Professional Documents
Culture Documents
the AWS resource access manager or am so I want to talk a bit about account
isolation in AWS for a minute you might hear something called a multi-account
strategy in AWS this means you can use different AWS accounts to separate
concerns like administration building or to minimize the so-called blast radius
around any mistakes or security vulnerabilities Now using a multi account
strategies great what percentage challenge when you need to create and share
resources across account that's where resource access manager comes in if you
have multiple individual AWS accounts or an AWS organization you can create
resources centrally and use AWS REM to share those Resources with other accounts
this means that you can reduce operational overhead because you won't be
duplicating resources in each of your account which can be a real pain to manage
every type of resource in AWS using our am currently at the time of this
recording he's a Services have resource types that you can share out so that's at
mesh Aurora CO to build easy too easy to image Builder license manager resource
groups and Route 53 so let's hear let's say we want to launch ec2 instances in a
shared subnet across accounts say we have to AWS accounts account one and account
too and we have a private subnet an account one that we want to share an account
to is able to see this private Subnet in account one this lets account to create
resources and account one's private subnet like ec2 instances what's important to
understand here is that account to has no control over account ones private
subnet so it can't alter the Subnet in any way with the exception of adding tags
in other words is something that isn't copy from a count one to account to it's
just shared and I want to show you one more example in the AWS Management console
using RDS so here I have two different accounts account one on the left and
account to on the right account one has this Aurora database cluster called
database one now I want to be able to clone that database in account to that you
can see here I don't have access we can grant access using our am so over here to
count one will go to the REM console and will select create a resource share will
give this name call the Aurora cluster resource type you see all the different
resource types that we can select will select Aurora DB clusters and you'll see
that database one is available for sharing that check box and you'll see it
selected here now we want to allow an external account this is what is referred
to as a principal I'm going to enter the AWS account number for account number 2
it's a piece that in here and click add so now we're going to be granting account
number to access to this cluster and account number one we can skip the tags and
will create the resource share now you can see I have one here in the deleted
State and that was just me testing this prior to recording the video so you can
actually ignore that one the one we're interested here is the world cluster share
that we just created whose status is active now you'll notice if you go over here
to account to and click refresh you don't see anyting well why is that what we
have to go into the share here and you'll see that the shared resource is in the
associated status with the shared principal the account itself is in the
associating State REM works by sending an invitation from a count one to account
to that you have to first accept so we'll go to our am an account to and under
shared with me under resource shares will see a pending invitation will click on
this and click accept resource share he'll go from pending click okay two
accepted and if we go back to RDS and click refresh we now see database one
shared from account number one so if we select this and under actions we can
create a clone of the state of base and start working with it in our own account
so that's just a simple example of how we can use AWS resource access manager to
share resources across accounts or within an AWS organization so that's pretty
much all you need to know for the exam about REM feel free to reach out with any
questions if not move on to the next lesson thanks