- A runtime deployed from a container image is scanned with no extra setup.
- A runtime deployed from a code zip keeps its code in an S3 bucket in your account. Plerion reads the zip only from buckets you share with it, so no other bucket is readable.
Share a code bucket with Plerion
Do this once for each bucket that holds runtime code. Runtimes deployed withagentcore deploy use your CDK assets bucket, named cdk-<qualifier>-assets-<account>-<region>.
- In the Amazon S3 console, open the bucket and choose Properties.
- Under Bucket ABAC, choose Edit, turn on Enable, and save. ABAC (attribute-based access control) lets IAM policies match on the bucket’s tags.
- Under Tags, add the tag
PlerionAccesswith the valueGranted.
Once ABAC is on, tags on the bucket are managed with
TagResource and UntagResource. The S3 console and CloudFormation already use them. Tools that still call PutBucketTagging can no longer change the bucket’s tags.What Plerion can read
The Plerion appliance role gets this statement in policy version v37 of the Plerion stack:aws:ResourceTag only on buckets with ABAC turned on, so a bucket needs both the tag and ABAC before Plerion can read it. The role can also read each bucket’s ABAC status and tags, so a scan can tell you which of the two is missing.
If the bucket is encrypted with a customer managed KMS key, Plerion decrypts through S3 with the same KMS key access you chose for the integration. Objects encrypted with the AWS managed aws/s3 key need nothing extra.
This works the same way whether Plerion scans in your account, from your service account, or from a Plerion-managed scanning account. Each of them reads the code as the Plerion appliance role in the runtime’s account.