> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Your AWS Account to Springwinter via CloudFormation

> Link your AWS account using a CloudFormation-provisioned IAM role. Springwinter assumes the role per-call and never stores permanent credentials.

Springwinter deploys and manages resources inside your AWS account using a dedicated IAM role that you create through a CloudFormation stack. You remain in full control of that role — you can inspect its permissions, restrict it further, or delete it at any time. Springwinter never receives long-lived AWS credentials; instead, it assumes the role on demand using a secure external ID unique to your account, and the temporary session keys it receives expire automatically.

## How the connection works

When you launch the CloudFormation stack, AWS creates a single IAM role in your account. That role's trust policy allows only the Springwinter control plane to assume it, and only when it presents your unique external ID — a random value generated at sign-up that acts as a second factor for the `sts:AssumeRole` call.

Each time Springwinter needs to take an action in your account — creating a service, reading a log group, fetching a cost estimate — it calls `sts:AssumeRole`, receives short-lived credentials scoped to that session, uses them for the operation, and discards them. No access keys are ever written to a database. If you revoke the role, Springwinter immediately loses the ability to act in your account.

## Connect your AWS account

<Steps>
  <Step title="Open AWS settings in the dashboard">
    Log in to the Springwinter dashboard and navigate to **Settings → AWS**. If you have not yet connected an account, you will see the **Connect AWS** button.
  </Step>

  <Step title="Generate your CloudFormation link">
    Click **Connect AWS**. Springwinter generates a pre-signed CloudFormation link that encodes your unique external ID and the template URL. Click the link — it opens directly to the **Create Stack** page in your AWS Console.
  </Step>

  <Step title="Review the CloudFormation template">
    On the AWS Console **Create Stack** page, review the template before proceeding. The template creates exactly one IAM role with a trust policy scoped to the Springwinter AWS principal and your external ID. You can download and audit the template source before you launch.
  </Step>

  <Step title="Launch the stack">
    Accept the IAM capabilities acknowledgment and click **Create Stack**. CloudFormation typically completes in under two minutes. The stack's **Events** tab shows progress in real time.
  </Step>

  <Step title="Copy the Role ARN from the stack Outputs">
    Once the stack status shows `CREATE_COMPLETE`, open the **Outputs** tab. Copy the value next to the `RoleArn` key — it looks like `arn:aws:iam::123456789012:role/SpringwinterRole`.
  </Step>

  <Step title="Paste the ARN into Springwinter and verify">
    Return to the Springwinter dashboard, paste the Role ARN into the field provided, and click **Verify**. Springwinter immediately attempts a test `sts:AssumeRole` call to confirm the role is reachable and the external ID matches. A green checkmark confirms the connection is live.
  </Step>
</Steps>

<Warning>
  Springwinter does not grant itself administrator access. The IAM role created by the CloudFormation template has a scoped permissions policy covering only the services Springwinter manages. Before any resource is created, the required IAM actions are checked against the role's effective permissions. If a required action is missing, the operation fails cleanly and nothing is created — your account is never left in a partial state.
</Warning>

## Required IAM permissions

The CloudFormation template provisions a policy that grants permissions in the following AWS service categories. Springwinter checks for the relevant actions at deploy time; if your organization adds an SCP or permission boundary that removes any of these, affected resource types will report a permission error before attempting to create anything.

| Service category | Used for |
| - | - |
| **ECS / ECR** | Deploying and updating web servers and workers as container tasks |
| **Elastic Load Balancing** | Creating and managing Application Load Balancers for web servers |
| **CloudWatch Logs & Metrics** | Reading application logs and publishing resource metrics |
| **S3** | Hosting static websites and managing storage buckets |
| **CloudFront** | Creating and updating CDN distributions for static websites |
| **Secrets Manager** | Storing and injecting secrets as environment variable references |
| **RDS** | Provisioning and managing PostgreSQL and MySQL databases |
| **ElastiCache** | Provisioning and managing Valkey (Redis-compatible) caches |
| **Cost Explorer** | Fetching per-resource cost data and monthly run-rate estimates |
| **STS** | Allowing Springwinter to assume the role itself during verification |

## What Springwinter stores

Springwinter stores only the metadata necessary to locate and assume your role:

* **AWS account number** — to scope API calls to your account
* **Role name and ARN** — to construct the `AssumeRole` call
* **External ID** — to satisfy the trust policy condition
* **Connection status** — active or disconnected

Temporary session credentials returned by `sts:AssumeRole` are used in memory for a single operation and are never written to disk or a database.

<Note>
  You can audit every action Springwinter takes in your account by enabling AWS CloudTrail. All API calls appear under the assumed role's session name, making it straightforward to attribute activity back to Springwinter operations.
</Note>

## Disconnect your AWS account

<Tip>
  To revoke Springwinter's access, delete the CloudFormation stack from your AWS Console (**CloudFormation → Stacks → select the Springwinter stack → Delete**). Deleting the stack removes the IAM role, immediately preventing any further `AssumeRole` calls. Resources that were already created in your account continue running — Springwinter will no longer be able to manage or read them until you reconnect.
</Tip>
