All documentation
Amazon Web Services

Cloud integration

Amazon Web Services

Connect AWS with a cross-account IAM role and Cost and Usage Report (CUR). OptCloud never needs your root credentials or write access.

Connection

Cross-account IAM role + External ID + CUR (S3)

Access model

Read-only

Time to value

First Cost Explorer totals in minutes; full CUR granularity after the first report lands

How OptCloud connects with AWS

OptCloud uses the AWS-recommended Cross-Account IAM Role pattern with a unique External ID. You create a role in your account that only OptCloud's hub account can assume, and only when the request includes the External ID we generate for your connection — this prevents the confused-deputy problem and means we never ask for or store long-lived AWS access keys. We pull Cost Explorer totals immediately for high-level spend, then ingest your Cost and Usage Report (CUR) from an S3 bucket for resource-level filtering, tagging, and recommendations. We only collect billing and inventory metadata — never application data from EC2, S3 objects, or databases.

Required permissions (read-only)

  • ce:* (Cost Explorer) — high-level historical spend
  • cur:Describe* / S3 GetObject on the CUR bucket — detailed line items
  • ec2:Describe*, rds:Describe*, s3:List*, eks:Describe*, lambda:List* — inventory and utilization metadata for recommendations
  • organizations:ListAccounts (optional) — multi-account rollups under AWS Organizations
  • compute-optimizer:Get* (optional) — additional rightsizing signals when Compute Optimizer is enabled

OptCloud never requests iam:Create*, ec2:TerminateInstances, or any mutation APIs. The role is assume-role only; no long-lived access keys are stored, and the trust policy only accepts requests carrying your unique External ID.

Cost Explorer vs. CUR — what you see, and when

When you first connect, OptCloud shows historical totals within minutes using AWS Cost Explorer. Cost Explorer gives high-level totals but not the detail needed to filter or group by resource, tag, or account. Full filtering requires your Cost and Usage Report (CUR), which AWS can take up to 24 hours to deliver for the first time. The first CUR only contains the current month — for full historical filtering, backfill previous months (see below). Until the first CUR lands, Rightsizing and Idle Resources will show partial data.

Connecting AWS Organizations (multiple accounts)

If you use AWS Organizations, connect the management (payer) account first. This lets OptCloud see consolidated costs and tags across every linked account in one place. If you connect only a member account, you will only see that account's spend, miss organization-wide cost allocation tags, and Savings Plans/RI coverage will be calculated in isolation instead of across the organization. OptCloud automatically discovers linked accounts under the management account's role and lists each one as a separate connection you can assign to teams or budgets.

Create a connection

  1. 1

    Create an OptCloud AWS connection

    In OptCloud, go to Cloud Accounts → Add account → AWS. We generate a unique External ID for this connection and give you a CloudFormation template (Terraform and manual IAM console setup are also available).

  2. 2

    Deploy the cross-account role

    Run the provided CloudFormation stack. It creates an IAM role trusting only OptCloud's hub account, locked to your External ID, and attaches the documented read-only policy. Acknowledge that CloudFormation may create IAM resources, then create the stack.

  3. 3

    Enable Cost and Usage Report

    Create a CUR that delivers daily reports to an S3 bucket in your account, with resource IDs enabled. Include split cost allocation data if you want Kubernetes/container-level AWS cost signals.

  4. 4

    Grant OptCloud access to the CUR bucket

    The stack (or policy snippet we provide) allows OptCloud to list and read objects from that bucket only. No write access to other buckets is required.

  5. 5

    Wait for the first CUR

    Cost Explorer data appears quickly. Full filter/group by resource, tag, and account requires the first CUR, which can take up to 24 hours. Optionally backfill previous months so historical periods are fully filterable.

  6. 6

    Verify in OptCloud

    On Cloud Accounts, the connection should show Connected. Open Cost Explorer and confirm spend by service (EC2, RDS, S3, EKS, etc.). Recommendations begin populating as utilization metadata syncs.

Backfilling historical CUR data

By default, your first CUR only contains the current month, so past months show totals only (no filtering by resource, tag, or account). To unlock full historical granularity, open a support ticket with AWS asking them to backfill the CUR export OptCloud created (a daily CSV with resource IDs enabled) for the date range you need, then let us know so we re-ingest it. Without backfill, everything still works — historical analysis is just limited to high-level totals.

Data collected

  • Cost and usage line items (service, account, region, usage type, tags)
  • Resource inventory metadata (instance type, state, attached volumes — not disk contents)
  • Commitment inventory (Savings Plans, Reserved Instances) for coverage analysis
  • Optional Compute Optimizer recommendations when enabled in AWS

What you get in OptCloud

  • Unified Cost Explorer across every connected AWS account
  • Rightsizing and idle resource recommendations ranked by ROI
  • Savings Plans / RI coverage and break-even modeling
  • Tag compliance and unallocated spend views
  • FinOps Agent answers grounded in your live AWS cost data

Filterable dimensions

Once connected, you can filter and group cost data in Cost Explorer and Reports by:

  • Account — AWS account name and ID
  • Category — compute, storage, network, database, other (OptCloud's normalized category)
  • Service — e.g. EC2, RDS, S3, EKS
  • Region — e.g. us-east-1, eu-west-1
  • Resource — specific resource ID (instance, volume, load balancer, etc.)
  • Tag / Not tagged — any AWS cost allocation tag key and value
  • Usage type and operation — the underlying CUR usage type driving the charge
  • Charge type — usage, tax, credit, refund, Savings Plan/RI amortization

Updating or rotating your connection

If OptCloud expands its read-only permission set, or you want to rotate the External ID for security hygiene, open the account in Cloud Accounts and click Update Connection. We generate a fresh CloudFormation template with the updated policy and/or a new External ID — redeploy the stack and the existing connection is updated in place, with no gap in data collection.

Troubleshooting

I see totals but cannot filter by tag or resource

You are likely seeing Cost Explorer-only data. Confirm CUR delivery to S3 and that OptCloud can read the bucket. After the first CUR processes (up to 24 hours), filtering becomes available.

Multi-account Organizations — do I connect every account?

Connect the management (payer) account first — see Connecting AWS Organizations above. Member-only connections work too if each account has its own CUR, but you lose the consolidated view.

China or GovCloud regions

Standard OptCloud ingestion targets commercial AWS regions. GovCloud/China require a CUR copy into a commercial-region bucket we can read — contact us for the supported pattern.

Related integrations

Ready to connect AWS?

Open the dashboard to add the account, or book a walkthrough with our team.