Skip to content

docs: document Porter IAM role trust marker tags#259

Open
mintlify[bot] wants to merge 1 commit into
mainfrom
mintlify/469fcfda
Open

docs: document Porter IAM role trust marker tags#259
mintlify[bot] wants to merge 1 commit into
mainfrom
mintlify/469fcfda

Conversation

@mintlify
Copy link
Copy Markdown
Contributor

@mintlify mintlify Bot commented May 14, 2026

Summary

Documents the new tags that Porter applies to every IAM role it provisions in customer AWS accounts.

Context

The upstream change tags Porter-managed IAM roles with trust markers (porter.run/externally-assumable or porter.run/in-cluster) in addition to the existing porter.run/managed tag. These tags are visible in customers' AWS accounts and can be referenced from customer-authored SCPs, IAM policies, and audit tooling, so they need to be documented.

Changes

  • Added a Role tags section to security-and-compliance/aws-permissions.mdx that:
    • Lists each tag key, its value, and which roles receive it.
    • Notes that externally-assumable and in-cluster are mutually exclusive.
    • Includes an example SCP fragment showing how to scope a policy to Porter's externally-assumable roles using aws:PrincipalTag.

@mintlify
Copy link
Copy Markdown
Contributor Author

mintlify Bot commented May 14, 2026

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
porter 🟢 Ready View Preview May 14, 2026, 9:28 PM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants