Image with AWS CLI and LastPass CLI installed
979
A module that pre-provisions emergency access users.
Users provisioned with this module have usernames and passwords automatically generated and saved to LastPass and have MFA enabled. The MFA seed is encrypted and saved to the parameter store of a central account.
In the event of emergency access users that have access to the account credentials in LastPass and have access to push to a specified GitHub repository can request to have the MFA seed emailed to them and gain access to the sealed account.
requests and processed-requests folders to the break-the-seal requests repositoryplaceholder to the directories created so that the directories exist when checked out
of git..github/workflows/upload-to-s3.yml
name: Upload to S3
on:
push:
branches: [ master ]
jobs:
upload:
if: "!contains(github.event.head_commit.message, '[skip ci]')"
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
with:
ssh-key: ${{ secrets.DEPLOY_KEY }}
ssh-strict: no
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v1
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY}}
aws-region: eu-west-1
- name: Zip Repo
run: |
zip -r ${GITHUB_SHA::7}.zip .
- name: Upload to S3
run: |
aws s3 cp ${GITHUB_SHA::7}.zip s3://<AWS ACCOUNT NUMBER>-<BUCKET NAME>/${GITHUB_SHA::7}.zip
Obtain AWS credentials / temporary credentials (aws-azure-login, vaulted, aws-vault).
Clone this repo.
(Optional) if you are going to seal many accounts export the following variables so that you don't have to enter them each time.
export LASTPASS_USERNAME=<mylastpass_username>export ROLE_ARN=<role to assume in central account>export KMS_KEY_ID=<kms key id - use the ID not the full ARN>From the root of this repo run make sealand follow the dialogue.
Running make seal on an account that already has a user called break.the.seal.user will first delete the existing
user and can be used to reseal an account once the seal has been broken
Content type
Image
Digest
Size
383 MB
Last updated
about 6 years ago
docker pull vydev/break-the-seal