RCD AWS Accounts
RCD can provision Amazon Web Services (AWS) accounts for researchers.
Benefits:
- Single Sign-On (SSO): Gain access to your account by using Clemson University SSO credentials to deploy any AWS resource you require.
- Integrated Billing: Billing is managed centrally by CCIT, with monthly charges based on your consumption. Charges are applied to the fund you supply. We can also work with our AWS Solutions Architect and Account Manager to see if your project may be eligible for POC credits.
- Security: Meets the university's security standards, ensuring that all the resources are compliant and secure.
- Consultation: Schedule an appointment with RCD cloud experts to help with proposals, pricing estimates, architecture advice and more. Visit our office hours page and select the Book Cloud Consultation option.
Provisioning
Only faculty can request an AWS account. To request an account, please follow the steps on our AWS account provisioning guide.
Pricing
RCD provisioned accounts will accrue costs at the standard AWS rate. AWS has a publicly available Pricing Calculator to help estimate the expenses. All costs associated with AWS are the responsibility of the faculty that utilizes them.
RCD encourages researchers to set up monthly budgets to better manage their cloud expenses. We also assist in setting up alarms to notify researchers if their usage approaches or exceeds their budgeted amount.
Account Administration
For details on:
- AWS account provisioning process
- Adding funds to AWS account
- Adding and removing users from AWS account
- Controlling allowed resources
Please read the AWS account owner's guide.
AWS Training
The RCD Cloud team is happy to help users begin using their AWS accounts. In addition to the many recommended external training options, you can book Cloud Computing consultation from the RCD team and request personalized training.
AWS Console Access
To access the AWS console for your account, go to https://clemson.awsapps.com/start. You should then be redirected to the Clemson Login page and log in using your Clemson username, password, and Duo.
Once logged in, you should see a list of accounts that you have access to.
Select the account, then select which role you would like to use. You should always select the role with the least privileges needed to perform your work.
To switch accounts or roles, simply go back to https://clemson.awsapps.com/start and select the new account or role.
AWS CLI Usage
AWS provides a powerful CLI tool for managing your AWS account. Almost everything you can do from the AWS console can be done using the AWS CLI.
Installation
Follow the AWS CLI instructions to install the AWS CLI.
Authentication
In order for the AWS CLI to function, it needs to know how to authenticate. The CLI relies on configured "profiles" which link authentication details to an AWS account and role. In a Clemson RCD provisioned account, the authentication will happen through AWS SSO/AWS Identity Center.
Creating a first profile
To create your first profile, we'll first have to configure an "SSO session". Run the following:
aws configure sso
Use the following options when prompted:
- SSO session name:
clemson - SSO start URL:
https://clemson.awsapps.com/start - SSO region:
us-east-1 - SSO registration scopes:
sso:account:access
A URL will be printed to the screen. Visit this URL and enter the code provided. This should redirect you to the Clemson Login page where you should log in with your Clemson credentials.
You may have to allow botocore-client-clemson to have access to your data in
Applications and AWS accounts. The botocore Python library is at the core of
the AWS CLI.
On the command line, you should then be asked to set up the profile:
- Select the desired AWS account to use.
- Select a role available to you. You should always select the role with the least privileges needed to perform your work.
- Use the region of
us-east-1. - Select a
default output format.
The formats are
json,textandtable. This can always be changed later, or even changed for a particular command invocation using the--outputflag. - Create a simple, memorable name for the profile. We do not recommend using the
default name. Instead, choose something like
labname-adminorlabname-readonly.
Once you've completed these steps, you should have a new profile you can use.
Creating more profiles
It is often beneficial to create multiple profiles:
- You may have access to multiple accounts.
- You may have access to multiple roles within an account, and it is best practice to use the lowest level roles/credentials needed to perform the desired task.
To create another profile, run the following command:
aws configure sso
When it asks for SSO session name, type clemson. It should then reuse the SSO
configuration that was set up on the first profile.
You should then be asked to set up the profile:
- Select the desired AWS account to use.
- Select a role available to you. You should always select the role with the least privileges needed to perform your work.
- Use the region of
us-east-1. - Select a
default output format.
The formats are
json,textandtable. This can always be changed later, or even changed for a particular command invocation using the--outputflag. - Create a simple, memorable name for the profile. We do not recommend using the
default name. Instead, choose something like
labname-adminorlabname-readonly.
Listing configured profiles
Run:
aws configure list-profiles
Display active account and role
Run:
aws sts get-caller-identity
Activating profiles
You can always pass --profile <profile-name> to an AWS CLI command (e.g.
aws sts get-caller-identity --profile labname-admin), however this gets
verbose quickly.
An alternative is to set the profile with an environment variable. You can use
export AWS_PROFILE=<profilename>
To set the profile for any AWS CLI command run in this terminal session.
For more information, please read the AWS CLI configuration documentation.