Cloud Setup

Cloud provider configurations

The provider credentials, regions, permissions, billing exports, service fields, and deployment settings CloudWatcher uses.

Use this page when you need to understand exactly what CloudWatcher asks for and why.

AWS configuration

  • Identity: IAM role ARN with external ID, or credentials used only where the workflow explicitly supports manual credential validation.
  • Regions: common regions include us-east-1, us-east-2, us-west-1, us-west-2, eu-west-1, eu-central-1, ap-south-1, ap-southeast-1, and ap-northeast-1.
  • Billing: Cost Explorer or billing permissions are required for billing metrics, spend trends, cost savings, and recommendations.
  • Monitoring: CloudWatch, CloudWatch Logs, service read permissions, and resource inventory permissions are required for dashboards and alerts.
  • Simulation deployment: Terraform workflows need create, update, read, and destroy permissions for the selected services.
  • Common compute fields: instance type, AMI, key pair, admin username, count, VPC, subnet, security group, and region.
  • Common network fields: VPC CIDR, subnet CIDR, SSH port, HTTP port, HTTPS port, private mode, load balancer port, target group routing, and public IP settings.

Azure configuration

  • Identity: tenant ID, subscription ID, client ID, and client secret for a service principal.
  • Regions: common regions include centralindia, eastus, eastus2, westus2, northeurope, westeurope, and southeastasia.
  • Billing: Azure Cost Management access is required for cost data.
  • Monitoring: subscription read access, resource inventory access, metrics access, and selected provider permissions are required for dashboards.
  • Simulation deployment: Contributor-style write permissions may be required for VM, storage, SQL, function, VNet, AKS, load balancer, disk, and public IP creation.
  • Common compute fields: VM size, VM count, admin username, OS disk type, Ubuntu image publisher, image offer, image SKU, and region.
  • Common storage fields: storage account name, account tier, replication type, account kind, region, and policy.
  • Common network fields: VNet name, address space, subnet CIDR, NSG rules, SSH port, HTTP port, HTTPS port, private mode, public IP, backend pool, and load balancer ports.

GCP configuration

  • Identity: project ID, service account client email, private key, and enabled APIs for the services you want to use.
  • Regions and zones: common regions include us-central1, us-east1, us-west1, europe-west1, europe-west3, asia-south1, and asia-southeast1; zones include values such as us-central1-a and asia-south1-a.
  • Billing: GCP billing export is required for reliable cost reporting.
  • Monitoring: service account roles must allow reading resources, metrics, and project data.
  • Simulation deployment: create and delete permissions are required for Compute Engine, Cloud Storage, Cloud SQL, Cloud Run Functions, GKE, VPC, firewall, load balancing, disks, and Artifact Registry.
  • Common compute fields: instance name, machine type, zone, image, boot disk size, HTTP access, and region.
  • Common storage fields: bucket name, storage class, location, versioning, region, and policy.
  • Common network fields: VPC network name, CIDR block, subnet CIDR, firewall ports, private mode, external IP, backend service, load balancer port, and Cloud CDN settings.

Application deployment configuration

  • GitHub repository: Git URL, branch, optional token, project type, runtime, build command, start command, app port, frontend directory, backend directory, API path, and backend port.
  • Supported project types: generic Node or Python, Node API, Vite frontend, MERN app, Next.js app, and Docker app.
  • Docker Hub: repository, tag, username, password, app port, and container port.
  • Container registries: AWS ECR, Azure Container Registry, and GCP Artifact Registry are used for image-based workflows where configured.

Need more help?

Keep moving with the right next guide

If your team still runs into setup issues, empty dashboards, billing delays, callback failures, or alerting problems, continue with troubleshooting before re-running the entire onboarding flow.