-
Epic
-
Resolution: Done
-
Critical
-
None
Goals
The goal is allow administrators to use an STS Role for authentication to Cloudwatch in lieu of a access token and credentials.
Non-Goals
Motivation
There is a larger movement with OpenShift to improve security by depending upon a role that allows token rotation instead of static tokens that would be required to be rotated manually.
Alternatives
Acceptance Criteria
- Verify CLF writes logs to CW using the STS Role instead of an access token
Risk and Assumptions
Documentation Considerations
- Update the CLF documentation to include the opinionated key for the role