Home / Companies / Pulumi / Blog / Post Details
Content Deep Dive

Organizing AWS Accounts With Pulumi

Blog post from Pulumi

Post Details
Company
Date Published
Author
Praneet Loke
Word Count
2,814
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

An IT self-service "vending machine" in an enterprise setting allows employees to efficiently request and access pre-approved cloud resources, with Pulumi programs orchestrating these resources behind the scenes. The example discussed involves using Pulumi to create an AWS child account within an AWS Organization, which can be initiated via a Pull Request in a git repository. This setup is beneficial for both large enterprises and smaller teams, promoting the organization of AWS accounts using the least-privileged access principle. The organizational structure described includes an Organizational Unit (OU) with member accounts, where user accounts for developers are provisioned in the root account, allowing them to assume specific roles in target accounts. The process involves creating IAM roles and backup policies to ensure compliance and resource backup, with Pulumi providing a flexible programming model to manage these infrastructures. The approach encourages structuring AWS accounts to enforce least-privileged access, offering a self-service mechanism that is especially advantageous for organizations seeking SOC2 certification or those requiring strict resource isolation.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 4 871 80 45 +29%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.