jump to content

Scaleway

Connect Scaleway as an access review source using an IAM secret key and Organization ID to review who has IAMReadOnly access to your account.

View as Markdown

the platform reads your Scaleway Organization’s IAM users through the Scaleway IAM API so you can review who has access.

  • the platform organization administrator access
  • A Scaleway API key whose bearer holds the IAMReadOnly (or IAMUserReadOnly) permission, so it can list the Organization’s users. The account Owner has this by default
  • Your Scaleway Organization ID, from the console under Organization Settings (use Copy ID next to the Organization name)
the platform fieldScaleway fieldNotes
Namefirst_name and last_nameFalls back to the username, then the email
Emailemail
Roletypeowner → Owner, member → Member
AdmintypeFlagged as an administrator when type is owner
Statusstatus and lockedInactive when the account is locked or its invitation is still pending
MFAtwo_factor_enabledWhether two-factor authentication is enabled (falls back to the mfa flag)
Last loginlast_login_atWhen the user last signed in
External IDidStable identifier used to track the account across reviews
Created atcreated_atWhen the user was added to the Organization

Generating an API key in the Scaleway console

  1. In the Scaleway console, open IAM & API keys from the top-right menu, then the API keys tab.
  2. Click Generate API key, choose the bearer (yourself, or an IAM application that holds the IAMReadOnly permission), add a description (e.g. Probo Access Review), and generate it.
  3. Copy the secret key (a UUID) and store it securely. It’s shown only once.
  1. In the platform, go to Access Reviews > Sources > Add Source.
  2. Find Scaleway, click API Key, paste the secret key, enter your Organization ID (from Organization Settings), and click Connect.

the platform names the source after your Organization and pulls its IAM users into your campaigns.

  • Key rejected. Confirm you pasted the secret key (a UUID), not the access key (SCW…) or the Organization ID. Only the secret key authenticates in the X-Auth-Token header.
  • No users appear. The key’s bearer needs the IAMReadOnly or IAMUserReadOnly permission, and the Organization ID must match the Organization you’re reviewing.

Ultima actualizare: