This article shows you how to update the CloudFormation StackSet in your AWS Organization so that the Cye Cloud Posture Solution role receives the permissions for newly monitored services.
Overview
Cye Cloud Posture Solution occasionally changes the role permissions to include additional AWS services it monitors. Updating the CloudFormation StackSet with the current template adds the required permissions to the accounts the StackSet covers, so scans keep working across the whole organization.
Replace the Template: Edit the existing StackSet in the master account and point it at the current template URL, leaving every other form value unchanged.
Redeploy to Your Organization: Enter the OU ID (or the entire organization), choose the us-east-1 region, acknowledge the IAM resources notice, and submit.
1. Open the StackSet
1. Open the StackSet
The update is made on the StackSet that connected your organization, from the master account.
Log in to the Org master account and open the CloudFormation console.
Go to StackSets.
Locate the StackSet Solvo-StackSet-Integration.
From the Actions dropdown, select Edit StackSet details.
2. Replace the template
2. Replace the template
The current template lives at a fixed S3 URL, so you replace the template rather than uploading a file.
3. Set the deployment targets and submit
3. Set the deployment targets and submit
The last step tells CloudFormation which accounts receive the updated template.
Fill in AWS OU ID (it can be the entire organization).
Choose us-east-1 as the region, then click Next.
Check I acknowledge that AWS CloudFormation might create IAM resources with custom names. and click Submit.
Wrap-up / Next Steps
Wrap-up / Next Steps
Review the new permissions: See How Cye Cloud Posture Solution Connects to Your AWS Environment for the full list of permissions the template grants.
Connect new accounts or OUs: Follow Connecting Your AWS Organization to create a StackSet for accounts that are not connected yet.
Check your connected accounts: Open Cloud Accounts in the console at console.solvo.cloud to review the accounts covered by the StackSet.




