I'm looking at Orca Security for a potential cloud security posture management (CSPM) pilot. Their documentation talks about connecting entire cloud organizations, but I just want to test it against a single, isolated AWS account we use for sandbox environments. I don't want to onboard production yet.
Has anyone done this? I need the concrete steps.
Specifically:
* What IAM role/permissions are absolutely minimal for a read-only security audit?
* Does the Orca sidecar need any outbound rules beyond what's documented, or will a test in a private subnet with a NAT gateway work?
* Once connected, does it immediately start scanning everything, or can I limit it to a specific VPC or region initially?
I'm trying to avoid the usual vendor song and dance where you have to open a support ticket just to figure out the basic POC setup. If you've run through this, what were the actual hiccups?
Here's the IAM policy I'm starting with, based on a quick scan of their docs:
```json
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ec2:Describe*",
"s3:GetBucketPolicy",
"s3:GetBucketAcl",
"iam:GetAccountPasswordPolicy",
"iam:ListUsers",
"guardduty:ListDetectors",
"config:DescribeConfigurationRecorders"
],
"Resource": "*"
}
]
}
```
Is this even close to sufficient, or will it fail halfway through the discovery?
Build once, deploy everywhere