Skip to main content
Information Security for Workload Factory

NetApp Workload Factory onboarding security workflow

Contributors netapp-rlithman

Onboarding to NetApp Workload Factory establishes secure access to your AWS environment before you begin using the product. The process combines AWS trust configuration, permission scoping, connectivity setup, observability verification, and optional AI diagnostics enablement.

Step 1: Decide your onboarding posture

  • Identify AWS accounts and environment boundaries (for example, prod vs non-prod separation).

  • Identify required workflows (read-only discovery vs provisioning vs ONTAP-native operations).

  • Decide whether to deploy VPC execution components (for example, Lambda link) based on workflow needs.

  • Decide whether to enable AI diagnostics (enabled by default).

Step 2: Establish AWS trust and access

  1. Deploy an IAM role in your AWS account.

  2. Gate role assumption using an external ID in the trust policy.

  3. Register the role ARN and external ID in Workload Factory.

Related information

AWS account integration

Step 3: Apply least-privilege permissions

  1. Select the minimum permission tier that supports your intended workflows.

  2. Validate that per-request session policies restrict actions to the operation being performed.

Step 4: Configure connectivity and VPC boundaries (as needed)

  1. Validate required network paths to AWS endpoints.

  2. If you require ONTAP-native operations, deploy and validate the appropriate execution option in your VPC.

Step 5: Verify observability

  1. Confirm metrics and telemetry are collected and retained as expected.

  2. Confirm you can access required operational records for troubleshooting and investigations.

Step 6: Enable AI diagnostics (optional)

AI diagnostics are enabled by default. If you enable them, verify that you meet the prerequisites and scope permissions to the minimum required.