AWS Integration
Read-only cloud visibility — cost by service, CloudWatch metrics & logs, CloudTrail audit events, S3 listings.
Capabilities
This integration enables workers to:
- Cost & usage summary by service (Cost Explorer)
- CloudWatch metric statistics (e.g. EC2 CPU)
- Search CloudWatch Logs for a pattern
- Look up CloudTrail audit events
- List S3 buckets and objects
Setup
Follow these steps to connect AWS:
- Create a read-only IAM user (e.g. ReadOnlyAccess + Cost Explorer) in AWS
- Navigate to Integrations and click 'Add Connection'
- Select AWS and paste the access key id, secret, and default region
- Assign your security/operations worker to use it
Official links
Security
- Read-only by design — no AWS mutations are exposed to workers
- IAM keys are verified via STS GetCallerIdentity and encrypted at rest
- Scope the IAM user to least-privilege read policies
Credential Storage
All integration credentials are encrypted at rest using AES-256-GCM encryption. OAuth tokens are automatically refreshed when needed.
Supported Roles
The following roles can use this integration by default: