Development

AWS Integration

Read-only cloud visibility — cost by service, CloudWatch metrics & logs, CloudTrail audit events, S3 listings.

Capabilities

This integration enables workers to:

  • Cost & usage summary by service (Cost Explorer)
  • CloudWatch metric statistics (e.g. EC2 CPU)
  • Search CloudWatch Logs for a pattern
  • Look up CloudTrail audit events
  • List S3 buckets and objects

Setup

Follow these steps to connect AWS:

  1. Create a read-only IAM user (e.g. ReadOnlyAccess + Cost Explorer) in AWS
  2. Navigate to Integrations and click 'Add Connection'
  3. Select AWS and paste the access key id, secret, and default region
  4. Assign your security/operations worker to use it

Official links

Security

  • Read-only by design — no AWS mutations are exposed to workers
  • IAM keys are verified via STS GetCallerIdentity and encrypted at rest
  • Scope the IAM user to least-privilege read policies

Credential Storage

All integration credentials are encrypted at rest using AES-256-GCM encryption. OAuth tokens are automatically refreshed when needed.

Supported Roles

The following roles can use this integration by default:

Related Documentation