AWS Infrastructure Coverage

Complete visibility across your AWS accounts. Every supported service is inventoried, analyzed, and monitored — with Terraform drift detection built in.

How it works

Four capabilities compose the coverage below.

01
Inventory

Discovers and syncs resources from AWS into the database. Runs on a schedule or on-demand per account and region.

02
Metrics

Pulls CloudWatch time-series data (CPU, memory, IOPS, latency…) and stores it for trend analysis and anomaly detection.

03
Optimization

Evaluates metric history against thresholds and turns findings into actionable cost-saving recommendations: right-sizing, Reserved Instance purchases, or deletion candidates.

04
Drift detection

Compares live inventory against Terraform state files to find resources created outside IaC — unmanaged infrastructure.

Coverage by service

One card per service. Each card lists its resource types and the capabilities they support.

Inventory Metrics Optimization Drift detection
Storage
5 resource types
  • CloudWatch Log Groups
  • EFS File Systems
  • S3 Buckets
  • EBS Volumes
  • EBS Snapshots
Databases
9 resource types
  • DynamoDB Tables
  • ElastiCache Clusters
  • Replication Groups
  • ElastiCache Reserved
  • OpenSearch Domains
  • OpenSearch Reserved
  • RDS Instances
  • Aurora Clusters
  • RDS Reserved
Compute
4 resource types
  • EC2 Instances
  • Reserved Instances
  • Lambda Functions
  • Savings Plan
Network
10 resource types
  • Elastic IPs
  • Classic Load Balancers
  • ALB / NLB
  • Target Groups
  • Route 53 Hosted Zones
  • VPCs
  • Subnets
  • Internet Gateways
  • NAT Gateways
  • VPC Endpoints
Security
5 resource types
  • Security Groups
  • IAM Policies
  • IAM Roles
  • KMS Keys
  • Secrets
Messaging
2 resource types
  • SNS Topics
  • SQS Queues

Configuration

Role template

Deploy as-is, then paste the resulting RoleArn output into the "Assume Role ARN" field.

Download role template
Choose the format that matches your infrastructure-as-code stack.

Required permissions65 actions

Grouped by AWS service. Read-only actions only — no create, modify, or delete.

Service IAM actions
Account_analyticsReadOnly
account_analytics
Account_settingsReadOnly
account_settings
CloudwatchReadOnly
cloudwatch:GetMetricStatistics
DynamodbReadOnly
dynamodb:DescribeTable dynamodb:ListTables dynamodb:ListTagsOfResource
Ec2ReadOnly
ec2:DescribeAddresses ec2:DescribeInstances ec2:DescribeInternetGateways ec2:DescribeNatGateways ec2:DescribeReservedInstances ec2:DescribeSecurityGroups ec2:DescribeSnapshots ec2:DescribeSubnets ec2:DescribeVolumes ec2:DescribeVpcEndpoints ec2:DescribeVpcs
ElasticacheReadOnly
elasticache:DescribeCacheClusters elasticache:DescribeReplicationGroups elasticache:DescribeReservedCacheNodes elasticache:ListTagsForResource
ElasticfilesystemReadOnly
elasticfilesystem:DescribeFileSystems elasticfilesystem:DescribeLifecycleConfiguration elasticfilesystem:DescribeTags
ElasticloadbalancingReadOnly
elasticloadbalancing:DescribeLoadBalancers elasticloadbalancing:DescribeTags elasticloadbalancing:DescribeTargetGroups
EsReadOnly
es:DescribeDomains es:DescribeReservedInstances es:ListDomainNames es:ListTags
KmsReadOnly
kms:DescribeKey kms:GetKeyRotationStatus kms:ListAliases kms:ListKeys kms:ListResourceTags
LambdaReadOnly
lambda:GetFunctionConfiguration lambda:ListFunctions lambda:ListTags
LogsReadOnly
logs:DescribeLogGroups logs:ListTagsForResource logs:ListTagsLogGroup
QueryReadOnly
query:read
RdsReadOnly
rds:DescribeDBClusters rds:DescribeDBInstances rds:DescribeReservedDBInstances rds:ListTagsForResource
Route53ReadOnly
route53:ListHostedZones route53:ListResourceRecordSets route53:ListTagsForResource
S3ReadOnly
s3:GetBucketLocation s3:GetBucketTagging s3:GetObject s3:ListAllMyBuckets s3:ListBucket
SavingsplansReadOnly
savingsplans:DescribeSavingsPlans
SecretsmanagerReadOnly
secretsmanager:ListSecrets
SnsReadOnly
sns:GetTopicAttributes sns:ListTagsForResource sns:ListTopics
SqsReadOnly
sqs:GetQueueAttributes sqs:ListQueueTags sqs:ListQueues
Workers_r2ReadOnly
workers_r2
ZoneReadOnly
zone

First sync

Once the account is saved, inventory runs on the next hourly cycle — or trigger it immediately from the account's detail page. Discovered resources, grouped by service (EC2, RDS, S3, ...) appear under Audit → AWS.