AWS Infrastructure Coverage
Complete visibility across your AWS accounts. Every supported service is inventoried, analyzed, and monitored — with Terraform drift detection built in.
How it works
Four capabilities compose the coverage below.
Inventory
Discovers and syncs resources from AWS into the database. Runs on a schedule or on-demand per account and region.
Metrics
Pulls CloudWatch time-series data (CPU, memory, IOPS, latency…) and stores it for trend analysis and anomaly detection.
Optimization
Evaluates metric history against thresholds and turns findings into actionable cost-saving recommendations: right-sizing, Reserved Instance purchases, or deletion candidates.
Drift detection
Compares live inventory against Terraform state files to find resources created outside IaC — unmanaged infrastructure.
Coverage by service
One card per service. Each card lists its resource types and the capabilities they support.
Storage
-
CloudWatch Log Groups
-
EFS File Systems
-
S3 Buckets
-
EBS Volumes
-
EBS Snapshots
Databases
-
DynamoDB Tables
-
ElastiCache Clusters
-
Replication Groups
-
ElastiCache Reserved
-
OpenSearch Domains
-
OpenSearch Reserved
-
RDS Instances
-
Aurora Clusters
-
RDS Reserved
Compute
-
EC2 Instances
-
Reserved Instances
-
Lambda Functions
-
Savings Plan
Network
-
Elastic IPs
-
Classic Load Balancers
-
ALB / NLB
-
Target Groups
-
Route 53 Hosted Zones
-
VPCs
-
Subnets
-
Internet Gateways
-
NAT Gateways
-
VPC Endpoints
Security
-
Security Groups
-
IAM Policies
-
IAM Roles
-
KMS Keys
-
Secrets
Messaging
-
SNS Topics
-
SQS Queues
Configuration
Role template
Deploy as-is, then paste the resulting RoleArn output into the "Assume Role ARN" field.
Download role template
Required permissions65 actions
Grouped by AWS service. Read-only actions only — no create, modify, or delete.
| Service | IAM actions |
|---|---|
| Account_analyticsReadOnly |
account_analytics
|
| Account_settingsReadOnly |
account_settings
|
| CloudwatchReadOnly |
cloudwatch:GetMetricStatistics
|
| DynamodbReadOnly |
dynamodb:DescribeTable
dynamodb:ListTables
dynamodb:ListTagsOfResource
|
| Ec2ReadOnly |
ec2:DescribeAddresses
ec2:DescribeInstances
ec2:DescribeInternetGateways
ec2:DescribeNatGateways
ec2:DescribeReservedInstances
ec2:DescribeSecurityGroups
ec2:DescribeSnapshots
ec2:DescribeSubnets
ec2:DescribeVolumes
ec2:DescribeVpcEndpoints
ec2:DescribeVpcs
|
| ElasticacheReadOnly |
elasticache:DescribeCacheClusters
elasticache:DescribeReplicationGroups
elasticache:DescribeReservedCacheNodes
elasticache:ListTagsForResource
|
| ElasticfilesystemReadOnly |
elasticfilesystem:DescribeFileSystems
elasticfilesystem:DescribeLifecycleConfiguration
elasticfilesystem:DescribeTags
|
| ElasticloadbalancingReadOnly |
elasticloadbalancing:DescribeLoadBalancers
elasticloadbalancing:DescribeTags
elasticloadbalancing:DescribeTargetGroups
|
| EsReadOnly |
es:DescribeDomains
es:DescribeReservedInstances
es:ListDomainNames
es:ListTags
|
| KmsReadOnly |
kms:DescribeKey
kms:GetKeyRotationStatus
kms:ListAliases
kms:ListKeys
kms:ListResourceTags
|
| LambdaReadOnly |
lambda:GetFunctionConfiguration
lambda:ListFunctions
lambda:ListTags
|
| LogsReadOnly |
logs:DescribeLogGroups
logs:ListTagsForResource
logs:ListTagsLogGroup
|
| QueryReadOnly |
query:read
|
| RdsReadOnly |
rds:DescribeDBClusters
rds:DescribeDBInstances
rds:DescribeReservedDBInstances
rds:ListTagsForResource
|
| Route53ReadOnly |
route53:ListHostedZones
route53:ListResourceRecordSets
route53:ListTagsForResource
|
| S3ReadOnly |
s3:GetBucketLocation
s3:GetBucketTagging
s3:GetObject
s3:ListAllMyBuckets
s3:ListBucket
|
| SavingsplansReadOnly |
savingsplans:DescribeSavingsPlans
|
| SecretsmanagerReadOnly |
secretsmanager:ListSecrets
|
| SnsReadOnly |
sns:GetTopicAttributes
sns:ListTagsForResource
sns:ListTopics
|
| SqsReadOnly |
sqs:GetQueueAttributes
sqs:ListQueueTags
sqs:ListQueues
|
| Workers_r2ReadOnly |
workers_r2
|
| ZoneReadOnly |
zone
|
First sync
Audit → AWS.