Viewing Core Account resources as a Member Account Developer
Overview
To view core account resources (that is resources created in a core account and shared to member accounts) developers can switch to Read-only roles to view their created resources.
Switching Roles
1) Log in (to your member account) the AWS Console using SSO. Click the drop down menu at the top right and choose Switch Role
.
2) To view VPCs and lower level DNS resources (eg hmpps-development.modernisation-platform.service.justice.gov.uk
) use the member-delegation-read-only
role and use the account aliases for each Core VPC account:
core-vpc-development
core-vpc-test
core-vpc-preproduction
core-vpc-production
3) To view higher level DNS resources (eg. modernisation-platform.service.justice.gov.uk
), or to view Network Firewall resources (eg. CloudWatch logs or Network Firewall policies) use the read-log-records
role and use the account alias for the Core Network account:
core-network-services-production
4) To view Shared Services resources i.e AMIs created and shared, use the member-shared-services
role and use the account alias for the Shared Services account:
core-shared-services-production