AWS Cloud Account Onboarding
Learn about AWS cloud account onboarding prerequisites and the onboarding
workflow in Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS AI Runtime Security in
AWS
|
|
Onboarding your AWS cloud account connects it to Strata Cloud Manager so Prisma® AIRS™
can discover and protect your AI workloads. Without onboarding, Prisma AIRS cannot
see your cloud resources or intercept AI traffic flowing through containers, virtual
machines, or serverless functions in your AWS environment.
The onboarding process uses a Terraform template you download from
Strata Cloud Manager
to create a service account in your AWS environment. The service account grants Prisma
AIRS the permissions it needs to read network flow logs, enumerate assets such as EKS
clusters, EC2 instances, Lambda functions, and Bedrock models, and—if you choose—
orchestrate security VPCs and redirect application traffic through the AI Runtime
firewall.
AWS Required Permissions lists the specific permissions
requested for each function you enable.
Before running the onboarding workflow in
Strata Cloud Manager, complete the
AWS Cloud Account Onboarding Prerequisites: create an S3
bucket for VPC flow log storage, enable VPC flow logs and Bedrock model invocation
logging to that bucket, configure your EKS clusters for IAM-based authentication,
and assign IAM roles so your EC2 instances and pods can invoke Bedrock models.
After completing the prerequisites, use
Onboard AWS Cloud Account in Strata Cloud Manager to select
permission scopes, define application boundaries for asset grouping, download and
apply the Terraform template in AWS, and validate asset discovery. Initial discovery
data populates in approximately 30 minutes; VPC flow log data may take up to an
hour to appear.