Connect a cloud account
Connect AWS, GCP, and Azure accounts to ZopNight using least-privilege credentials.
4 lessons.
Read in order, or jump to what you need.
Vault credentials: the model
By the end of this lesson, you will be able to describe how ZopNight stores cloud credentials and explain the four properties of the vault model.
AWS: the IAM policy and why it's read-mostly
By the end of this lesson, you will be able to configure the AWS IAM role for ZopNight and explain which permissions enable read-only discovery versus scoped-write execution.
GCP & Azure: service accounts and SPNs
By the end of this lesson, you will be able to configure GCP service accounts and Azure service principals for ZopNight and identify the GCP and Azure equivalents of the AWS read-mostly pattern.
Permission Visibility: what the dashboard tells you
By the end of this lesson, you will be able to read the Permission Visibility drawer and act on any Denied entry to restore full discovery.