Skip to main content
Springwinter deploys and manages resources inside your AWS account using a dedicated IAM role that you create through a CloudFormation stack. You remain in full control of that role — you can inspect its permissions, restrict it further, or delete it at any time. Springwinter never receives long-lived AWS credentials; instead, it assumes the role on demand using a secure external ID unique to your account, and the temporary session keys it receives expire automatically.

How the connection works

When you launch the CloudFormation stack, AWS creates a single IAM role in your account. That role’s trust policy allows only the Springwinter control plane to assume it, and only when it presents your unique external ID — a random value generated at sign-up that acts as a second factor for the sts:AssumeRole call. Each time Springwinter needs to take an action in your account — creating a service, reading a log group, fetching a cost estimate — it calls sts:AssumeRole, receives short-lived credentials scoped to that session, uses them for the operation, and discards them. No access keys are ever written to a database. If you revoke the role, Springwinter immediately loses the ability to act in your account.

Connect your AWS account

1

Open AWS settings in the dashboard

Log in to the Springwinter dashboard and navigate to Settings → AWS. If you have not yet connected an account, you will see the Connect AWS button.
2

Generate your CloudFormation link

Click Connect AWS. Springwinter generates a pre-signed CloudFormation link that encodes your unique external ID and the template URL. Click the link — it opens directly to the Create Stack page in your AWS Console.
3

Review the CloudFormation template

On the AWS Console Create Stack page, review the template before proceeding. The template creates exactly one IAM role with a trust policy scoped to the Springwinter AWS principal and your external ID. You can download and audit the template source before you launch.
4

Launch the stack

Accept the IAM capabilities acknowledgment and click Create Stack. CloudFormation typically completes in under two minutes. The stack’s Events tab shows progress in real time.
5

Copy the Role ARN from the stack Outputs

Once the stack status shows CREATE_COMPLETE, open the Outputs tab. Copy the value next to the RoleArn key — it looks like arn:aws:iam::123456789012:role/SpringwinterRole.
6

Paste the ARN into Springwinter and verify

Return to the Springwinter dashboard, paste the Role ARN into the field provided, and click Verify. Springwinter immediately attempts a test sts:AssumeRole call to confirm the role is reachable and the external ID matches. A green checkmark confirms the connection is live.
Springwinter does not grant itself administrator access. The IAM role created by the CloudFormation template has a scoped permissions policy covering only the services Springwinter manages. Before any resource is created, the required IAM actions are checked against the role’s effective permissions. If a required action is missing, the operation fails cleanly and nothing is created — your account is never left in a partial state.

Required IAM permissions

The CloudFormation template provisions a policy that grants permissions in the following AWS service categories. Springwinter checks for the relevant actions at deploy time; if your organization adds an SCP or permission boundary that removes any of these, affected resource types will report a permission error before attempting to create anything.

What Springwinter stores

Springwinter stores only the metadata necessary to locate and assume your role:
  • AWS account number — to scope API calls to your account
  • Role name and ARN — to construct the AssumeRole call
  • External ID — to satisfy the trust policy condition
  • Connection status — active or disconnected
Temporary session credentials returned by sts:AssumeRole are used in memory for a single operation and are never written to disk or a database.
You can audit every action Springwinter takes in your account by enabling AWS CloudTrail. All API calls appear under the assumed role’s session name, making it straightforward to attribute activity back to Springwinter operations.

Disconnect your AWS account

To revoke Springwinter’s access, delete the CloudFormation stack from your AWS Console (CloudFormation → Stacks → select the Springwinter stack → Delete). Deleting the stack removes the IAM role, immediately preventing any further AssumeRole calls. Resources that were already created in your account continue running — Springwinter will no longer be able to manage or read them until you reconnect.