Migrate AWS SSO SCIM Integration to IAM Identity Center APIs
in progress
J
Johannes Rudolph
We are deprecating the AWS SSO SCIM-based integration for meshStack's AWS IAM Identity Center connectivity.
This integration method will be
removed on October 1, 2026
.Why We're Deprecating This
The SCIM token approach has several drawbacks:
- Over-privileged: The SCIM token grants more permissions than meshStack needs
- Requires manual rotation of long-lived secrets
- Reduced auditability in AWS CloudTrail (shared token with other systems like Entra ID)
What Replaces It
The
AWS Identity Store API integration
(available since meshStack v2026.10.0) is the recommended replacement:- Uses an IAM role with least-privilege Identity Store permissions
- Compatible with Workload Identity Federation — fully secret-less operation possible
- Better CloudTrail auditability per action
- Supports locally managed IAM Identity Center users
Timeline
- Now:AWS Identity Store API integration is available and recommended for all new AWS platform setups
- October 1, 2026:AWS SSO SCIM integration will be removed from meshStack
Migration
To migrate, follow our in-place upgrade guide:
- Apply the updated terraform-aws-meshplatform v0.7.0 module to add Identity Store IAM permissions to your AWS integrations in addition to existing AWS SSO SCIM permissions.
- Switch the IAM integration type to "AWS Identity Store API" in your AWS platform configuration. You can do this via meshPanel or you use this opportunity to start managing your meshPlatform via terraform
- Remove the old SCIM token and permissions after successful validation
Full migration documentation is available at https://docs.meshcloud.io/docs/integrations/aws/sso-setup.html
If you need help migrating, contact us at support@meshcloud.io or reach out to your Customer Success contact.
Florian Nowarre
Step 1 – Add the Identity Store permissions to the meshStack replicator role
Do this in the AWS account where IAM Identity Center is managed. Usually that's the Organizations management account.
- Sign in to the AWS console and open IAM → Roles.
- Open the role meshStack uses for replication (by default MeshfedServiceRole).
- Select Add permissions → Create inline policy → JSON, and paste:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "OrgManagementIdentityStoreGroupManagement",
"Effect": "Allow",
"Action": [
"identitystore:GetGroupId",
"identitystore:CreateGroup",
"identitystore:DeleteGroup",
"identitystore:ListGroupMemberships",
"identitystore:CreateGroupMembership",
"identitystore:DeleteGroupMembership",
"identitystore:GetUserId"
],
"Resource": "*"
}
]
}
- Name the policy meshstack-identitystore-access and save it.
- Leave the existing sso:* permissions on the role as they are. meshStack still needs them to assign permission sets to accounts.
Step 2 – Collect the IAM Identity Center details
In the AWS console, open IAM Identity Center → Settings and note:
- Identity Store ID, e.g. d-1234567890
- Instance ARN, e.g. arn:aws:sso:::instance/ssoins-xxxxxxxxxxxxxxxx
- AWS access portal URL (sign-in URL), e.g. https://d-1234567890.awsapps.com/start
Step 3 – Switch the platform configuration in meshStack
1. In meshPanel, go to your AWS platform's settings and open the replication configuration.
- In the IAM / identity section, change the mode from AWS SSO (SCIM) to AWS Identity Store.
- Enter the Identity Store ID, Instance ARN and sign-in URL from Step 2.
- Important: Keep the group name pattern and the role mappings (project role → permission set) exactly as they are now. meshStack then keeps working with the groups that already exist and doesn't create duplicates.
- Save the configuration.
J
Johannes Rudolph
updated the status to
in progress