Skip to content

AWS CloudFormation Account Controls

Use this guide when the customer account owner adjusts CloudFormation controls in the customer-owned CloudFormation onboarding stack, AccountConfigSetup.

In the stack parameters, find the customer-controlled access parameters (grouped under Customer-controlled Omnistrate access when the console shows parameter groups):

  • AgentInfrastructureMutationEnabled controls AWS infrastructure changes through the account-config roles.
  • DataplaneKubernetesAccessRole controls the Kubernetes permissions of the dataplane agent on selected BYOC PrivateLink host clusters.
  • K8sDebugAccessEnabled controls the network path used for Omnistrate Kubernetes debug access on selected BYOC PrivateLink host clusters.
  • DataplaneKubernetesAccessTargets and K8sDebugAccessTargets independently scope the two Kubernetes controls.

The update runs in the AWS account that owns the stack and is visible in AWS CloudFormation history.

Control Parameters

Parameter Value Result
AgentInfrastructureMutationEnabled true (default) Allows Omnistrate agents to create, update, and delete AWS infrastructure when required for provisioning, updates, deletion, and reconciliation.
AgentInfrastructureMutationEnabled false Disables AWS infrastructure mutation through the affected account-config roles by applying an explicit deny for non-read AWS actions while preserving read-only inspection.
DataplaneKubernetesAccessRole default (default) Does not reconcile Kubernetes permissions and leaves the existing access role unchanged. The associated target list is ignored. A new host cluster without a previously persisted selection starts with admin access.
DataplaneKubernetesAccessRole admin Grants the dataplane-agent service account the Kubernetes cluster-admin role required for normal lifecycle operations.
DataplaneKubernetesAccessRole read-only Removes Kubernetes resource mutation access from the dataplane-agent service account. Existing deployments continue running, but provisioning, updates, scaling, repairs, and deletion that require Kubernetes writes are blocked.
K8sDebugAccessEnabled default (default) Does not reconcile the debug network path and leaves its existing state unchanged. The associated target list is ignored.
K8sDebugAccessEnabled true BYOC PrivateLink only. Allows access to the regional Manager Kubernetes API proxy port on the management VPC endpoint security groups.
K8sDebugAccessEnabled false BYOC PrivateLink only. Removes access to the regional Manager Kubernetes API proxy port from the management VPC endpoint security groups.

The default value is a no-op for the two Kubernetes controls, not a permission level or enabled/disabled state. To restore a specific state, select admin, read-only, true, or false explicitly.

Target Parameters

DataplaneKubernetesAccessTargets scopes DataplaneKubernetesAccessRole, while K8sDebugAccessTargets independently scopes K8sDebugAccessEnabled.

Use the following target formats:

Target Result
us-west-2 Applies the selected control to all Omnistrate-managed BYOC PrivateLink host clusters in the region.
us-west-2:hc-xxxx Applies the selected control only to the specified host cluster.
us-west-2:hc-xxxx,us-east-1 Applies the selected control to multiple comma-delimited targets.
Empty Applies the selected control to all managed BYOC PrivateLink host clusters in all enabled AWS regions.

An explicit region:host-cluster-id target that cannot be discovered causes the CloudFormation update to fail. A target list is ignored when its corresponding control is set to default.

Update the Stack

  1. Open the generated AWS CloudFormation update URL or command for the target AWS account.
  2. Keep generated parameters unchanged, including OIDC values, service account values, ProvisionAccountConfig=true, and generated account-type or topology values such as IsBYOAAccount and IsBYOCPrivateAccount.
  3. In the customer-controlled access parameters, set the required controls and their target parameters.
  4. Submit the stack update and wait for UPDATE_COMPLETE.

Verify the State

After CloudFormation reaches UPDATE_COMPLETE, verify the stack parameters in the AWS CloudFormation console. The BYOC PrivateLink Kubernetes controls reconcile their targets as part of the CloudFormation update, so UPDATE_COMPLETE means the target operations for controls not set to default completed successfully. Controls set to default skip reconciliation and their target lists are ignored. To confirm per-target activity, review the stack events for the update.

For K8sDebugAccessEnabled, verify by attempting Omnistrate Kubernetes debug access to a target host cluster: with false, kubectl access through the debug path must fail; with true, it succeeds.

For AgentInfrastructureMutationEnabled, verify that the stack parameter matches the intended state. When the value is false, provisioning and lifecycle operations that require AWS changes can fail until you restore it to true.