DevOpsArk + AWS
EKS, EC2, ECR, IAM and billing in one plane
Vendor: Amazon Web Services
What does the DevOpsArk AWS integration do?
The DevOpsArk AWS integration connects one or more AWS accounts so that EKS clusters, EC2 instances, ECR repositories, IAM configuration and billing data are managed from the same plane as the rest of your estate.
What the AWS integration provides
- Manage Amazon EKS clusters alongside AKS, GKE and self-managed Kubernetes in one inventory.
- Inventory EC2 instances with their operating system, patch state and configuration baseline.
- Publish container images to Amazon ECR by immutable digest from ArkBuilder.
- Evaluate account configuration against CIS AWS Foundations and your own policy.
- Attribute Cost and Usage Report data to clusters, namespaces, services and teams.
- Review IAM roles and policies as part of the unified effective-access model.
- Manage Route 53 zones and records with change validation and dangling-record detection.
- Track ACM and third-party certificates presented by AWS load balancers.
Exactly what is read, and what can be written
Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.
- EKS cluster, node group and add-on configuration
- EC2 instance inventory, tags and instance metadata
- ECR repositories, images and scan findings
- IAM users, roles, policies and last-used data
- CloudWatch metrics and logs
- Cost and Usage Report exports
- Route 53 hosted zones and record sets
- VPC, security group and load balancer configuration
- Kubernetes workloads deployed to EKS through ArkCD
- Container images pushed to ECR
- Route 53 record changes through the reviewed change path
- Approved remediation of tagged resources where write scope is granted
Connecting AWS
- 1Create a role
Create an IAM role for DevOpsArk with the supplied read-only policy, trusted for cross-account assumption.
- 2Register the account
Add the account and role ARN in DevOpsArk; the connection is verified immediately.
- 3Attach billing
Point DevOpsArk at the Cost and Usage Report export in S3 to enable cost attribution.
- 4Grant write scope if wanted
Add scoped write permissions per account only for the actions you want DevOpsArk to perform.
Which modules use AWS
Kubernetes
Multi-cluster Kubernetes management
Servers
Fleet inventory, patching and access
Cost Management
Cloud and Kubernetes cost attribution
Security
Posture, policy and continuous verification
ArkCD
Continuous delivery and progressive rollout
DNS Management
Records, zones and change safety
AWS integration: frequently asked questions
It connects your AWS accounts so EKS clusters, EC2 instances, ECR repositories, IAM configuration, Route 53 zones and billing data appear in the same inventory as the rest of your infrastructure, and can be governed by the same delivery, security and cost models.
A cross-account IAM role with the supplied read-only policy is enough for inventory, monitoring, security posture and cost. Write permissions are separate, scoped per account and per action type, and only required for deployment or remediation.
Yes. Accounts across an AWS Organization can be connected individually or through the management account, and everything is presented in one cross-account inventory.
Yes, through ArkCD. EKS clusters are targets like any other Kubernetes cluster, with per-cluster rollout strategy, configuration and approvals.
The Cost and Usage Report is joined with the live infrastructure inventory, so EC2 and EKS node cost is distributed across namespaces and workloads by request and usage, then mapped to owning teams.
Yes, subject to the region exposing the standard AWS APIs. Environments with no inbound connectivity can connect through an outbound-only relay.
Connect AWS and see your own data
Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.