- Setting up the permissions required to run Plerion infrastructure
- Installing the infrastructure in the regions where you want to run workload scans
Step 1: Set up permissions
On the Plerion dashboard, go to Settings > Integrations

Find AWS workload service account and click the + button

Launch the CloudFormation stack
Launch stack to open the Quick create stack page in AWS CloudFormation.
Confirm the service account is added
- After the CloudFormation stack completes, the service account will be created automatically.
- You will see it listed on the Service Accounts page in Plerion.

Open the service account details

Configure regions for deployment
- From the service account details page, configure the regions where you want to install the Plerion infrastructure.
- See Step 2: Install infrastructure in regions.
Limitations
- An AWS account can only be associated with one service account.
- Service accounts cannot be shared across tenants or organizations.
- A maximum of 10 service accounts can be created in a tenant.
Resources created
Creating the CloudFormation stack will deploy:Troubleshooting
Error:PlerionInstanceProfileRole already exists in the stackCause: This indicates the AWS account is already being used as a service account in another Plerion organization.
Fix: Remove the existing service account and stack, or use a different AWS account.
Step 2: Install infrastructure in regions
On the service account dashboard, click Enable Region

Launch the CloudFormation stack
Launch Stack.
Complete the AWS CloudFormation wizard
Confirm the region is enabled
- After the stack finishes, the region will appear as enabled in the service account dashboard.
- Enable and install infrastructure in all regions where you want to run workload scans.

Link target accounts to the service account
- After installing infrastructure in all required regions, link target accounts.
- See Linking target accounts to a service account.
Resources created
Installing the CloudFormation template will create the following resources in each region:Troubleshooting
Error:AWS::SQS::Queue with identifier plerion-appliance-scan-queue already existsCause: This occurs if Plerion infrastructure is already installed in that region.
Fix:
- Delete the existing infrastructure and retry; or
- Choose a different region