Skip to content

docs: clarify AWS sync operations - #1

Merged
captainpacket merged 1 commit into
mainfrom
agent/aws-sync-doc-guidance
Jul 16, 2026
Merged

docs: clarify AWS sync operations#1
captainpacket merged 1 commit into
mainfrom
agent/aws-sync-doc-guidance

Conversation

@captainpacket

Copy link
Copy Markdown
Collaborator

Summary

  • separate AWS Organizations discovery permissions from member-account collection-role permissions
  • explain that setup-level success can coexist with per-account collection failures
  • add multi-setup preflight, dry-run, and apply examples
  • document review-gated removals and an Organizations visibility versus sts:AssumeRole decision table

Why

Operators need a clear way to distinguish retired or moved AWS accounts from active accounts with broken IAM configuration. The previous guidance covered the individual prerequisites but did not connect the discovery and collection signals into an operational decision.

Impact

This makes automation safer by showing when to repair IAM, when to investigate Organizations discovery, and when a removal can be approved. Public examples use generic setup IDs.

Validation

  • go test ./...
  • git diff --check

@captainpacket
captainpacket marked this pull request as ready for review July 16, 2026 13:02
@captainpacket
captainpacket merged commit 55f3319 into main Jul 16, 2026
1 check passed
@captainpacket
captainpacket deleted the agent/aws-sync-doc-guidance branch July 16, 2026 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant