Resource Groups

Resource groups are collections of resources. They simplify cloud automation, management, and permissions at scale. They can be used to apply granular permissions to a subset of your cloud footprint, to improve visibility, and to help apply custom policy.

From the Resource Groups page, accessed from the main menu, you can:

  • See a full list of the resource groups you have created

  • Access details of resources within each group

  • View a summary of each resource group

  • Create and delete resource groups.

Creating a Resource Group

  1. To create a resource group, go to the Resource Groups page from the main menu.

  2. Click on Create Resource Group in the top right corner of the page.

  3. Give the resource group a name and description. Select Submit.

_images/resource_groups_1.gif

Creating a Resource Group

  1. To add resources to your resource group, go to the Resources page via the main menu.

  2. Click on the type of resource you want to use, then scroll down to the results section which lists the resources of this type.

  3. In the results section check the box for those resources you wish to add to your resource group, then click the “Add to resource group” icon.

  4. Select a resource group; include dependencies if you wish. Select Submit.

_images/resource_groups_2.gif

Adding Resources to a Resource Group

  1. Continue selecting resources in this manner until you have selected all the resources you want to include in your resource group.

  1. Return to the Resource Groups page from the main menu.

  2. Click on the name of your resource group; you will see an overview of the resources in the group. The overview includes:

  3. A percentage breakdown of your resource group by resource type

  4. A breakdown of resources in your group by region.

_images/resource_groups_3.gif

Viewing Summary Information for a Resource Group

You can view details of the resources within a specific resource group by selecting the hamburger menu under the “Go to Resources” column on the Resources Group page. This takes you to the Resources page, already scoped for your resource group.

_images/resource_groups_4.gif

Viewing Details of Resources in a Resource Group

Using Resource Groups

Resource groups can be used for scoping resources, insights, and bots. They are particularly useful in defining what resources bots should act upon.

Running Bot Actions on Resource Group

you have created a resource group, you can use this group to scope bot actions. See Bot Creation, Step 2, for more information on scoping your bot with your resource group.

_images/resource_groups_5.png

Using a Resource Group to Scope a Bot

Resource Group Curation

You can assign bot actions to resource groups in one of two ways: to curate a resource group and to add resources to a resource group.

Curate Resource Group

TRiA ships with a bot action named Curate Resource Group, which, when added to a bot’s instruction set, assumes responsibility for maintaining the state of the resource group. This action can be used only as a one-to-one relationship between a single bot and single group. The bot will autonomously move resources in and out of the group as needed, based on the configured policy. (See example below.)

Add to Resource Group

On occasion, you may want to use multiple bots to add resources to a group. You can do this using the bot action Add To Resource Group. As the name implies, this action will only add resources to a group and will not automatically remove resources that no longer apply.

Curate Resource Group Example

In the following Curate Resource Group example, a resource group named Production Resources is created. This group includes resources with the tag key “environment” and a tag value of “production”. The scope of the bot will be set to look for appropriately-tagged resources across Microsoft Azure, Amazon Web Services, and Google Compute Engine.

    AwsConfig,
    AppServer,
    ContainerRegistry,
    ContainerImage,
    Instance,
    ResourceAccessList,
    ResourceAccessListRule,
    Volume,
    Snapshot,
    DatabaseSnapshot,
    MemcacheSnapshot,
    BigDataSnapshot,
    EmailServiceDomain,
    PublicIp,
    PrivateNetwork,
    PrivateSubnet,
    NetworkFlowLog,
    NetworkInterface,
    NetworkPeer,
    InternetGateway,
    NatGateway,
    RouteTable,
    DnsZone,
    SshKeyPair,
    PrivateImage,
    DatabaseInstance,
    DatabaseCluster,
    MemcacheInstance,
    ElasticsearchInstance,
    BigDataInstance,
    InstanceReservation,
    LoadBalancer,
    BackendService,
    ForwardingRule,
    TargetProxy,
    Hypervisor,
    RestApi,
    RestApiKey,
    RestApiStage,
    Secret,
    ServerlessFunction,
    ServiceAlarm,
    ServiceApp,
    ServiceAccessKey,
    ServiceDataset,
    ServiceDomain,
    ServiceEncryptionKey,
    ServiceEncryptionKeyVault,
    ServiceLogGroup,
    ServicePolicy,
    ServiceRegion,
    ServiceRole,
    ServiceGroup,
    ServiceUser,
    ServiceCertificate,
    SharedFileSystem,
    StorageAccount,
    StorageContainer,
    StackTemplate,
    ApiAccountingConfig,
    AutoscalingGroup,
    Datastore,
    DistributedTable,
    MessageQueue,
    DistributedTableCluster,
    Workspace,
    MapReduceCluster,
    DataStream,
    DeliveryStream,
    SearchCluster,
    Spanner,
    IdentityProvider,
    Container,
    ContainerInstance,
    ContainerDeployment,
    KubernetesIngress,
    Pod,
    PodSecurityPolicy,
    KubernetesService,
    ContainerCluster,
    ContentDeliveryNetwork,
    NotificationTopic,
    NotificationSubscription,
    MLInstance,
    Database,
    ContainerRegistry,
    ContainerImage,
    DirectConnect,
    DDoSProtection,
    WebApp,
    ThreatFinding
  1. Create a new resource group. Navigate to the Resource Groups section of the tool and create a new resources group called “Production Resources”.

_images/curate_step_1.png

Creating a “Production Resources” Resources Group

  1. Create a new bot. Click on the Create Bot button and enter the name, description, and category (in this example “Best Practices”).

_images/curate_step_2.png

Creating a Bot—Initial Bot Setup

  1. Configure the bot’s scope. The scope defines the resource type(s) and cloud account(s) to be inspected. For this example, scope includes billable resource types—such as instances, database instances (e.g., AWS RDS), volumes, and snapshots—across three cloud accounts. Note: If “Select All Clouds” had been selected, the bot would scan every configured cloud account.

_images/curate_step_3.png

Scoping the Bot

  1. Configure the bot’s conditions. For this example, the bot uses a single condition that inspects resource tags and looks for a single key Environment with a single value Production.

_images/curate_step_4.png

Configuring the Bot’s Conditions

  1. Configure the bot’s actions. The action used for this example is Curate Resource. Select that action from the listing and then use the drop-down to select the desired group Production Resources.

_images/curate_step_5.png

Configuring the Bot’s Actions

  1. Choose when the bot will run. For this type of bot, we recommend using resource created and resource modified. The bot will now act any time a new resource is spun up in the cloud, or when its tags are modified. If you select an on-demand scan (enable batch execution), this bot will execute immediately and will look at all selected resources, including those previously discovered.

_images/curate_step_6.png

Choosing When the Bot Will Run

  1. Save the bot. Once done, you can perform a retroactive scan and, if you have resources that meet the configured conditions, they should show up in the Production Resources group.

Troubleshooting

If you see an AccessDeniedException when attempting to create a resource group, please contact your TRiA Administrator to either create the needed resource group(s) or to upgrade your role to a TRiA Administrator role.

_images/rg_troubleshooting_1.png

AccessDeniedException When Attempting to Create a Resource Group