Skip to main content

Update Your AWS Onboarding

Overview

As Upwind Cloud Scanner introduces support for new scanning capabilities and additional resource types, your existing AWS onboarding configuration may require additional IAM permissions to allow those resources to be discovered and scanned.

You can update your existing onboarding deployment in place to apply the latest Upwind roles and permissions, without disconnecting your AWS accounts or repeating the onboarding process.

This ensures that your existing Cloud Scanners have the permissions required to use newly supported scanning capabilities as they become available.

When You Need to Update

Update your AWS onboarding when you need to:

  • Enable a new Cloud Scanner capability that requires additional IAM permissions, such as Data Security or support for additional resource types.
  • Apply updates or improvements to the IAM roles and permissions used by your existing deployment.
Updating vs. migrating

This guide applies when your environment is already using the Combined Stack onboarding model and you only need to update the existing roles or permissions.

If you are moving from single-account onboarding or the legacy three-stack model to Combined Stack organizational onboarding, follow the Migration guide instead.

If your AWS Organization has not yet been connected to Upwind, follow the onboarding instructions.

Before You Begin

Before updating your deployment:

  • Confirm that your Cloud Scanner uses the Outpost deployment model and that your environment is already connected using the Combined Stack onboarding flow. If Upwind hosts your Cloud Scanner infrastructure, follow the SaaS update guide instead.
  • Locate your existing onboarding resources:
    • CloudFormation: the stack is typically named UpwindCombinedOrg.
    • Terraform: the root module that applies upwind_aws_org_onboarding to the accounts in scope.
  • Make sure the identity performing the update has permission to update the relevant CloudFormation stack or apply Terraform changes.

Update Steps

Step 1. Open the Existing Stack

  1. Sign in to the AWS Management Console .
  2. Open CloudFormation.
  3. Select your existing Upwind onboarding stack, typically named UpwindCombinedOrg.
  4. Choose UpdateMake a direct update.

Step 2. Use the Latest Upwind Template

  1. Select Replace existing template.

  2. Select Amazon S3 URL, and enter:

    https://get.upwind.io/cfn/templates/iam/cross-account-roles/v2/upwind-combined-org-onboarding.yaml
  3. Choose Next.

  4. Keep the existing stack parameters unchanged unless Upwind Support has instructed you to update them.

  5. Review the changes and acknowledge that the template may create or modify IAM resources.

  6. Submit the update.

Wait until the stack reaches UPDATE_COMPLETE. The update duration may vary depending on the size and structure of your AWS Organization.

After the Update

After the CloudFormation update or Terraform apply completes successfully:

  • The updated IAM roles and permissions become available to Upwind.
  • Existing Cloud Scanners can use the updated permissions without requiring you to reconnect your AWS accounts.
  • To use a newly supported scanning capability enabled by the updated permissions, open the relevant Cloud Scanner in the Upwind Management Console, go to Capabilities in Scope, and configure or enable the capability.
  • Verify that your AWS accounts remain connected under Organizations and accounts.

Need Help?

If you need assistance with the update, contact Upwind through: