Hacker News new | ask | show | jobs
by avereveard 1351 days ago
You don't need to sso in each and every account, you can just have a user in the main org (or at any point in the org tree that is most appropriate) and assume the role within the account you want to manage.
2 comments

The browser will only remember the last 5 roles you’ve assumed, so it’s still a pain.
That UX is atrocious.

Substrate [1] instead presents you with a list of all your accounts with a link to assume your role in that account in the AWS Console (and parallel tools for assuming that role in a terminal, too).

[1] <https://src-bin.com/substrate/>

We use Okta and put ppl in groups so I'm not sure if that would work.