AWS
AWS
Connect an Amazon Web Services account and get your servers, bill, security findings, logs and storage in one place.
If you use Amazon Web Services, connecting it turns DevOps Agent into a single screen for the things you normally open five AWS consoles to find: what you are spending, what is insecure, who did what, what is in your storage, and what your logs say.
Connecting AWS is optional. If your servers come from an ordinary hosting company, use a Server Only project and ignore this section.
Start here
- Connect AWS — creating an access key and adding the project.
- Permissions — what the key needs to be allowed to do, and how to stay read-only.
The screens
| Screen | What it answers |
|---|---|
| Dashboard | How much do I have, what does it cost, is anything obviously insecure? |
| Cost | Where is the money going? |
| FinOps | How do I spend less? |
| Users / IAM | Who has access, who has MFA, what did they do? |
| GuardDuty & Inspector | Is anything attacking me, or vulnerable? |
| CloudWatch & Logs | What do my logs say? |
| S3 | What is in my file storage? |
| CloudFormation | What is deployed, and has anyone changed it by hand? |
| Servers (EC2) | Open a shell on an instance |
Regions
AWS resources live in regions, and most screens work one region at a time with a selector at the top. Your project has a default region, set when you created it and changeable in Settings → Project.
The Dashboard is the exception — it scans every enabled region each time you open it, which is why it takes a few seconds.
What the assistant can do with AWS
In an AWS project the assistant can run AWS commands directly: describe resources, read logs, check costs, and — in Execute mode, with your approval — make changes.
Two things worth knowing:
- Deleting or terminating cloud resources always asks, even with auto-approve on.
- Operators cannot delete or terminate AWS resources at all. See Roles.
