Skip to main content

Multiple Accounts Collection

Configure Multiple Accounts Collection

For multiple accounts within the same organization, select the option as shown below and click Next.

Scope Multiple Accounts

warning

This selection requires an Enterprise-enabled account. All child accounts need to be Enterprise-managed. Requires service ID in the hub account.

Create an IBM Cloud Service ID

In this step, the wizard will guide you through creating an IBM Cloud Service ID.

  1. Go to URL for Service ID: https://cloud.ibm.com/iam/serviceids
  2. Create a Service ID either under default group or a group of your choice. To do so:
    • Click Create Service ID.
    • Specify a name and description.
  3. Assign access permissions to the Service ID by selecting the following services:
    • VPC Infrastructure Service
    • Direct Link
    • Transit Gateway
    • All Account Management Services
note

Choose all resources with service access and platform access as reader/viewer for all of the services above except Transit Gateway and Direct Link which require editor access.

IBM Cloud Service ID

Click Next to continue.

Create API key for Service ID

Follow the instructions below to create an API key for the Service ID created above:

  1. Switch to the API keys tab under the Service ID you just created.
  2. Click Create and assign a name and description to it.
  3. Click Download to download the created key.
  4. Upload that key file.

IBM Cloud API key

Click Next to continue.

Create policy template

To create a policy template follow these steps:

  1. Go to the template creation page: https://cloud.ibm.com/iam/enterprise-templates

  2. Click on Policies tab and create 4 new policy templates:

    Policy 1:
    Name: fwd-read-vpc-template
    Service: VPC Infrastructure Services
    Resources: all
    Access: reader/viewer

    Policy 2:
    Name: fwd-read-dxl-template
    Service: Direct Link
    Resources: all
    Access: editor

    Policy 3:
    Name: fwd-read-tgw-template
    Service: Transit Gateway
    Resources: all
    Access: editor

    Policy 4:
    Name: fwd-read-rg-template
    Service: All Account Management Services
    Resources: all
    Access: viewer

IBM Cloud Policy Template

Click Next to continue.

Create Trusted Profile

To create a trusted profile in all child accounts that you want to collect from follow these steps:

  1. Go to the Trusted profile tab. Create a new trusted profile template by providing a name for this profile in the enterprise hub account as well as a name to be used in all the child accounts.
  2. Once that profile is created, configure the profile as follows:
    1. Under the Trust relationship:

      • Go to Service IDs sub-tab → add the Service ID you created in the previous step.
      • Click Add.
    2. Under the Access tab:

      • Click Add and select the 4 policy templates you created earlier.
      • Click Add to add them to the trusted profile.
      • Click Review and accept the agreement by checking the checkbox.
      • Click Commit.
    3. Under the Assignment tab:

      • Click Assign accounts.
      • In the pop up, select all accounts that you want this profile to be applied to. Note that these are the accounts that Forward will be able to collect from.
      • Click Assign accounts to push the template to all the child accounts.

IBM Cloud Trusted Profile

Click Next to continue.

Select accounts

When the Auto-detect and collect all accounts option is enabled, the Collector will attempt to collect all accounts discovered from this account, including any new accounts created in the future.

Disable this option to customize account selection.

IBM Cloud Select Accounts

Click Next to continue.

Select Regions

Select one or more region to collect from, then click Next.

IBM Cloud Regions

Click Next to continue.

Test Connection

Provide a unique Account name, and click on Test connection. Forward Enterprise will test the connection with the IBM cloud regions selected.

IBM Cloud Test Connection

Clicking See logs, opens a new window with all the connection logs. Click Next to continue.

Summary

Click Done to complete the setup.

IBM Cloud Summary

Managing Your IBM Cloud Setup

Setup Edit

To update an existing IBM Cloud setup:

  1. Click the Edit icon.
  2. Expand the Accounts section to update accounts selections.
  3. Expand the Regions to collect from section to update region selections.
  4. Click Test connection to revalidate the setup.
  5. Click Save to apply changes.

IBM Cloud Setup Edit

Exclude Setup from Collection

To exclude an IBM Cloud setup from active collection, toggle the switch on the left side of the setup.

Excluding an IBM Cloud setup

Delete Setup

To permanently delete an IBM Cloud setup:

  • Click the kebab (three-dot) icon.
  • Select Delete.
  • Confirm the deletion.

Deleting an IBM Cloud setup