Global tagging represents a significant advancement over existing tag management capabilities, which were previously limited to account-level functionalities. This global approach enables the creation of universal tags that can be applied across all accounts within Bridge, thereby enhancing the efficiency of administration and management. This streamlined process reduces the need to manage numerous identical tags across multiple accounts, especially when dealing with large quantities of tags and their corresponding values.
Main considerations:
Administrators are responsible for maintaining and organizing the global tags.
The “global_” prefix has been reserved for global tags. The system will automatically add this prefix, so there is no need to add it manually.
Global tags can only be created from the Bridge Operations account, and Global tag definitions can only be managed from this account.
Once a tag is created in the global control pane, it gets added to the tag repositories of all accounts in Bridge. For example, if a tag is created and classified as global with the key "ENV," it will be represented as "global_ENV,". This tag will be compliant even at the account-level tag repository because the tag definitions for it exist in the global tag definition.
The "global_" prefix is prohibited in non-operational accounts, as it is designated only for global tags created from the Operations tenant.
To get started, open the global menu and select
Control Tower
. This central hub allows you to manage various functions across multiple accounts. In the tag management section, you'll find the global tag definition and global tag repository features.
Global tag definitions
The tag administrator can only create a global tag key from the global tag definition, available in the operations tenant. Once an active global tag key is created, it will be available in the tag repository of all other accounts in Bridge. All capabilities are available for the standard tag definitions also apply to the global tag definition, such as:
View Details:
Access detailed information about the current definition.
Edit:
Open the related definition in edit mode, with Key Name, type, and state as read-only.
Use as Template:
Aliases and tag keys are not pre-populated.
Delete:
Ability to delete the current definition.
Provider and resource type scope applies to global tags, and change history functionality remains unchanged from account-level tags. Upon creating new tag definitions, the risk of duplication is eliminated. Creating a new tag labeled "OS" will follow the same validation rules, preventing duplicates.
Global tag repository
Tag administrators can only create a global tag from the global tag repository. Global tags are '
Read Only
' in tag repositories of other (non-global) accounts. All capabilities are available for the standard tag repository also apply to the global tag repository, in which the user can add tags to the tag repository in multiple ways, as described next:
Capability 1:
Add tag values to the tag keys created from the global tag repositories. If the user adds tag values to these tag keys that are outside the allowed values defined in the constraints of the definition, an error message is displayed indicating that this action is not supported.
Capability 2:
Create and save a new key or value pair directly within the global repository.
Capability 3:
Import tags to the Tag Repository page can also be done for global tags.
The global tag repository only displays the global tags, while the account-specific tag repository showcases both global tags and account-level tags. All the other capabilities of the tag repository also apply to the global repository, such as:
Delete conditions:
Global tag deletion is only allowed in the Bridge Operations tenant.