AWS CloudFormation Account Controls¶
Use this guide when the customer account owner adjusts CloudFormation controls in the customer-owned CloudFormation onboarding stack, AccountConfigSetup.
In the stack parameters, find the customer-controlled access parameters (grouped under Customer-controlled Omnistrate access when the console shows parameter groups):
AgentInfrastructureMutationEnabledcontrols AWS infrastructure changes through the account-config roles.DataplaneKubernetesAccessRolecontrols the Kubernetes permissions of the dataplane agent on selected BYOC PrivateLink host clusters.K8sDebugAccessEnabledcontrols the network path used for Omnistrate Kubernetes debug access on selected BYOC PrivateLink host clusters.DataplaneKubernetesAccessTargetsandK8sDebugAccessTargetsindependently scope the two Kubernetes controls.
The update runs in the AWS account that owns the stack and is visible in AWS CloudFormation history.
Control Parameters¶
| Parameter | Value | Result |
|---|---|---|
AgentInfrastructureMutationEnabled | true (default) | Allows Omnistrate agents to create, update, and delete AWS infrastructure when required for provisioning, updates, deletion, and reconciliation. |
AgentInfrastructureMutationEnabled | false | Disables AWS infrastructure mutation through the affected account-config roles by applying an explicit deny for non-read AWS actions while preserving read-only inspection. |
DataplaneKubernetesAccessRole | default (default) | Does not reconcile Kubernetes permissions and leaves the existing access role unchanged. The associated target list is ignored. A new host cluster without a previously persisted selection starts with admin access. |
DataplaneKubernetesAccessRole | admin | Grants the dataplane-agent service account the Kubernetes cluster-admin role required for normal lifecycle operations. |
DataplaneKubernetesAccessRole | read-only | Removes Kubernetes resource mutation access from the dataplane-agent service account. Existing deployments continue running, but provisioning, updates, scaling, repairs, and deletion that require Kubernetes writes are blocked. |
K8sDebugAccessEnabled | default (default) | Does not reconcile the debug network path and leaves its existing state unchanged. The associated target list is ignored. |
K8sDebugAccessEnabled | true | BYOC PrivateLink only. Allows access to the regional Manager Kubernetes API proxy port on the management VPC endpoint security groups. |
K8sDebugAccessEnabled | false | BYOC PrivateLink only. Removes access to the regional Manager Kubernetes API proxy port from the management VPC endpoint security groups. |
The default value is a no-op for the two Kubernetes controls, not a permission level or enabled/disabled state. To restore a specific state, select admin, read-only, true, or false explicitly.
Target Parameters¶
DataplaneKubernetesAccessTargets scopes DataplaneKubernetesAccessRole, while K8sDebugAccessTargets independently scopes K8sDebugAccessEnabled.
Use the following target formats:
| Target | Result |
|---|---|
us-west-2 | Applies the selected control to all Omnistrate-managed BYOC PrivateLink host clusters in the region. |
us-west-2:hc-xxxx | Applies the selected control only to the specified host cluster. |
us-west-2:hc-xxxx,us-east-1 | Applies the selected control to multiple comma-delimited targets. |
| Empty | Applies the selected control to all managed BYOC PrivateLink host clusters in all enabled AWS regions. |
An explicit region:host-cluster-id target that cannot be discovered causes the CloudFormation update to fail. A target list is ignored when its corresponding control is set to default.
Update the Stack¶
- Open the generated AWS CloudFormation update URL or command for the target AWS account.
- Keep generated parameters unchanged, including OIDC values, service account values,
ProvisionAccountConfig=true, and generated account-type or topology values such asIsBYOAAccountandIsBYOCPrivateAccount. - In the customer-controlled access parameters, set the required controls and their target parameters.
- Submit the stack update and wait for
UPDATE_COMPLETE.
Verify the State¶
After CloudFormation reaches UPDATE_COMPLETE, verify the stack parameters in the AWS CloudFormation console. The BYOC PrivateLink Kubernetes controls reconcile their targets as part of the CloudFormation update, so UPDATE_COMPLETE means the target operations for controls not set to default completed successfully. Controls set to default skip reconciliation and their target lists are ignored. To confirm per-target activity, review the stack events for the update.
For K8sDebugAccessEnabled, verify by attempting Omnistrate Kubernetes debug access to a target host cluster: with false, kubectl access through the debug path must fail; with true, it succeeds.
For AgentInfrastructureMutationEnabled, verify that the stack parameter matches the intended state. When the value is false, provisioning and lifecycle operations that require AWS changes can fail until you restore it to true.