AWS

AWS

Connect an Amazon Web Services account and get your servers, bill, security findings, logs and storage in one place.

If you use Amazon Web Services, connecting it turns DevOps Agent into a single screen for the things you normally open five AWS consoles to find: what you are spending, what is insecure, who did what, what is in your storage, and what your logs say.

Connecting AWS is optional. If your servers come from an ordinary hosting company, use a Server Only project and ignore this section.

Start here

  1. Connect AWS — creating an access key and adding the project.
  2. Permissions — what the key needs to be allowed to do, and how to stay read-only.

The screens

ScreenWhat it answers
DashboardHow much do I have, what does it cost, is anything obviously insecure?
CostWhere is the money going?
FinOpsHow do I spend less?
Users / IAMWho has access, who has MFA, what did they do?
GuardDuty & InspectorIs anything attacking me, or vulnerable?
CloudWatch & LogsWhat do my logs say?
S3What is in my file storage?
CloudFormationWhat is deployed, and has anyone changed it by hand?
Servers (EC2)Open a shell on an instance

Regions

AWS resources live in regions, and most screens work one region at a time with a selector at the top. Your project has a default region, set when you created it and changeable in Settings → Project.

The Dashboard is the exception — it scans every enabled region each time you open it, which is why it takes a few seconds.

What the assistant can do with AWS

In an AWS project the assistant can run AWS commands directly: describe resources, read logs, check costs, and — in Execute mode, with your approval — make changes.

Two things worth knowing:

  • Deleting or terminating cloud resources always asks, even with auto-approve on.
  • Operators cannot delete or terminate AWS resources at all. See Roles.