Skip to main content

Cloud connections

Cloud connections

A cloud connection is a read-only link to one account. Create one from Organisation → Settings → Cloud connections; it needs integration.manage.

Read-only access

Continuum never writes to your cloud account. The permissions it asks for are descriptive: list and describe. If you are reviewing the role, anything that mutates infrastructure is out of scope and should be refused.

AWS

Grant a role Blueprintr can assume, using the account id and external id the connection page shows you. The external id stops another tenant assuming your role. Do not omit it.

Azure

Register an application and grant it a reader role over the subscriptions you want visible.

Scoping the grant

Grant the narrowest scope that covers what you want to draw: one subscription, or one set of accounts. Widening the scope later is one edit. Narrowing it once diagrams have been drawn from the wider scope changes those diagrams.

Terraform

State can also be used as a source, for estates where reading state is easier than granting access to the live account.