AWS

Connect AWS

Create an access key with the right permissions and add it as a project.

Before you start: you need to be able to sign into the AWS console with enough rights to create an IAM user, or someone who can do it for you. It takes about five minutes.

What we need

Three things:

  • an Access key ID (starts AKIA…),
  • a Secret access key,
  • a default region, such as us-east-1 or ap-south-1.

These are the username and password of a robot user in your AWS account. Whatever that robot is allowed to do, DevOps Agent can do. Whatever it is not allowed to do, we cannot do either — which is how you stay in control.

Step 1 — Create the key in AWS

  1. Sign into the AWS Console and open IAM.
  2. Users → Create user. Name it something recognisable, e.g. devops-agent.
  3. Do not give it console access. It only needs programmatic access.
  4. Attach permissions. The simplest safe starting point is the AWS-managed ReadOnlyAccess policy plus Cost Explorer access. Exactly what to attach, and what each screen needs, is on AWS permissions.
  5. Finish, then open the user → Security credentials → Create access key → choose Application running outside AWS.
  6. Copy both values now. AWS shows the secret key once and never again.

Step 2 — Add the project

In DevOps Agent, click + next to the project name in the sidebar.

FieldWhat to enter
NameWhat you will call it: Acme production
TypeAWS
Access keyThe AKIA… value
Secret keyThe secret
RegionYour main region, e.g. us-east-1

Save. The keys are encrypted with AES-256-GCM before being stored and are only decrypted on our server when making an AWS call for you. See How we protect your credentials.

The menu grows to fifteen items and you land on the Dashboard.

Step 3 — Check it works

Open the Dashboard. It scans every enabled region and shows EC2, S3 and RDS counts, cost charts and security checks.

  • Numbers appear → you are connected.
  • A region shows an error → that is usually a missing permission. The error names the API call that was refused; compare it with Permissions.
  • Everything fails → the key or secret is wrong, or the user has no permissions at all. Replace the keys in Settings → Project.

Rotating or replacing keys

Settings → Project for an AWS project lets you replace the access key and secret, and change the region. Do this whenever you rotate keys in AWS — nothing else in the project changes, and your servers, monitors and integrations are untouched.

Good practice

  • One IAM user per project here, not your personal key. Then you can see what it did in CloudTrail, and revoke it without affecting anyone else.
  • Start read-only. Add write permissions only when you want to use a feature that needs them.
  • Rotate the key every few months.
  • Never paste your root account credentials. Ever, anywhere.

Google Cloud

GCP appears in the project type picker marked Coming soon and cannot be selected.