Permissions Reference

Consolidated view of all cloud provider permissions required by DigiUsher

Overview

DigiUsher needs read-only access to the cost, usage, resource, and metrics data in your cloud environments. This page lists the permissions for each supported cloud provider.

DigiUsher asks for write access only when you enable an optional feature. These features are AWS EC2 scheduling, AWS commitment purchases, and the Azure Terraform flag enable_power_scheduler that starts and deallocates virtual machines.

Cross-Cloud Summary

CloudIdentity TypeAuthenticationAccess LevelScope
AWSCross-account IAM RoleSTS AssumeRole + ExternalId (temporary tokens)Read-onlyPer-account (root or linked)
GCPService AccountJSON keyRead-only (viewer roles)Organization-wide or per-project
AzureApp RegistrationClient secretRead-only (Reader role)Management Group (all subscriptions)
OCIIAM UserAPI key pair (PEM + fingerprint)Read-onlyTenancy-wide
Alibaba CloudRAM UserAccess Key ID + Access Key SecretRead-only (OSS object listing and download)Single OSS bucket holding the FOCUS export
KubernetesIn-cluster agent (Helm chart)Agent API token issued by DigiUsherRead-only (Kubernetes API object metadata and node metrics via ClusterRole)Per cluster

Amazon Web Services (AWS)

Access Summary

ComponentDetails
Identity typeCross-account IAM Role (no credentials stored in your account)
AuthenticationSTS AssumeRole with ExternalId. Temporary session tokens only
Trust relationshipCross-account IAM role trusting DigiUsher AWS account 058264546051 with ExternalId
Base permissionsRead-only across cost, compute, database, storage, networking, security, and organizational metadata
Optional permissionsEC2 start and stop, commitment purchases, tag management, and automation. All of these are off by default
Data accessThe S3 bucket with the Cost and Usage Reports. DigiUsher reads the CUR data only
ScopeSingle AWS account (root or linked)
CapabilityWhat It Provides
Billing dataCost analytics, chargeback and showback, budgeting, forecasting, anomaly detection
Resource inventoryAsset discovery, idle resource detection, tag-based cost allocation
Optimization recommendationsRightsizing, commitment analysis (RI/SP), idle resource cleanup
Utilization metricsCPU, memory, network, disk usage for rightsizing analysis

DigiUsher cannot create, change, or delete an AWS resource. The only exception is an optional write permission that you enable yourself.

Core Permissions (Read-Only)

DigiUsher attaches the IAM policy that follows (DigiUsherCorePermissions) to its IAM role as an inline policy:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DigiUsherCostAndBillingPermissions",
      "Effect": "Allow",
      "Action": [
        "ce:Describe*",
        "ce:Get*",
        "cur:Describe*",
        "cur:Get*",
        "bcm-data-exports:ListExports",
        "bcm-data-exports:GetExport",
        "budgets:ViewBudget",
        "savingsplans:DescribeSavingsPlans",
        "savingsplans:DescribeSavingsPlansOfferings",
        "savingsplans:DescribeSavingsPlansOfferingRates",
        "invoicing:GetInvoicePDF",
        "invoicing:GetInvoiceUnit",
        "invoicing:GetInvoiceSummary",
        "invoicing:ListInvoiceSummaries",
        "invoicing:BatchGetInvoiceProfile",
        "pricing:GetProducts"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherComputePermissions",
      "Effect": "Allow",
      "Action": [
        "ec2:Describe*",
        "autoscaling:Describe*",
        "application-autoscaling:Describe*",
        "lambda:GetFunction",
        "lambda:GetFunctionConfiguration",
        "lambda:GetPolicy",
        "lambda:GetProvisionedConcurrencyConfig",
        "lambda:List*",
        "ecs:Describe*",
        "ecs:List*",
        "eks:Describe*",
        "eks:List*",
        "elasticloadbalancing:Describe*",
        "compute-optimizer:Get*",
        "compute-optimizer:UpdateEnrollmentStatus"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherDatabasePermissions",
      "Effect": "Allow",
      "Action": [
        "rds:DescribeDBInstances",
        "rds:DescribeDBClusters",
        "rds:DescribeReservedDBInstances",
        "rds:DescribeReservedDBInstancesOfferings",
        "rds:ListTagsForResource",
        "dynamodb:Describe*",
        "dynamodb:List*",
        "elasticache:Describe*",
        "elasticache:List*",
        "es:Describe*",
        "es:List*",
        "redshift:Describe*",
        "redshift:List*",
        "docdb:Describe*",
        "docdb:List*",
        "neptune:Describe*",
        "neptune:List*",
        "timestream:DescribeEndpoints",
        "timestream:DescribeDatabase",
        "timestream:DescribeTable",
        "timestream:ListDatabases",
        "timestream:ListTables",
        "dms:Describe*",
        "dms:List*",
        "memorydb:Describe*",
        "memorydb:List*"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherStoragePermissions",
      "Effect": "Allow",
      "Action": [
        "s3:GetBucketAcl",
        "s3:GetBucketLocation",
        "s3:GetBucketPolicyStatus",
        "s3:GetBucketPublicAccessBlock",
        "s3:GetBucketTagging",
        "s3:GetLifecycleConfiguration",
        "s3:GetIntelligentTieringConfiguration",
        "s3:ListAllMyBuckets",
        "elasticfilesystem:Describe*",
        "fsx:Describe*",
        "glacier:Describe*",
        "glacier:List*",
        "ecr:Describe*",
        "ecr:List*",
        "ecr:GetLifecyclePolicy",
        "backup:Describe*",
        "backup:List*",
        "backup:GetBackupPlan"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherNetworkingAndCDNPermissions",
      "Effect": "Allow",
      "Action": [
        "cloudfront:GetDistributionConfig",
        "cloudfront:ListDistributions",
        "route53:List*",
        "route53:GetHostedZone",
        "apigateway:GET"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherDataAndAnalyticsPermissions",
      "Effect": "Allow",
      "Action": [
        "glue:GetJobs",
        "glue:GetCrawlers",
        "glue:GetDatabases",
        "glue:ListJobs",
        "glue:ListCrawlers",
        "elasticmapreduce:DescribeCluster",
        "elasticmapreduce:DescribeInstanceGroups",
        "elasticmapreduce:ListClusters",
        "elasticmapreduce:ListInstances",
        "elasticmapreduce:ListInstanceGroups",
        "states:DescribeStateMachine",
        "states:ListStateMachines",
        "states:ListExecutions",
        "athena:List*",
        "athena:GetWorkGroup",
        "kinesis:Describe*",
        "kinesis:List*",
        "kafka:Describe*",
        "kafka:List*",
        "quicksight:List*",
        "quicksight:DescribeDashboard",
        "quicksight:DescribeAccountSubscription",
        "sagemaker:List*",
        "sagemaker:DescribeEndpoint",
        "sagemaker:DescribeNotebookInstance"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherMessagingPermissions",
      "Effect": "Allow",
      "Action": [
        "sqs:List*",
        "sqs:GetQueueAttributes",
        "sns:List*",
        "sns:GetTopicAttributes",
        "ses:GetSendQuota",
        "ses:ListIdentities",
        "mq:Describe*",
        "mq:List*",
        "events:Describe*",
        "events:List*"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherMonitoringAndLoggingPermissions",
      "Effect": "Allow",
      "Action": [
        "cloudwatch:Get*",
        "cloudwatch:List*",
        "cloudtrail:Describe*",
        "cloudtrail:GetTrailStatus",
        "cloudtrail:List*",
        "logs:DescribeLogGroups"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherSecurityAndCompliancePermissions",
      "Effect": "Allow",
      "Action": [
        "iam:GetAccessKeyLastUsed",
        "iam:GetLoginProfile",
        "iam:ListAccessKeys",
        "iam:ListUsers",
        "sso:List*",
        "sso:Describe*",
        "identitystore:List*",
        "identitystore:Describe*",
        "kms:List*",
        "kms:DescribeKey",
        "secretsmanager:List*",
        "secretsmanager:DescribeSecret",
        "guardduty:List*",
        "guardduty:GetDetector",
        "securityhub:GetEnabledStandards",
        "securityhub:DescribeHub",
        "wafv2:List*",
        "wafv2:GetWebACL",
        "config:Describe*",
        "config:GetDiscoveredResourceCounts"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherResourceExplorerPermissions",
      "Effect": "Allow",
      "Action": [
        "resource-explorer-2:Get*",
        "resource-explorer-2:List*",
        "resource-explorer-2:BatchGetView",
        "resource-explorer-2:Search"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherRAMPermissions",
      "Effect": "Allow",
      "Action": [
        "ram:GetResourceShares",
        "ram:ListResources",
        "ram:ListPrincipals"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherOrganizationsAndTaggingPermissions",
      "Effect": "Allow",
      "Action": [
        "organizations:DescribeAccount",
        "organizations:DescribeOrganization",
        "organizations:DescribeOrganizationalUnit",
        "organizations:ListAccounts",
        "organizations:ListAccountsForParent",
        "organizations:ListChildren",
        "organizations:ListOrganizationalUnitsForParent",
        "organizations:ListParents",
        "organizations:ListRoots",
        "organizations:ListTagsForResource",
        "tag:GetResources",
        "tag:GetTagKeys",
        "tag:GetTagValues",
        "resourcegroups:GetGroup",
        "resourcegroups:ListGroups",
        "servicequotas:Get*",
        "servicequotas:List*"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherSustainabilityPermissions",
      "Effect": "Allow",
      "Action": [
        "sustainability:GetCarbonFootprintSummary"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherTrustedAdvisorPermissions",
      "Effect": "Allow",
      "Action": [
        "trustedadvisor:Describe*",
        "trustedadvisor:Get*",
        "trustedadvisor:List*"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DigiUsherMarketplacePermissions",
      "Effect": "Allow",
      "Action": [
        "aws-marketplace:ListEntities"
      ],
      "Resource": "*"
    }
  ]
}

S3 CUR Access (Root/Payer Accounts Only)

A second inline policy (DigiUsherS3CURAccess) gives read access to the S3 bucket that holds the Cost and Usage Reports:

Replace YOUR_BUCKET_NAME with your actual bucket name:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DigiUsherCURPermissions",
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:ListBucket"
      ],
      "Resource": [
        "arn:aws:s3:::YOUR_BUCKET_NAME",
        "arn:aws:s3:::YOUR_BUCKET_NAME/*"
      ]
    }
  ]
}

S3 Bucket Policy (Billing Services)

The S3 bucket that holds the CUR data needs a bucket policy. This policy lets the AWS billing services write the reports:

Replace YOUR_BUCKET_NAME and YOUR_ACCOUNT_ID with your actual values:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowBillingServiceAccess",
      "Effect": "Allow",
      "Principal": {
        "Service": [
          "billingreports.amazonaws.com",
          "bcm-data-exports.amazonaws.com"
        ]
      },
      "Action": [
        "s3:GetBucketAcl",
        "s3:GetBucketPolicy",
        "s3:PutObject"
      ],
      "Resource": [
        "arn:aws:s3:::YOUR_BUCKET_NAME",
        "arn:aws:s3:::YOUR_BUCKET_NAME/*"
      ],
      "Condition": {
        "StringLike": {
          "aws:SourceArn": [
            "arn:aws:cur:us-east-1:YOUR_ACCOUNT_ID:definition/*",
            "arn:aws:bcm-data-exports:us-east-1:YOUR_ACCOUNT_ID:export/*"
          ]
        },
        "StringEquals": {
          "aws:SourceAccount": "YOUR_ACCOUNT_ID"
        }
      }
    }
  ]
}

Optional Permissions

These permissions are off by default. If you need one of them, add it as a separate inline policy on the DigiUsher IAM role.

What DigiUsher CAN Access (Read-Only)

  • The cost data and the usage data in S3, which are the CUR exports
  • The resource metadata, such as names, types, regions, and tags, of the compute, database, storage, networking, and security services
  • The utilization metrics in CloudWatch
  • The optimization recommendations of Compute Optimizer and Trusted Advisor
  • The information about the Reserved Instances and the Savings Plans
  • The hierarchy of the organization, the accounts, and the organizational units

The core policy contains compute-optimizer:UpdateEnrollmentStatus. This action enrolls the account one time, and it enables the recommendations of Compute Optimizer. It does not create, change, or delete your resources. You can remove this permission. Without it, DigiUsher gives no rightsizing recommendations from Compute Optimizer.

What DigiUsher CANNOT Do

  • Create, change, or delete an AWS resource. The only exception is an optional write permission that you enable yourself
  • Read application data, databases, or the content of your storage. It reads the CUR data only
  • Change an IAM policy or a permission
  • Read secrets, credentials, or encryption keys
  • Read network traffic or the content of your logs
  • Buy a product or change the billing configuration. The only exception is the optional permission for commitment purchases

Google Cloud Platform (GCP)

Access Summary

ComponentDetails
IdentityGCP service account (digiusher-finops). It uses the API only, and it has no Console login
AuthenticationJSON key. By default it does not expire
Access levelRead-only. Every role is a viewer role or a reader role
ScopeThe whole organization, which DigiUsher recommends, or selected projects
BillingBilling Viewer on a single billing account
Data accessThe BigQuery billing export dataset only. DigiUsher cannot read another dataset
CapabilityWhat It Provides
Billing dataCost analytics, chargeback and showback, budgeting, forecasting, anomaly detection
Resource inventoryAsset discovery, idle resource detection, tag-based cost allocation
Optimization recommendationsVM rightsizing, CUD/reservation analysis, idle resource cleanup
Utilization metricsCPU, memory, network, disk usage for rightsizing analysis

DigiUsher cannot create, change, or delete a GCP resource.

Roles and APIs

Billing Account

RolePurpose
Billing Account ViewerView billing data and cost information

Organization

RolePurpose
BrowserBrowse org/folder/project hierarchy
Tag ViewerRead tags for chargeback/showback
Cloud Asset ViewerResource inventory across projects
Recommender ViewerCost optimization recommendations
Compute ViewerView CUDs, reservations, and Compute resources
Cloud SQL ViewerView Cloud SQL details and commitments
BigQuery Resource ViewerView BigQuery resource metadata for recommendations
Monitoring ViewerRead utilization metrics

Project

RolePurpose
BigQuery Job UserExecute billing queries
BigQuery Read Session UserEfficient parallel data reads via Storage Read API
Service Usage ConsumerRequired for Cloud Asset API calls

BigQuery Dataset

RolePurpose
BigQuery Data ViewerRead billing export data

APIs

These APIs must be enabled in the project that holds the service account:

  • bigquery.googleapis.com
  • cloudbilling.googleapis.com
  • cloudresourcemanager.googleapis.com
  • iam.googleapis.com
  • cloudasset.googleapis.com
  • recommender.googleapis.com
  • compute.googleapis.com
  • sqladmin.googleapis.com
  • monitoring.googleapis.com

What DigiUsher CAN Access (Read-Only)

  • The billing data and the cost data in BigQuery
  • The resource metadata, such as names, types, regions, labels, and tags
  • The utilization metrics for CPU, memory, network, and disk, in Cloud Monitoring
  • The optimization recommendations of the Recommender API of Google
  • The information about the CUDs and the reservations
  • The hierarchy of the organization, the folders, and the projects

What DigiUsher CANNOT Do

  • Create, change, or delete a GCP resource
  • Read application data, databases, or the content of your storage
  • Change an IAM policy or a permission
  • Read secrets, credentials, or encryption keys
  • Read network traffic or the content of your logs
  • Buy a product or change the billing configuration
  • Read a BigQuery dataset that is not the billing export dataset

Scope Controls

  • To limit the access to selected projects, and not to the whole organization, set target_project_ids in Terraform
  • The BigQuery access always covers the billing export dataset only, also with access to the whole organization
  • The Billing Viewer role covers one billing account only

Microsoft Azure

Access Summary

ComponentDetails
IdentityAzure App Registration (DigiUsherApp). It is a service principal, without an interactive login
AuthenticationClient secret. DigiUsher recommends an expiry of 24 months
Access levelRead-only. The Reader role at the level of the Management Group
ScopeAll subscriptions under the root Management Group
BillingFOCUS cost export from your billing scope: EA, MCA, or MPA
Data accessStorage Blob Data Reader on the cost export storage account only
CapabilityWhat It Provides
Billing dataCost analytics, chargeback and showback, budgeting, forecasting, anomaly detection
Resource inventoryAsset discovery, idle resource detection, tag-based cost allocation
Optimization recommendationsReservation and Savings Plan analysis, idle resource cleanup
Utilization metricsResource usage for rightsizing analysis

DigiUsher cannot create, change, or delete an Azure resource. The only exception is the optional Terraform flag enable_power_scheduler, which is off by default. This flag creates a custom role that can start and deallocate virtual machines.

Roles

ScopeRolePurpose
Management Group (root)ReaderRead-only access to all subscriptions and resources
Storage AccountStorage Blob Data ReaderRead FOCUS cost export data
Billing scope (EA, Terraform only)Cost Management ContributorCreate and trigger the FOCUS export at the billing scope
Billing account (MCA, Terraform only)Billing Account ContributorCreate and start the FOCUS export. MCA uses its own billing RBAC
Tenant (optional)Reservations ReaderView reservation details and utilization
Tenant (optional)Savings Plan ReaderView savings plan details and utilization

The resource provider Microsoft.CostManagementExports must be registered on the subscription that holds the storage account.

What DigiUsher CAN Access (Read-Only)

  • The cost data and the usage data in the FOCUS exports in Azure Storage
  • The resource metadata, such as names, types, regions, and tags, through the Reader role
  • The information about the Reservations and the Savings Plans, when you give that optional access
  • The hierarchy of the Management Groups, the subscriptions, and the resource groups

What DigiUsher CANNOT Do

  • Create, change, or delete an Azure resource
  • Read application data, databases, or the content of your storage. It reads the cost exports only
  • Change an IAM policy or a role assignment
  • Read secrets, credentials, or encryption keys
  • Read network traffic or the content of your logs
  • Buy a product or change the billing configuration

Oracle Cloud Infrastructure (OCI)

Access Summary

ComponentDetails
IdentityOCI IAM user (digiusher-service-user). It uses the API only, and it has no Console password
AuthenticationAPI key pair: a PEM private key and a fingerprint
Access levelRead-only. Every policy uses the verb read only
ScopeTenancy-wide
BillingRead-only access to cost and usage reports
Data accessThe Cost and Usage Reports in the cross-tenancy bucket of Oracle, in the FOCUS format only
CapabilityWhat It Provides
Billing dataCost analytics, chargeback and showback, budgeting, forecasting, anomaly detection
Resource inventoryAsset discovery, idle resource detection, tag-based cost allocation
Optimization recommendationsRightsizing, commitment analysis, idle resource cleanup
Utilization metricsCPU, memory, network, disk usage for rightsizing analysis

DigiUsher cannot create, change, or delete an OCI resource.

OCI needs the define statement and the endorse statement in a different policy from the Allow statements. Create these two policies at the level of the tenancy, which is the root compartment.

Policy 1: Cost Report Cross-Tenancy Access

This policy gives read access to the cost reporting tenancy of Oracle, for the FOCUS cost reports. The OCID in the statement is the cost reporting tenancy of Oracle. It is the same for every OCI customer.

define tenancy usage-report as ocid1.tenancy.oc1..aaaaaaaaned4fkpkisbwjlr56u7cj63lf3wffbilvqknstgtvzub7vhqkggq
endorse group digiusher-finops-group to read objects in tenancy usage-report

Policy 2: DigiUsher Access Policy

This policy gives read access to the usage reports, the budget data, the resource metadata, and the monitoring metrics.

Allow group digiusher-finops-group to read usage-report in tenancy
Allow group digiusher-finops-group to read usage-budgets in tenancy
Allow group digiusher-finops-group to read all-resources in tenancy
Allow group digiusher-finops-group to read metrics in tenancy

All policies are read-only. DigiUsher cannot create, change, or delete anything in your environment.

Note

If you remove the last two statements, all-resources and metrics, DigiUsher gives no optimization recommendations, no rightsizing recommendations, and no data from the utilization metrics.

What DigiUsher CAN Access (Read-Only)

  • The Cost and Usage Reports in the FOCUS format, in the cross-tenancy bucket of Oracle
  • The budget data
  • The resource metadata, such as names, types, regions, and tags, through the Resource Search API
  • The utilization metrics for CPU, memory, network, and disk, in OCI Monitoring
  • The hierarchy of the organization and the compartments

What DigiUsher CANNOT Do

  • Create, change, or delete an OCI resource
  • Read application data, databases, or the content of your storage
  • Change an IAM policy or a permission
  • Read secrets, credentials, or encryption keys
  • Read network traffic or the content of your logs
  • Buy a product or change the billing configuration

On this page