Welcome to your first step towards cloud efficiency and savings with Infrastructure Optimizer. By following our setup checklist, you'll enable Infrastructure Optimizer to operate smoothly in your environment.
Environment Prerequisites Overview
Component | Section Link |
---|---|
VPC | |
Certificate | |
IAM Roles | |
EKS Cluster |
Network
Anchor | ||||
---|---|---|---|---|
|
Expand | ||||||
---|---|---|---|---|---|---|
| ||||||
|
Security
Anchor | ||||
---|---|---|---|---|
|
Expand | ||||||
---|---|---|---|---|---|---|
| ||||||
|
Compute
Anchor | ||||
---|---|---|---|---|
|
Expand | ||||
---|---|---|---|---|
| ||||
|
Permissions
Anchor | ||||
---|---|---|---|---|
|
We understand that cloud control and security are essential to you. In order to install Infrastructure Optimizer and start saving right away, we need your help to set up the right permissions for Infrastructure Optimizer to operate. For seamless operation installation and integration with AWS services, the following IAM roles with specific permissions are requiredrole is required for the user who performs the operations:
User IAM Role
Expand | |||||||||
---|---|---|---|---|---|---|---|---|---|
| |||||||||
Info |
| who install and use the product.||||||||
|
Management Server IAM Role
Expand | |||||||
---|---|---|---|---|---|---|---|
| |||||||
Type: Customer managed
|
Controller IAM Role
Expand | |||||
---|---|---|---|---|---|
| |||||
Type: Customer managed
|
Worker IAM Role
Expand | ||||
---|---|---|---|---|
| ||||
Type: AWS Managed | Policy | Explanation | ||
1 |
| This allows read-only access to Amazon EC2 Container Registry repositories | ||
2 |
| This provides the Amazon VPC CNI Add-on permissions it requires to modify the IP address configuration on your EKS worker nodes | ||
3 |
| This allows Amazon EKS worker nodes to connect to Amazon EKS Clusters | ||
4 |
| This is to enable AWS Systems Manager service core functionality | ||
5 |
| This allows the CSI driver service account to make calls to related services such as EC2 | Policy | Explanation |
1 |
| This allows worker nodes to modify the instance metadata parameters on a running or stopped EC2 instance | ||
2 |
| This denies unassigning one or more secondary private IP addresses, or IPv4 Prefix Delegation prefixes from a network interface | ||
Code Block | ||||
|