How the connection works
When you launch the CloudFormation stack, AWS creates a single IAM role in your account. That role’s trust policy allows only the Springwinter control plane to assume it, and only when it presents your unique external ID — a random value generated at sign-up that acts as a second factor for thests:AssumeRole call.
Each time Springwinter needs to take an action in your account — creating a service, reading a log group, fetching a cost estimate — it calls sts:AssumeRole, receives short-lived credentials scoped to that session, uses them for the operation, and discards them. No access keys are ever written to a database. If you revoke the role, Springwinter immediately loses the ability to act in your account.
Connect your AWS account
1
Open AWS settings in the dashboard
Log in to the Springwinter dashboard and navigate to Settings → AWS. If you have not yet connected an account, you will see the Connect AWS button.
2
Generate your CloudFormation link
Click Connect AWS. Springwinter generates a pre-signed CloudFormation link that encodes your unique external ID and the template URL. Click the link — it opens directly to the Create Stack page in your AWS Console.
3
Review the CloudFormation template
On the AWS Console Create Stack page, review the template before proceeding. The template creates exactly one IAM role with a trust policy scoped to the Springwinter AWS principal and your external ID. You can download and audit the template source before you launch.
4
Launch the stack
Accept the IAM capabilities acknowledgment and click Create Stack. CloudFormation typically completes in under two minutes. The stack’s Events tab shows progress in real time.
5
Copy the Role ARN from the stack Outputs
Once the stack status shows
CREATE_COMPLETE, open the Outputs tab. Copy the value next to the RoleArn key — it looks like arn:aws:iam::123456789012:role/SpringwinterRole.6
Paste the ARN into Springwinter and verify
Return to the Springwinter dashboard, paste the Role ARN into the field provided, and click Verify. Springwinter immediately attempts a test
sts:AssumeRole call to confirm the role is reachable and the external ID matches. A green checkmark confirms the connection is live.Required IAM permissions
The CloudFormation template provisions a policy that grants permissions in the following AWS service categories. Springwinter checks for the relevant actions at deploy time; if your organization adds an SCP or permission boundary that removes any of these, affected resource types will report a permission error before attempting to create anything.What Springwinter stores
Springwinter stores only the metadata necessary to locate and assume your role:- AWS account number — to scope API calls to your account
- Role name and ARN — to construct the
AssumeRolecall - External ID — to satisfy the trust policy condition
- Connection status — active or disconnected
sts:AssumeRole are used in memory for a single operation and are never written to disk or a database.
You can audit every action Springwinter takes in your account by enabling AWS CloudTrail. All API calls appear under the assumed role’s session name, making it straightforward to attribute activity back to Springwinter operations.