You launch the stack
Connect AWS asks for the 12-digit account number and gives you a CloudFormation Quick Create link. The template was published from Springwinter’s control plane. You open it in your account, read it, and create the stack. Springwinter does not callCreateStack.
The stack creates one IAM role for that connection. The role’s trust policy names the Springwinter control-plane principal and requires this connection’s external ID. A caller who knows the role name, but not that external ID, cannot assume the role through Springwinter.
The external ID is generated for the connection. It is stored with the connection, and it is part of the trust policy. Treat it as a secret. Do not put it in a ticket, a screenshot, or a public repository.
You choose the permissions
The template carries the permission contract for the resources Springwinter creates: web servers, workers, static sites, databases, caches, and the project network. It is notAdministratorAccess. You can inspect the policy before you create the stack, and you can change the role later in IAM.
Springwinter does not attach extra permissions after the stack exists. If you remove an action, the next operation that needs it stops.
A call is checked, then assumed
Before a web server, worker, or static site is created, Springwinter callsiam:SimulatePrincipalPolicy on the role. The same check runs again before a redeploy that would create something new. If a required action is missing, the API returns missing_permissions and creates nothing. Caches and the project security controls simulate their own action lists the same way.
When the simulation passes, Springwinter calls sts:AssumeRole with the role ARN and the external ID. The credentials from that call are temporary. They are not written to the application database, and they are not written to logs. The next call assumes the role again.
A log line for an assumption can include the role ARN, the region, and a session identifier used to correlate the call. It does not include the external ID or the keys.
What is stored about the connection
The account number is unique for an organization. The role ARN and the external ID are unique across Springwinter, including after a connection is removed, so a deleted connection’s identifiers are not reused.
What you can revoke
Access lasts as long as the role trusts Springwinter and the external ID still matches.- Delete the CloudFormation stack, or delete the role, and later assumptions fail.
- Tighten the role’s policy, and the next operation that needs a removed action fails the simulation and creates nothing.
- Resources already created stay in your account until you remove them. Disconnecting Springwinter does not delete your VPC, your databases, or your buckets.
The role ARN and the external ID are stored because the next call has to know which role to assume. They are not a substitute for the temporary keys, and they are not enough to assume the role from outside Springwinter’s control plane.