Kosli Capture is still in active development. Its capabilities and configuration format may change, and onboarding is done together with Kosli’s Customer Success team.
Kosli capture permissions
The Kosli Capture managed service uses the public AWS, GCP and Azure APIs to extract information about your cloud environments. In order to do this, you need to provide Kosli with an IAM role that allows access to these APIs. The role is created and owned by you. Kosli publishes a CloudFormation template, for use in AWS, showing the permissions needed. The template is publicly accessible and can be used directly within an aws cloudformation create-stack call.
Assume role
The IAM role defined within the CloudFormation template includes an “assume role” policy granting permission from Kosli. This appears as:
All permissions needed
The IAM role defined within the Cloudformation template includes a number of IAM policy statements, granting read-only access to some AWS APIs. The statements are: