Hi,Late last week I start noticing my terraform build was failing every time I was trying to deploy my JSM access role, which was previously working. It's been failing with this error message:MalformedPolicyDocument: Invalid principal in policy: "AWS":"arn:aws:iam::186683438898:role/jsm-securityhub-appI notice the jsm-securityhub-app role for this specific AWS account doesn't exist anymore.The role for the other 11 Atlassian AWS accounts are still there and still working.Is 186683438898 been deprecated ? If yes is there a way I can get informed when one of your AWS account get deprecated ? I used this page https://support.atlassian.com/jira-service-management-cloud/docs/integrate-with-amazon-security-hub/to add all those accounts in my infrastructure.I have removed 186683438898 for now to ensure my build doesn't fail.Thanks,Yannick
Hi Marc,
Thanks for getting back to me and for the clarification.
I was under the impression that the AWS accounts referenced in the JSM Security Hub integration documentation were managed by Atlassian. If that’s not the case, I’ll take a different approach and investigate this further on my side.
One follow-up question: does Atlassian maintain an official or up-to-date list of AWS account IDs used for the Security Hub integration?
Thanks again for your help.Thanks,Yannick
Hi @Yannick Mbimbe
Welcome to the community.
You will have to reach out to your AWS admins, or you might be one.
This is not related to JSM, it's an AWS issue, related to the role in AWS.
Possible causes:
No there is no AWS account ID list for integration, this is based on the Atlassian account(s) used for the integration.
In the integration there must be an account an api or oauth mentioned that is used to trigger actions in Jira
Please accept my answer if it helped solving your question.
Hi @Marc -Devoteam- Thanks again for the clarification. This is useful information.Thanks,Yannick
Hi @Marc -Devoteam-
Thanks for helping @Yannick Mbimbe .
I'm having the same issue, and I would like to understand who owns
237192868841, 713666869533, 395302896244, 063477313105, 401089113854, 495179308371, 089311581210, 265418188386, 838921230308, 110021325195, 028860521379?
AWS accounts.
The template https://jsm-integration.s3.us-west-2.amazonaws.com/amazon-security-hub-integration-cloudformation-template/securityhub-outgoing-permission-template.json seems to be maintained by Atlassian, and it is static.
Removing the account 186683438898 seems like a hack to me.
Maybe other customers are also affected.
It looks like you're new here. Sign in or register to get started.