Skip to main content

AWS

This config type is used to scrape information about your AWS infrastructure.

Registry

The Mission Control Registry includes an AWS Helm chart that provides a pre-configured Scraper with common defaults

aws-scraper.yaml
apiVersion: configs.flanksource.com/v1
kind: ScrapeConfig
metadata:
name: aws-scraper
spec:
aws:
- region:
- eu-west-1
exclude:
- Amazon EC2 Reserved Instances Optimization
- Savings Plan
- trusted_advisor
- cloudtrail
FieldDescriptionSchemeRequired
scheduleSpecify the interval to scrape in cron format. Defaults to every 60 minutes.Cron
retentionSettings for retaining changes, analysis and scraped itemsRetention
awsSpecifies the list of AWS configurations to scrape.[]AWS

AWS​

FieldDescriptionScheme
accessKey

Access Key ID

EnvVar

assumeRole

Role ARN to assume

string

cloudtrail

Ingest cloudtrail events

CloudTrail

compliance

Toggle scraping of compliance metadata

boolean

connection

The connection url to use, mutually exclusive with accessKey and secretKey

Connection

costReporting

Enable cost and usage reporting

CostReporting

endpoint

Custom AWS Endpoint to use

string

exclude

AWS resources to exclude from scraping

[]string

exclusions

Exclude individual scraped items by type, name and/or tags

[]Exclusion

include

AWS resources to include for scraping

[]string

region

The AWS region

string

secretKey

Secret Access Key

EnvVar

sessionToken

Session token

EnvVar

skipTLSVerify

Skip TLS verify when connecting to AWS

boolean

labels

Labels for each config item.

map[string]string

properties

Custom templatable properties for the scraped config items.

[]ConfigProperty

tags

Tags for each config item. Max allowed: 5

[]ConfigTag

transform

Transform configs after they've been scraped

Transform

Exclusions​

Where exclude drops whole resource types, exclusions drops individual items. A rule matches when all of its populated fields match, and an item is excluded when any rule matches.

type and name accept comma-separated patterns and support globs (*, prefix*, *suffix*) and negation (!pattern).

FieldDescriptionScheme
typeConfig type patterns to exclude e.g. AWS::EC2::Instancestring
nameName patterns to excludestring
tagsTags the item must carry, values matched as patternsmap[string]string
aws-exclusions.yaml
aws:
- exclusions:
# Drop every scratch bucket
- type: AWS::S3::Bucket
name: 'scratch-*'
# Drop anything tagged as ephemeral
- tags:
lifecycle: ephemeral

CloudTrail​

FieldDescriptionScheme
excludeSet events to be excluded from scraping[]string
maxAgeSet maximum age of events for scraping, Defaults to 7dDuration

Cost Reporting​

FieldDescriptionScheme
s3BucketPathSet path for S3 bucket to scrape published AWS billing reportsstring
tableSpecify table containing cost and usage datastring
databaseSpecify database containing cost and usage datastring
regionSpecify region for S3 bucketstring
lookbackDaysHow many days of the cost and usage report to read on each scrape. Values of 0 or less use the 45 day defaultint

Trusted Advisor​

The scraper integrates with AWS Trusted Advisor to collect real-time guidance across cost optimization, performance, fault tolerance, security, and service limits to help optimize your AWS infrastructure.

Rate Limitations

Trusted Advisor checks run with a minimum interval of 16 hours (due to API rate limitations). This can be overridden by setting the property scraper.aws.trusted_advisor.minInterval.

To disable Trusted Advisor altogether, you can add an exclusion rule:

exclude:
- trusted_advisor

Supported Resources​

Resource TypeAWS TypeConfig ClassDescription
AccountAWS::IAM::AccountAccountAWS Account information
CloudFormationStackAWS::CloudFormation::StackStackCloudFormation stacks
DHCPOptionsAWS::EC2::DHCPOptionsDHCPDHCP Options Sets
DNSZoneAWS::Route53::HostedZoneDNSZoneRoute53 Hosted Zones
EBSVolumeAWS::EBS::VolumeDiskStorageElastic Block Store Volumes
EC2InstanceAWS::EC2::InstanceVirtualMachineEC2 Instances
ECRRepositoryAWS::ECR::RepositoryContainerRegistryElastic Container Registry Repositories
ECSClusterAWS::ECS::ClusterECSClusterECS Clusters
ECSServiceAWS::ECS::ServiceECSServiceECS Services
ECSTaskAWS::ECS::TaskECSTaskECS Tasks
ECSTaskDefinitionAWS::ECS::TaskDefinitionECSTaskDefinitionECS Task Definitions
EFSFileSystemAWS::EFS::FileSystemFileSystemElastic File System
EKSClusterAWS::EKS::ClusterKubernetesClusterElastic Kubernetes Service Clusters
ElastiCacheAWS::ElastiCache::CacheClusterCacheElastiCache Clusters
FargateProfileAWS::EKS::FargateProfileFargateProfileEKS Fargate Profiles
IAMInstanceProfileAWS::IAM::InstanceProfileProfileIAM Instance Profiles
IAMRoleAWS::IAM::RoleRoleIAM Roles
IAMUserAWS::IAM::UserUserIAM Users
LambdaFunctionAWS::Lambda::FunctionLambdaLambda Functions
LoadBalancerAWS::ElasticLoadBalancing::LoadBalancerLoadBalancerClassic Load Balancers
LoadBalancerV2AWS::ElasticLoadBalancingV2::LoadBalancerLoadBalancerApplication/Network Load Balancers
RDSInstanceAWS::RDS::DBInstanceRelationalDatabaseRDS Database Instances
RouteTableAWS::EC2::RouteTableRouteVPC Route Tables
S3BucketAWS::S3::BucketObjectStorageS3 Buckets
SecurityGroupAWS::EC2::SecurityGroupSecurityGroupSecurity Groups
SNSTopicAWS::SNS::TopicTopicSimple Notification Service Topics
SQSQueueAWS::SQS::QueueQueueSimple Queue Service Queues
SubnetAWS::EC2::SubnetSubnetVPC Subnets
VPCAWS::EC2::VPCVPCVirtual Private Clouds