Terraform modules for connecting AWS accounts to Sweet Security.
Sweet reads your cloud inventory, identities and topology through a cross-account read-only IAM role. These modules create that role.
| Module | Purpose |
|---|---|
modules/account-least-privilege |
Read-only role for a single AWS account, limited to the specific API actions Sweet uses. |
module "sweet" {
source = "github.com/sweet-security/terraform-sweet-aws//modules/account-least-privilege"
# optional
external_id = "your-external-id"
}Then apply, and finish the setup in the Sweet UI under Deployment → Cloud Entities → + Add configuration → AWS:
| Field | Value |
|---|---|
| IAM Role ARN | role_arn output |
| External ID | the external_id you set, if any |
| Regions | the regions you want monitored |