Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions,
see Getting Started with Amazon Web Services in China
(PDF).
Share a resource discovery
Follow the steps in this section to share a resource discovery using Amazon Resource Access Manager. For more information about Amazon RAM, see Sharing your Amazon resources in the Amazon RAM User Guide.
Creating, sharing, and associating resource discoveries is part of the process of integrating
IPAM with accounts outside of your organizations (see Integrate IPAM with accounts outside of your organization). If you are not creating
an IPAM and integrating it with accounts outside your organization, you do not need to create, share, or associate resource discoveries.
When you create an IPAM that monitors accounts outside your organization, the
Secondary Org Admin Account shares their resource discovery with the Primary Org IPAM
Account using Amazon RAM. You must first share a resource discovery with the Primary Org IPAM
Account before the Primary Org IPAM Account can associate the resource discovery with
their IPAM. For more information about the roles involved in this process, see Process overview.
When you create a resource share using Amazon RAM to share a resource discovery, you must create the resource share in the home Region of the Primary Org IPAM.
The account that creates and deletes a resource share for a resource discovery must have the
following permissions in their IAM policy:
ec2:PutResourcePolicy
ec2:DeleteResourcePolicy
If you are integrating an IPAM with accounts outside of your organizations, this is a
required step that must be completed by the Secondary Org Admin
Account.
- Amazon Management Console
-
To share a resource discovery
Open the IPAM console at
https://console.amazonaws.cn/ipam/.
In the navigation pane, choose Resource discoveries.
Choose the Resource sharing tab.
Choose Create resource share. The Amazon RAM console opens, which is where you will create the resource share.
In the Amazon RAM console, choose Settings.
Choose Enable sharing with Amazon Organizations, and then choose Save settings.
Choose Create a resource share.
Add a Name for the shared resource.
Under Select resource type, select IPAM Resource Discovery, and choose the resource discovery.
Choose Next.
Under Associate permissions, you can view the default permission that will be enabled for principals that are granted access to this resource share:
Specify the principals that are allowed access to the shared resource. For Principals, choose the Primary Org IPAM Account, and then choose Add.
Choose Next.
Review the resource share options and the principals that you’ll be sharing with. Then choose Create resource share.
After a resource discovery is shared, it must be accepted by the Primary Org IPAM Account and
then associated with an IPAM by the Primary Org IPAM Account. For
more information, see Associate a resource discovery with an IPAM.
- Command line
-
The commands in this section link to the Amazon CLI Reference documentation.
The documentation provides detailed descriptions of the options that you can use
when you run the commands.