Add jpodivin access to AWS #13464

Open
opened 2026-07-16 10:57:27 +00:00 by msuchy · 3 comments

Description of request

I want to request @jpodivin access to AWS.

Jiri Podivin is a member of the Logdetective team. He has been using an instance in EC2 as part of aws-copr. He did not need access to AWS as I spawned the machine for him and added him to the SSH access key.

Now he resolved that instead of using a standalone machine for interference, it would be easier and cheaper to use the AWS Bedrock service.

I created in AWS IAM the role aws-logdetective that has access to Bedrock, and is coupled to Fedora identity provider. But the next step is to configure FAS (if I understand it correctly) to allow usage of the aws role. And this is what I am unable to set up.
Can you please finish the configuration?

### Description of request I want to request @jpodivin access to AWS. Jiri Podivin is a member of the Logdetective team. He has been using an instance in EC2 as part of aws-copr. He did not need access to AWS as I spawned the machine for him and added him to the SSH access key. Now he resolved that instead of using a standalone machine for interference, it would be easier and cheaper to use the AWS Bedrock service. I created in AWS IAM the role aws-logdetective that has access to Bedrock, and is coupled to Fedora identity provider. But the next step is to configure FAS (if I understand it correctly) to allow usage of the aws role. And this is what I am unable to set up. Can you please finish the configuration?
Owner

So, you want this to be a new aws-bedrock role with group, etc? If that then https://docs.fedoraproject.org/en-US/infra/sysadmin_sops/aws-access/#_adding_a_role_to_aws_iam is the process (needs a new fas group, ipsilon changes and aws changes)

Or did you just want existing aws-logdetective role to be able to use it? In that case you should be able to just add that iam policy to the existing aws-logdetective role?

So, you want this to be a new aws-bedrock role with group, etc? If that then https://docs.fedoraproject.org/en-US/infra/sysadmin_sops/aws-access/#_adding_a_role_to_aws_iam is the process (needs a new fas group, ipsilon changes and aws changes) Or did you just want existing aws-logdetective role to be able to use it? In that case you should be able to just add that iam policy to the existing aws-logdetective role?
Owner

@msuchy any thoughts on the above?

@msuchy any thoughts on the above?
Author

Sorry for the delay. I want the latter - the existing aws-logdetective role to be able to use.
But the aws-logdetective is something I created just moments before I created this ticket. So I will need to go though that SOP you linked (thank you for that).
I.e. can you please create the FAS group aws-logdetective and make jpodivin member and sponsor of this group for a start?

Sorry for the delay. I want the latter - the existing aws-logdetective role to be able to use. But the aws-logdetective is something I created just moments before I created this ticket. So I will need to go though that SOP you linked (thank you for that). I.e. can you please create the FAS group `aws-logdetective` and make jpodivin member and sponsor of this group for a start?
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
infra/tickets#13464
No description provided.