Skip to main content
You connect an AWS account you already own. Springwinter does not create a stack in that account, and it does not grant itself administrator access.

You launch the stack

Connect AWS asks for the 12-digit account number and gives you a CloudFormation Quick Create link. The template was published from Springwinter’s control plane. You open it in your account, read it, and create the stack. Springwinter does not call CreateStack. The stack creates one IAM role for that connection. The role’s trust policy names the Springwinter control-plane principal and requires this connection’s external ID. A caller who knows the role name, but not that external ID, cannot assume the role through Springwinter. The external ID is generated for the connection. It is stored with the connection, and it is part of the trust policy. Treat it as a secret. Do not put it in a ticket, a screenshot, or a public repository.

You choose the permissions

The template carries the permission contract for the resources Springwinter creates: web servers, workers, static sites, databases, caches, and the project network. It is not AdministratorAccess. You can inspect the policy before you create the stack, and you can change the role later in IAM. Springwinter does not attach extra permissions after the stack exists. If you remove an action, the next operation that needs it stops.

A call is checked, then assumed

Before a web server, worker, or static site is created, Springwinter calls iam:SimulatePrincipalPolicy on the role. The same check runs again before a redeploy that would create something new. If a required action is missing, the API returns missing_permissions and creates nothing. Caches and the project security controls simulate their own action lists the same way. When the simulation passes, Springwinter calls sts:AssumeRole with the role ARN and the external ID. The credentials from that call are temporary. They are not written to the application database, and they are not written to logs. The next call assumes the role again. A log line for an assumption can include the role ARN, the region, and a session identifier used to correlate the call. It does not include the external ID or the keys.

What is stored about the connection

The account number is unique for an organization. The role ARN and the external ID are unique across Springwinter, including after a connection is removed, so a deleted connection’s identifiers are not reused.

What you can revoke

Access lasts as long as the role trusts Springwinter and the external ID still matches.
  • Delete the CloudFormation stack, or delete the role, and later assumptions fail.
  • Tighten the role’s policy, and the next operation that needs a removed action fails the simulation and creates nothing.
  • Resources already created stay in your account until you remove them. Disconnecting Springwinter does not delete your VPC, your databases, or your buckets.
The role ARN and the external ID are stored because the next call has to know which role to assume. They are not a substitute for the temporary keys, and they are not enough to assume the role from outside Springwinter’s control plane.