_public_addr    = "example.teleport.sh:443"
  teleport_discovery_group_name = "cloud-discovery-group"

  # Discover EC2 AWS resources 
  match_aws_resource_types = ["ec2"]
  # Apply the additional AWS tag "origin=example" to all AWS resources created by this module
  apply_aws_tags = { origin = "example" }
  # Apply the additional Teleport label "origin=example" to all Teleport resources created by this module
  apply_teleport_resource_labels = { origin = "example" }

  # Examples of existing AWS resource reuse:
  # AWS IAM OIDC provider for this Teleport cluster's public proxy address must already exist
  create_aws_iam_openid_connect_provider = false

  # Use a custom IAM policy with permission conditions
  aws_iam_policy_document = data.aws_iam_policy_document.teleport_discovery_service_single_account.json
}

data "aws_iam_policy_document" "teleport_discovery_service_single_account" {
  # read-only discovery
  statement {
    effect = "Allow"
    actions = [
      "account:ListRegions",
      "ec2:DescribeInstances",
      "ssm:DescribeInstanceInformation",
      "ssm:GetCommandInvocation",
      "ssm:ListCommandInvocations",
    ]
    resources = ["*"]
  }

  # SSM command execution document access
  # (Allows using any document, or restrict to specific documents here)
  statement {
    effect = "Allow"
    actions = [
      "ssm:SendCommand",
    ]
    resources = [
      "arn:aws:ssm:*:*:document/AWS-RunShellScript"
    ]
  }

  # SSM command execution instance access
  statement {
    effect = "Allow"
    actions = [
      "ssm:SendCommand",
    ]
    resources = [
      "arn:aws:ec2:*:*:instance/*"
    ]

    # restrict command execution on instances based on resource tags
    condition {
      test     = "StringEquals"
      variable = "aws:ResourceTag/TeleportManaged"
      values   = ["true"]
    }
  }
}

################################################################################
# teleport/discovery/aws/examples/single-account-legacy/outputs.tf
################################################################################

output "aws_discovery" {
  value = module.aws_discovery
}

################################################################################
# teleport/discovery/aws/examples/single-account-legacy/versions.tf
################################################################################

terraform {
  required_version = ">= 1.0"

  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = ">= 5.0"
    }
    tls = {
      source  = "hashicorp/tls"
      version = ">= 4.0"
    }
    teleport = {
      source  = "terraform.releases.teleport.dev/gravitational/teleport"
      version = ">= 18.5.1"
    }
  }
}