Micetro supports the management of cloud accounts across your AWS Organization from a single AWS instance/access key. This involves giving Micetro access to read account information in your AWS Organization.
This configuration requires the configuration of several accounts, roles, and users/instances:
- On the Networking Account, the AWS account from which you want to run Micetro, a defined role allows the designated user/instance read-only access to the AWS Organization, as well as the ability to assume roles on the other accounts in the Organization to fetch their data.
- On the Organization Account, the account that managements the AWS Organization, the Micetro user/instance reads Organization data and manages DNS/DHCP services on each account in the Organization. This account should be the Organization management/delegated administrator account.
- On the AWS Organization's Member Accounts, a Micetro account management role allows the user/instance to manage the accounts in the Organization.
To set up Organization discovery in Micetro, there are two steps you need to complete: