Opal + AWS EKS

Integration Overview

Opal lets you define fine-grained access controls to Kubernetes clusters on EKS using federated IAM sessions. This simplifies and unifies access controls to AWS IAM while enabling developers to connect easily and request new access to many different clusters. Similar to other integrations, sessions are logged and captured with solid attribution.

Use cases

  • Implement Least Privilege - With Opal, customers are able to adopt granular and ephemeral access to critical resources
  • Accelerate Access Requests - Customers can delegate approvals to resource owners/managers and accelerate approvals via one-click in Slack
  • Streamline User Onboarding - Integrated with popular identity providers, customers can bind resource level access to native group structures
  • Configure break glass access - Opal enables customers to automate emergency break-glass access via integrations with on-call providers and manual pre-approvals
  • Automate Access Reviews - Opal offers end-to-end automation for user access reviews -  snapshotting user lists, notifying reviewers, providing a self-service review workflow, and generating automated reports

How it works

You can set up the AWS integration in minutes:

  • Select Amazon Web Services from the Application catalog
  • Tag infrastructure in AWS
  • Create IAM user for Opal
  • Create IAM user connection

Integrate