AWS Basics

circle-exclamation

Organizations

Labs manages a set of AWS accounts using the AWS Organizationsarrow-up-right service. This allows us to create a structure and better manage dozens of separate accounts.

  • All student AWS Product Accounts are located in the Students Organizational Unit (OU).

  • Only Engineering Managers can create new AWS Product Accounts.

  • Labs projects must never use AWS Accounts not managed by BloomTech Labs.

You can see a list of accounts herearrow-up-right. Note, this list is not automatically updated, if you don't see your account, contact your engineering manager! Thanks.

IAM Users

Each member of a student team will have an associated IAM User. This IAM User will be created and managed by the RM for the Product.

IAM Groups

Each account will have a group named Students that all student IAM Users will be assigned to. This group has only specific permissions required for their project, adhering to the Principle of Least Privilegearrow-up-right.

Labs Bot

Labs RMs will have access to a Slack Bot that will allow them to manage user accounts for student teams.

Adding Users

Labs Bot can create IAM users. These users should be created following the naming format for IAM Users in the Engineering Standardsarrow-up-right.

circle-info

RMs can run /labsbot in Slack to work with the Labs Bot

  • Example: jane.doe@bloomtech.com - Jane Doe

Last updated

Was this helpful?