Skip to main content

Shared Role

Before the Combine Team can deploy Combine to the AWS Account you provide, you deploy a shared IAM Role that we can assume. We provide this role as an AWS CloudFormation Template.

CloudFormation Template​

  1. Deploy the CloudFormation Template as a CloudFormation Stack, preferably in the same AWS Region where Combine will be deployed. For help, see the AWS documentation on creating a CloudFormation Stack from the console.
  2. After the CloudFormation Stack deploys successfully, give the Combine Support Team the AWS Account ID of the AWS Account.

CloudFormation Template - Advanced Configuration​

The CloudFormation Template has several CloudFormation Parameters that support advanced use cases:

CloudFormation ParameterDescription
EnablePermissionsFollowerAccountCredentialsSet to true for certain Combine network topologies.
ProvisioningRoleNameOverrideChanges the default name of the Combine Provisioning Role. The default name is Combine-Provisioning-Role.
PrincipalAccountSet to true to allow the Combine Provisioning Role to be assumed from a Combine DevOps account. The default value is true.
PrincipalAccountNumberOverrideChanges the default account number for the Combine DevOps account. Use this if you deploy Combine yourself with the internal automation tool.
PrincipalEC2Set to true to create an EC2 Instance Profile for the Combine Provisioning Role. Use this if you deploy Combine yourself with the internal automation tool.
ReadOnlyModeSet to true to restrict the Combine Provisioning Role to ReadOnlyAccess. Use this to limit the Combine Team's access to your account after a deployment, if desired.