Pump
Back to Home
  • Getting Started
    • Introduction
    • The Hitchhiker's Guide to Pump
    • Joining Pump
      • Our Features
      • Running your Savings Estimate
      • Selecting a mode (Autopilot or Manual Mode)
      • Savings Survey
      • When can I expect to see Savings?
      • Money Back Guarantee
    • Billing Info
      • Billing Process
      • First Month Billing
      • Currencies Supported
      • Supported Payment Methods
      • Invoice Verification or Errors
      • Invoices for Indian Customers
      • Invoices from AWS
      • Sales Tax or Value Added Tax (VAT)
    • How Pump works
    • Real Customers, Real Success Stories
    • Money Back Guarantee
    • FAQ
  • AWS: Joining Pump
    • How to Join Pump (3 easy steps)
      • Step 1 - View Estimate
      • Step 2 - Authorize Pump
      • Step 3 - Know your business
      • Finishing Touches
        • Inviting your team
        • Adding additional AWS accounts
        • Post onboarding
        • AWS Seller Registration
        • Sign up for Auto Pay
    • AWS Multi-account architecture
      • via 'Join Account(s)'
      • via 'Join With A Pre-Existing Org(s)'
      • Join via CTA
      • How Pump handles SSO
      • Leave an AWS Organization
    • AWS Role Deployment and Permissions
  • Maximizing Pump with AWS
    • Using Pump
      • Savings Summary
      • Past Savings
      • Reserved Instances
      • Savings Plans
      • Group buying discounts
      • Payments
      • Sales or Value added tax (VAT)
      • Credit FAQ
    • AWS Discount Prices
    • Pump Secure
    • AWS Credits FAQ
  • GCP: Joining Pump
    • Getting Started with GCP
      • Step 1 - View Savings Estimate
      • Step 2 - Authorize Pump
  • Azure: Joining Pump
    • Azure Role Deployment and Permissions
  • Pump University
    • Welcome to Pump University
  • Support
    • Fast & Free Support
    • Security & Access
      • Cross Account Role
      • Role Deployment
      • Access Management
      • Other Housekeeping
    • Invoices from AWS
    • Invoices from GCP
    • Request a Demo
    • Security Standards
    • Changing Infrastructure while on Pump
Powered by GitBook
On this page
  1. Support
  2. Security & Access

Role Deployment

PreviousCross Account RoleNextAccess Management

Last updated 10 months ago

Pump automates cross-account role deployment using (CFN) and, more specifically, "" These links enable Pump to pass a CFN template along with user-specific parameters, such as the cross-account role, external ID, Pump ID, and more.

Pump automates cross-account role deployment using AWS CloudFormation (CFN) and, more specifically, "quick-create links." These links enable Pump to pass a CFN template along with user-specific parameters, such as the cross-account role, external ID, Pump ID, and more.

Users only need to click the quick-create link and then click "deploy" to have the role deployed to their AWS account. The CFN templates are stored publicly, allowing users to review them before agreeing to the deployment:

(you can read more about these roles in the previous article, )

During deployment, after role creation, a list of properties is sent to Pump's management account:

  • Pump ID

  • Cross-account role ARN

  • Pump external ID

  • User's account ID

  • Role type (read-only or auto-pilot)

These properties are stored in Pump's database. If the deployment occurs during the last step, Pump will also invite the user's AWS account to join Pump's AWS Organization. If the user already belongs to an organization, this step will fail. We support existing organizations joining Pump on a case-by-case basis. Please contact our support team if this applies to you!

Lastly, we offer manual role deployment for customers who cannot work with CloudFormation.

Please contact our support team for more information.

AWS CloudFormation
quick-create links.
Read-only role
Auto-pilot role
here
support@pump.co