This repository provides a collection of Terraform sub-modules used to provision the appropriate support roles and permissions within your AWS accounts. Each module is independently deployable and scoped to a specific support function.
Deploys into your AWS management account (where Control Tower and the Landing Zone Accelerator pipeline run). It provisions a cross-account IAM role that Appvia's support team can assume to monitor and troubleshoot the LZA deployment.
Key resources:
AppviaLZASupportRole— cross-account role with a trust policy scoped to Appvia's SSO roleAppviaLZASupportPolicy— grants view and trigger access to CodePipeline, CloudFormation, CodeBuild, and CodeCommitAppviaCostAnalysisSupportPolicy(optional) — grants read access to Cost Explorer, Billing, and Cost Optimization Hub; enabled viaenable_cost_analysis_support = true
→ Module README · Example
Deploys into your AWS Cost Analysis account (where CUDOS dashboards and CUR data are hosted). It provisions a cross-account IAM role that Appvia's team can assume to support the CUDOS platform and cost reporting tooling.
Key resources:
AppviaCostAnalysisSupportRole— cross-account role with a trust policy scoped to Appvia's SSO roleAppviaCudosSupportPolicy— grants access to QuickSight, Athena, Glue, S3 (CID/CUDOS buckets), Step Functions, Lambda, and CloudWatch Logs
→ Module README · Example
See the examples directory for sample deployments of each module.
No providers.
No inputs.
No outputs.
