Cloud

DevOpsArk + AWS

EKS, EC2, ECR, IAM and billing in one plane

Vendor: Amazon Web Services

Short answer

What does the DevOpsArk AWS integration do?

The DevOpsArk AWS integration connects one or more AWS accounts so that EKS clusters, EC2 instances, ECR repositories, IAM configuration and billing data are managed from the same plane as the rest of your estate.

Capabilities

What the AWS integration provides

  • Manage Amazon EKS clusters alongside AKS, GKE and self-managed Kubernetes in one inventory.
  • Inventory EC2 instances with their operating system, patch state and configuration baseline.
  • Publish container images to Amazon ECR by immutable digest from ArkBuilder.
  • Evaluate account configuration against CIS AWS Foundations and your own policy.
  • Attribute Cost and Usage Report data to clusters, namespaces, services and teams.
  • Review IAM roles and policies as part of the unified effective-access model.
  • Manage Route 53 zones and records with change validation and dangling-record detection.
  • Track ACM and third-party certificates presented by AWS load balancers.
Access

Exactly what is read, and what can be written

Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.

Read
  • EKS cluster, node group and add-on configuration
  • EC2 instance inventory, tags and instance metadata
  • ECR repositories, images and scan findings
  • IAM users, roles, policies and last-used data
  • CloudWatch metrics and logs
  • Cost and Usage Report exports
  • Route 53 hosted zones and record sets
  • VPC, security group and load balancer configuration
Write, only if granted
  • Kubernetes workloads deployed to EKS through ArkCD
  • Container images pushed to ECR
  • Route 53 record changes through the reviewed change path
  • Approved remediation of tagged resources where write scope is granted
Setup

Connecting AWS

  1. 1
    Create a role

    Create an IAM role for DevOpsArk with the supplied read-only policy, trusted for cross-account assumption.

  2. 2
    Register the account

    Add the account and role ARN in DevOpsArk; the connection is verified immediately.

  3. 3
    Attach billing

    Point DevOpsArk at the Cost and Usage Report export in S3 to enable cost attribution.

  4. 4
    Grant write scope if wanted

    Add scoped write permissions per account only for the actions you want DevOpsArk to perform.

FAQ

AWS integration: frequently asked questions

Connect AWS and see your own data

Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.