Configure a GovCloud Account Using IAM Access Keys

If your organization requires you to use IAM access keys, use the instructions in this topic. If your organization requires a more secure method to credential your GovCloud account and you are using the AMI product, review the Configure a GovCloud Account Using a Cross-Account Role (AMI only) topic.

AWS GovCloud is an isolated cloud region that hosts sensitive data and regulated workloads for customers who must comply with strict US government security and compliance requirements. Only companies or organizations operated by employees who are US citizens working on US soil can access the AWS GovCloud environment.

Because AWSGovCloud operates under such strict requirements, its configuration is a little more complicated than your standard commercial AWS account.

In a standard commercial account, you need one set of credentials—an IAM access key and secret key—to connect your CloudCheckr and AWS accounts:

In a GovCloud configuration, all AWS GovCloud activity, usage, and billing is managed through a standard AWS account or linked commercial account so you need two sets of credentials: one for your GovCloud account and one for your commercial linked account:


Determine Your Payer

Before CloudCheckr can ingest the cost data from your AWS GovCloud account, you must provide the payer credentials.

Who the payer is depends on your GovCloud setup:

Scenario

Use Credentials From

CloudCheckr Configuration

Master Payer account directly linked to GovCloud account

Master Payer

Master Payer and GovCloud accounts

Linked Commercial account is a payee of the Master Payer account

Linked Commercial

Master Payer, Linked Commercial, and GovCloud accounts

Because AWS stores the billing data in the Master Payer account and payees cannot access this data directly, you must set up the Master Payer and its payees as separate accounts.

CloudCheckr will correctly disperse the billing data to each of the payees.

If your Linked Commercial account is one of multiple payees but you used the Master Payer account credentials, you could see duplicate costs in your payee accounts.

Procedure

Click each step to learn how to configure a GovCloud account using a cross-account role.

Since it is the most common setup, these instructions are tailored to the GovCloud scenario where a linked commercial account is a payee of a Master Payer account.
A Master Payer account is required so that CloudCheckr can ingest the cost data from the GovCloud region.

All GovCloud activity, usage, and billing is managed through a standard AWS account referred to as the linked commercial account.


How did we do?