Plerion AWS integration API
In order to connect your AWS account to Plerion or update existing account, you will need, CloudFormation Template URL. Retrieve the template from Get CloudFormation template External Id of the tenant. Retrieve the External Id from Get the external id of the tenant Plerion AWS Account Id. The value will always be 588158338731 Temporary Auth Token. Token to be passed to CloudFormation template that auto registers the AWS integration. Retrieve the temporary auth token from Generate temporary token for creating AWS integration Plerion API URL. The value will always be au.api.plerion.com Select Capabilities. Select CSPM for CSPM only capability or ALL for both CSPM and CWPP capability. Select KMSKeyAccessMode. When CWPP is enabled, you can choose the KMS Key access mode to facilitate Plerion's access to keys for decrypting volumes, images, and lambda code. In the ALL_KEYS mode, Plerion is granted access to all KMS keys in the account. However, you have the option to restrict access to certain keys by applying the "PlerionAccess: Denied" tag. Alternatively, the SELECTED_KEYS mode allows Plerion access solely to the KMS keys that have been tagged with "PlerionAccess: Granted". Passing the parameters to the CloudFormation template will create a new AWS integration or update existing integration. Quick Start Follow the guide to create a new AWS integration or update existing integration using curl command. Note: Replace {$PLERION_API_KEY} with your API key. Create a new AWS Integration export PLERION_API_URL=au.api.plerion.com export PLERION_API_KEY={$PLERION_API_KEY} export PLERION_AWS_ACCOUNT_ID=588158338731 # Fetch the template URL export TEMPLATE_URL=$(curl -s GET "https://$PLERION_API_URL/v1/tenant/cloudformation-templates?type=AWSAccount" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.templateURL') # Generate the temporary auth token export TEMP_AUTH_TOKEN=$(curl -s -X POST "https://$PLERION_API_URL/v1/tenant/integrations/token" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.token') # Fetch the external ID export EXTERNAL_ID=$(curl -s -X GET "https://$PLERION_API_URL/v1/tenant/external-id" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.externalId') # Create the stack export PLERION_STACK_NAME=plerion-aws-integration aws cloudformation create-stack --stack-name $PLERION_STACK_NAME --template-url $TEMPLATE_URL --capabilities CAPABILITY_NAMED_IAM \ --parameters ParameterKey=ExternalId,ParameterValue=$EXTERNAL_ID \ ParameterKey=PlerionAccountId,ParameterValue=$PLERION_AWS_ACCOUNT_ID \ ParameterKey=AuthToken,ParameterValue=$TEMP_AUTH_TOKEN \ ParameterKey=Capabilities,ParameterValue=ALL \ ParameterKey=KMSKeyAccessMode,ParameterValue="ALL_KEYS" \ ParameterKey=PlerionURL,ParameterValue=$PLERION_API_URL # Wait for the stack to complete aws cloudformation wait stack-create-complete --stack-name $PLERION_STACK_NAME Update an existing AWS Integration export PLERION_API_URL=au.api.plerion.com export PLERION_API_KEY={$PLERION_API_KEY} export PLERION_AWS_ACCOUNT_ID=588158338731 # Fetch the template URL export TEMPLATE_URL=$(curl -s GET "https://$PLERION_API_URL/v1/tenant/cloudformation-templates?type=AWSAccount" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.templateURL') # Generate the temporary auth token export TEMP_AUTH_TOKEN=$(curl -s -X POST "https://$PLERION_API_URL/v1/tenant/integrations/token" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.token') # Fetch the external ID export EXTERNAL_ID=$(curl -s -X GET "https://$PLERION_API_URL/v1/tenant/external-id" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.externalId') # Update an existing stack export PLERION_STACK_NAME=plerion-aws-integration aws cloudformation update-stack --stack-name $PLERION_STACK_NAME --template-url $TEMPLATE_URL --capabilities CAPABILITY_NAMED_IAM \ --parameters ParameterKey=ExternalId,ParameterValue=$EXTERNAL_ID \ ParameterKey=PlerionAccountId,ParameterValue=$PLERION_AWS_ACCOUNT_ID \ ParameterKey=AuthToken,ParameterValue=$TEMP_AUTH_TOKEN \ ParameterKey=Capabilities,ParameterValue=ALL \ ParameterKey=KMSKeyAccessMode,ParameterValue="ALL_KEYS" \ ParameterKey=PlerionURL,ParameterValue=$PLERION_API_URL # Wait for the stack to complete aws cloudformation wait stack-update-complete --stack-name $PLERION_STACK_NAME